Forum Home |  MWR University |  New to the Board? |  IRC Chatroom |  Who Runs This Site? |  ASAP Members |  Microsoft MVP Members |  Downloads |  Good & Bad P2P Programs |  Our Rules

MalWare Removal Forum

Malware Removal University - Teaching people how to support those with infected computers - Teaching them to never give up untill your computer is clean and secure.

Tutorials (etc.) : Boot to Safe Mode - Safely - What to do if your Computer's running slowly
It is currently Thu 23 May, 2013 9:50 pm

All times are UTC [ DST ]


Forum rules


Please read > >THIS ANNOUNCEMENT< < before posting your NEW topic about your problem.

Please do NOT reply to your topic until a staff member has responded as they are looking for topics that have ZERO replies.

Paste your logs into your post. DO NOT USE ATTACHMENTS! Logs posted as attachments will be ignored and the topic will be closed.

If no expert has replied after 3 days, and you still require assistance, please post in our 72 hour bump room > > CLICK HERE < < Please do NOT reply to your own topic in an attempt to "bump" it. Bumped topics will be closed, requiring you to start again from the beginning.

If you are being helped and you haven't replied to your helper within 3 days of their last post, your topic will be closed as inactive. If that happens, you will need to start a new topic when you have the time available to promptly complete all instructions.

If your topic has been closed due to inactivity, do NOT request that your topic be reopened - we do NOT reopen topics unless they have been closed in error - you will need to start a NEW topic with NEW DDS logs. Do NOT attempt to start a new topic with a post that is essentially a reply to your closed topic.



Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 42 posts ]  Go to page Previous  1, 2, 3  Next
Author Message
 Post subject: Re: Google search redirected
New postPosted: Tue 07 Feb, 2012 3:24 pm 
Offline
Regular Member

Joined: Wed 25 Jan, 2012 12:00 am
Posts: 20
http://virusscan.jotti.org/en/scanresul ... 99124773d4

Top
 Profile E-mail  
 
 Post subject: Re: Google search redirected
New postPosted: Tue 07 Feb, 2012 11:39 pm 
Offline
Regular Member

Joined: Wed 25 Jan, 2012 12:00 am
Posts: 20
says ext sys not allowed
_________________


Top
 Profile E-mail  
 
 Post subject: Re: Google search redirected
New postPosted: Wed 08 Feb, 2012 12:39 am 
Offline
Regular Member

Joined: Wed 25 Jan, 2012 12:00 am
Posts: 20
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-07 15:30:00
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 FUJITSU_MHV2100BH_PL rev.00000029
Running: 4vi5131v.exe; Driver: C:\DOCUME~1\Bill\LOCALS~1\Temp\pwrdyfog.sys


---- System - GMER 1.0.15 ----

SSDT 89033720 ZwCreateKey
SSDT 88EE54A0 ZwCreateMutant
SSDT 89032520 ZwCreateProcess
SSDT 89032820 ZwCreateProcessEx
SSDT 88EE5860 ZwCreateSymbolicLinkObject
SSDT 89034FC0 ZwCreateThread
SSDT 89033D20 ZwDeleteKey
SSDT 89034620 ZwDeleteValueKey
SSDT 88EE5A40 ZwDuplicateObject
SSDT 88EE51A0 ZwLoadDriver
SSDT 89032B20 ZwOpenProcess
SSDT 89034C00 ZwOpenSection
SSDT 89032E20 ZwOpenThread
SSDT 89034020 ZwRenameKey
SSDT 89034320 ZwRestoreKey
SSDT 88EE5680 ZwSetSystemInformation
SSDT 89033A20 ZwSetValueKey
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xA84C0640]
SSDT 89033420 ZwTerminateThread
SSDT 89034DE0 ZwWriteVirtualMemory

Code \??\C:\DOCUME~1\Bill\LOCALS~1\Temp\catchme.sys pIofCallDriver

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Udfs \UdfsCdRom DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\meiudf \MeiUDF_Disk DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\meiudf \MeiUDF_CdRom DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Udfs \UdfsDisk DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

AttachedDevice \Driver\Tcpip \Device\Ip tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

---- EOF - GMER 1.0.15 ----
don't use aol or view point

Top
 Profile E-mail  
 
 Post subject: Re: Google search redirected
New postPosted: Wed 08 Feb, 2012 12:41 am 
Offline
Regular Member

Joined: Wed 25 Jan, 2012 12:00 am
Posts: 20
otl wont complete window pops up that says list of index out of bounds (487)

OTL stalls when trying to scan google chrome

Thanks, OTC
_________________


Top
 Profile E-mail  
 
 Post subject: Re: Google search redirected
New postPosted: Wed 08 Feb, 2012 12:08 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Fri 18 Feb, 2005 2:14 am
Posts: 8817
Location: Jerusalem
Quote:
says ext sys not allowed

Sorry but I do not understand what you mean. Please explain.

