Redirect Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by 1StumpedGeek, Dec 11, 2009.

  1. 1StumpedGeek

    1StumpedGeek Private E-2

    Have read similar threads but with no success. System works fine (no pop ups or slow down) but search engine redirects. Help please!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    We need to use ComboFix to apply a fix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    • Now please save Win32kDiag file to your desktop.
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    "%userprofile%\desktop\win32kdiag.exe" -f -r

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • the Win32kDiag log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. 1StumpedGeek

    1StumpedGeek Private E-2

    Sorry for the delay. I am waiting to download ComboFix to try the fix. Thanks for the reply.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already had it on your Desktop. Did you delete it? Currently the download site has taken it offline to fix a bug but you could have still used the version you had.
     
  5. 1StumpedGeek

    1StumpedGeek Private E-2

    I tried using ComboFix a couple of times and it hung up before printing the log despite not touching anything while it ran. I thought it could be a remanant from AGV 9 that removed so there would not be a conflict. AGV did not completely remove all the files so I used the removal tool from AGV. It got rid of AGV and ComboFix at the same time... oops. So I wait for the release of the updated version. Still getting redirect issue.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try the beta version of ComboFix which is named KittyFix.exe

    Download ComboFix from http://download.bleepingcomputer.com/sUBs/Beta/KittyFix.exe and save it to your Desktop.

    Note: This is a beta version of combofix and might be unstable but tests done so far have proved it works well



    Note: It is important that it is saved directly to your desktop and run from the desktop and not any other folder on your computer.
    • Now Exit/Close/Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Close any open browsers and any other programs you might have running.
    • Double click on kittyfix.exe & follow the prompts.
      • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this
    • When finished, it will produce a report for you. Please attach the "C:\ComboFix.txt" to your next message.
    Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
     
    Last edited: Dec 17, 2009
  7. 1StumpedGeek

    1StumpedGeek Private E-2

    Sorry for the delay in responding. I am out of the country. I had success cleaning with TDSSKiller and reinstalling my Java as suggested on another forum. NO more redirects. Thanks for your help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds