Iexplore/firefox redirect. Nothing finds it
#16
Posted 16 November 2011 - 09:54 PM
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8178
Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421
11/16/2011 9:49:32 PM
mbam-log-2011-11-16 (21-49-32).txt
Scan type: Quick scan
Objects scanned: 218556
Time elapsed: 3 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Roguekiller log:
RogueKiller V6.1.9 [11/16/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows Vista (6.0.6002 Service Pack 2) 64 bits version
Started in : Normal mode
User: Administrator [Admin rights]
Mode: Scan -- Date : 11/16/2011 21:51:24
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 4 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
[HJ] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[1].txt >>
RKreport[1].txt
I have a vista recovery CD.
#17
Posted 16 November 2011 - 09:59 PM
#18
Posted 17 November 2011 - 06:10 PM
This post has been edited by rob71: 17 November 2011 - 06:22 PM
#19
Posted 17 November 2011 - 06:45 PM
#20
Posted 18 November 2011 - 06:58 PM
In that topic above they cleaned the virus but the person that started helping and the one I think that got the virus is now in the banned groups. So not sure to follow along those lines or not...
This post has been edited by rob71: 18 November 2011 - 07:53 PM
#21
Posted 18 November 2011 - 08:50 PM
ok.time to take a deeper look:
*Download escan removal tool.it will download two files.
http://update1.mwti.net/akdlm/download/tools/mwav.exe
* To remove escan setup properly from your system just run esremove.exe .
*After unistallation complete you will get pop "eScan removed Sucessfully."
*After download completion,double click on saved file.
*The scan window will open,update if asked otherwise perform a full scan.
*IT will remove anything found automaticlly.
*Come back with results.
This post has been edited by shreyas1995: 03 August 2011 - 02:35 AM
That's what got it. Haven't done it yet. Antivir desktop is still on the computer and uninstallable as far as I can tell. Presently have no active anti-virus running. Downloaded SAS and it found 300 tracking cookies then rebooted. Running in depth SAS again now. He then suggested CCleaner and to use it on the registry. I'm not that computer literate but before this knew not to tread there if you didn't have too. Gonna read up on eScan while SuperAntiSpyware runs a thorough scan. Security says i can turn anti-vir desktop back on. after SAS finishes i'm going to do that and see if it returns to the program list. Can't find that much on eScan other than thier own blogs i may download Kaspersky virus removal tool and let it run. If anyone knows that eScan is really useful and not just a scanner. plus combofix is still on the desktop, not sure if either should be run with it still there. Still reading and SAS still running. SAS has found 39 more tracking cookies (I am still browsing) 2 game uninstall files it see's as trojans and 1 syswow64\drivers\ute40dq4.sys as a trojan. I will probably skip these unless I can find something about them as to not lock the system down.
This post has been edited by rob71: 18 November 2011 - 09:30 PM
#22
Posted 18 November 2011 - 09:46 PM
Lots, many svchosts chewing up some memory, startup only has SAS but services is full
This post has been edited by rob71: 18 November 2011 - 11:13 PM
#23
Posted 19 November 2011 - 11:28 AM
At this point we will no longer be able to assist you as you are receiving help from others along with making many changes on your own.
The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-

If I have helped you, consider making a donation to help me continue the fight against Malware!
Just click
#24
Posted 20 November 2011 - 08:32 AM
Kept posting all I did except running the eScan. Then ran Eset online scanner which came back clean. Ran TFC for temp folders. Had tons of games and programs that got removed so I ran CCleaner to help clean that up. Today I'm going to Update Windows, adobe and java. Although I had wondered Having removed so much and it being poorly maintained for so long if I should have just reformatted.
My wife sells on ebay and we keep our banking info on here so considering what virus we had I was determined to get it off ASAP. Learned allot off these forums. I'm going to read up on how remove the tools before I just throw them in the recyclebin. I thank you for the time you spent on it and hope you have a great weekend.
I will not be running AntiVir desktop again. The virus hid it and hacked it so that it wouldn't run. Could not re-install to get it to work and couldn't uninstall. Several download sites had downloads that didn't help, found one that had a control console that had options for install, repair and uninstall. It couldn't fix what the virus had done to get it to run but it was able to uninstall and remove it from the system. I wil try and find that site again and post that link but dummy me ran TFC so my history of where I got it is gone and I had tried several before getting that one.
This post has been edited by rob71: 20 November 2011 - 08:47 AM
#25
Posted 20 November 2011 - 08:33 AM
rob71, on 18 November 2011 - 09:46 PM, said:
Lots, many svchosts chewing up some memory, startup only has SAS but services is full. The svchosts are suppose to be there. Checked them all out and none seems to be running any questionable services.

Help


Back to top









