Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unknown malware... Internet browser redirects 75% of the time.


  • This topic is locked This topic is locked
2 replies to this topic

#1 Fallenchaos

Fallenchaos

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:21 AM

Posted 10 February 2011 - 09:06 AM

My internet browsers (Firefox, Google Chrome) Redirect me when I click on links and Malwarebytes can't find anything. I am also getting an error every 3-5 minutes saying "The instruction at "0x001a624b" reference memory at "0x00000000". The memory could not be "written"." The window that pops up with this message is titled "svchost.exe - Application Error.. Can someone help me??

Attached Files



BC AdBot (Login to Remove)

 


#2 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:11:21 AM

Posted 12 February 2011 - 03:04 PM

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


O1 - Hosts: 67.230.163.204 www.google.com
O1 - Hosts: 67.230.163.204 google.com
O1 - Hosts: 67.230.163.204 google.com.au
O1 - Hosts: 67.230.163.204 www.google.com.au
O1 - Hosts: 67.230.163.204 google.be
O1 - Hosts: 67.230.163.204 www.google.be
O1 - Hosts: 67.230.163.204 google.com.br
O1 - Hosts: 67.230.163.204 www.google.com.br
O1 - Hosts: 67.230.163.204 google.ca
O1 - Hosts: 67.230.163.204 www.google.ca
O1 - Hosts: 67.230.163.204 google.ch
O1 - Hosts: 67.230.163.204 www.google.ch
O1 - Hosts: 67.230.163.204 google.de
O1 - Hosts: 67.230.163.204 www.google.de
O1 - Hosts: 67.230.163.204 google.dk
O1 - Hosts: 67.230.163.204 www.google.dk
O1 - Hosts: 67.230.163.204 google.fr
O1 - Hosts: 67.230.163.204 www.google.fr
O1 - Hosts: 67.230.163.204 google.ie
O1 - Hosts: 67.230.163.204 www.google.ie
O1 - Hosts: 67.230.163.204 google.it
O1 - Hosts: 67.230.163.204 www.google.it
O1 - Hosts: 67.230.163.204 google.co.jp
O1 - Hosts: 67.230.163.204 www.google.co.jp
O1 - Hosts: 67.230.163.204 google.nl
O1 - Hosts: 67.230.163.204 www.google.nl
O1 - Hosts: 67.230.163.204 google.no
O1 - Hosts: 67.230.163.204 www.google.no
O1 - Hosts: 67.230.163.204 google.co.nz
O1 - Hosts: 67.230.163.204 www.google.co.nz
O1 - Hosts: 67.230.163.204 google.pl
O1 - Hosts: 67.230.163.204 www.google.pl
O1 - Hosts: 67.230.163.204 google.se
O1 - Hosts: 67.230.163.204 www.google.se
O1 - Hosts: 67.230.163.204 google.co.uk
O1 - Hosts: 67.230.163.204 www.google.co.uk
O1 - Hosts: 67.230.163.204 google.co.za
O1 - Hosts: 67.230.163.204 www.google.co.za
O1 - Hosts: 67.230.163.204 www.google-analytics.com
O1 - Hosts: 67.230.163.204 www.bing.com
O1 - Hosts: 67.230.163.204 search.yahoo.com
O1 - Hosts: 67.230.163.204 www.search.yahoo.com
O1 - Hosts: 67.230.163.204 uk.search.yahoo.com
O1 - Hosts: 67.230.163.204 ca.search.yahoo.com
O1 - Hosts: 67.230.163.204 de.search.yahoo.com
O1 - Hosts: 67.230.163.204 fr.search.yahoo.com
O1 - Hosts: 67.230.163.204 au.search.yahoo.com

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO, then use the following settings for a more complete scan.

    Posted Image
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#3 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:11:21 AM

Posted 19 February 2011 - 08:55 PM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users