BleepingComputer.com: Infection and Redirects

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

Infection and Redirects No Updates for Win7 or Antivirus Allowed+Redir

#31 User is offline   dbj15 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 22
  • Joined: 09-May 07

Posted 07 June 2011 - 03:12 PM

Hello Gringo.When I get to the "Choose a Recovery Tool" dialog menu,and select "startup repair"it finally stops and states "Start up Repair cannot repair this computer automatically".When you click finish it returns back to the System recovery options
choices.As none of the five options are of any value, all I can do is select Shut Down! David

#32 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,453
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 07 June 2011 - 05:41 PM

Hello David


I want you to boot into the recovery options again and this time select "command prompt"


go to this page and print it out or copy what you can - http://www.sevenforums.com/tutorials/139810-sfc-scannow-run-command-prompt-boot.html


on part 7 is what I want you to start


Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#33 User is offline   dbj15 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 22
  • Joined: 09-May 07

Posted 08 June 2011 - 01:50 AM

Hello again Gringo.I have run into a problem that I need your clarification on.On the Sevnforums link that you wanted me to start at number (7) at, it says that after opening the command window that to be sure to use your drive letter where in the demo his was F: and that the actual user drive probably will not be the same so he types sfc /scannow /offbootdir=f:\ /offwindir=f:windows. When I open my DOS box and find the cursor blinking,it opens at X:\windows\system32> So I typed sfc /scannow /offbootdir=x;\ /offwindir=x:\windows And got back a response of "The arguments passed to sfc are invalid. The offline windows directory specified points to the online system"! Also, is this "X" drive created for a ram drive for the repair utility? I am sure that my windows installation partition was created on the "C:" drive.David

This post has been edited by dbj15: 08 June 2011 - 01:51 AM


#34 User is offline   dbj15 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 22
  • Joined: 09-May 07

Posted 08 June 2011 - 04:53 AM

My last reply after the one that I asked for a clarification seems to have been lost! It also had an attachment of a zipped log file.I shall try to replicate it again here.I have found that the drive letter I needed to use in the scannow command is drive E: on the sick computer.I ran the command and waited until it finished. It came back with the following."Beginning system scan. This process will take some time.Windows Resource Protection found corrupt files but was unable to fix some of them.Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log I then zipped the CBS.log file as it was quite large and I am attaching it here.DavidAttached File  CBSlog.zip (105.63K)
Number of downloads: 2

#35 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,453
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 08 June 2011 - 08:06 AM

Please download Kaspersky Virus Removal Tool and SAVE it to your desktop

  • Right click and run as admin (xp please double click to run)

  • select lang

  • click on next

  • accept the license aggreement

  • select location and click on next

  • in autoscan make sure the first three boxes are checked and the box next to the C:/ drive

  • click on start scan

  • when complete click on report

  • in the three drop down boxes choose autoscan - do not group and important events

  • click on save and save to desktop

  • copy and paste this report in your next post

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#36 User is offline   dbj15 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 22
  • Joined: 09-May 07

Posted 09 June 2011 - 01:25 AM

Hello Gringo.I have to ask regarding your last reply to me as to whether you recall that my sick computer condition is stuck at a Blue screen that momentarily appears just long enough to tell me that it is being shut down to avoid damage! As there is no desktop available to me,how would I make use of the Kaspersky Virus Removal Tool and configure it unless there is some way to do so using the xpud system tool? Let me know when you next get a chance please.David 6-8-11 11:24PM

#37 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,453
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 09 June 2011 - 01:16 PM

sorry about that


going thru that CBS.log it indicates that explorer still does not pass and that is the only thing I can think of

we keep replacing it but it is not helping - the best thing I can think of is to use the usb to remove anything you want to keep and reinstall windows


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#38 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,453
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 12 June 2011 - 02:06 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

Share this topic:


  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users