I am doing some research to find out what is stopping OTL. Please be patient. :)

Top
 Profile  
 
 Post subject: Re: Google search redirected
New postPosted: Wed 08 Feb, 2012 12:34 pm 
Offline
Regular Member

Joined: Wed 25 Jan, 2012 12:00 am
Posts: 20
when program was going through the "scan Modules" window pops up> use of index out of bounds (487)

Re: OTL the program was scanning at the bottom of screen you can see what is being scanned,when google chrome started the whole process stopped.

Also the redirection issue has stopped

Thanks

Top
 Profile E-mail  
 
 Post subject: Re: Google search redirected
New postPosted: Wed 08 Feb, 2012 5:46 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Fri 18 Feb, 2005 2:14 am
Posts: 8817
Location: Jerusalem
Please try the following:

Reboot the computer into Safe Mode and try to run OTL in this mode.

If you do not know how to start the computer in safe mode let me know and I will give you instructions. :)

Top
 Profile  
 
 Post subject: Re: Google search redirected
New postPosted: Thu 09 Feb, 2012 11:38 pm 
Offline
Regular Member

Joined: Wed 25 Jan, 2012 12:00 am
Posts: 20
Tried in safe mode the same thing happened. Scans some files and then stall scanning chrome.

Thanks, Bill

Top
 Profile E-mail  
 
 Post subject: Re: Google search redirected
New postPosted: Fri 10 Feb, 2012 4:49 am 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Fri 18 Feb, 2005 2:14 am
Posts: 8817
Location: Jerusalem
Let's check the version of OTL that you are trying to run.

When you open the OTL what is the version that you see at the top of the page. It starts with
OTL by OldTimer and then says Version. It should show 3.2.31.0
If it does not then delete the version of OTL that you have and download the latest version from url=http://oldtimer.geekstogo.com/OTL.exe and run it.

Please tell me if you used the latest version and if not please post the OTL log that you get.

An older version of OTL behaved exactly as you describe its behaviour on your computer.

Top
 Profile  
 
 Post subject: Re: Google search redirected
New postPosted: Fri 10 Feb, 2012 12:03 pm 
Offline
Regular Member

Joined: Wed 25 Jan, 2012 12:00 am
Posts: 20
The OTL is the latest version.

Thanks, Bill

Top
 Profile E-mail  
 
 Post subject: Re: Google search redirected
New postPosted: Fri 10 Feb, 2012 1:39 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Fri 18 Feb, 2005 2:14 am
Posts: 8817
Location: Jerusalem
Let's try the following:

Disable SUPERAntiSpyware
Programs like SUPERAntiSpyware, may interfere with the fix, so we need to temporarily disable it.
  • Right-click on the SUPERAntiSpyware icon, in the system tray.
  • Choose View Control Center... "Preferences/options" button/tab.
  • On the General and Startup...tab, uncheck, "Start SUPERAntiSpyware when Windows starts"
  • click Close to exit.
Don't forget to enable your SUPERAntiSpyware protection, when your computer is clean.

Now try the OTL again.

Sorry about the many tries to get OTL to run, but it is very disturbing that OTL does not run as expected. We are testing all the simpler solutions before getting to some more coplicated ones that will check the memory of the computer.

Please note that I will be off line an hour from now until about 27 hours from then.

Top
 Profile  
 
 Post subject: Re: Google search redirected
New postPosted: Fri 10 Feb, 2012 1:52 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Fri 18 Feb, 2005 2:14 am
Posts: 8817
Location: Jerusalem
Disregard the last post and try the following instead.

OTS
Please download OTS.exe... by OldTimer. Save it to your desktop.
  1. Double click on OTSc.exe to run it.
    If you recieve the "Open File - Security Warning" prompt, press "Run".
  2. Click on Run Scan at the top left hand corner. It may take a few minutes...be patient, let it run.
  3. When done, Notepad will open with the log file "OTS.txt" contents. File can be found on your desktop.
Please post the entire OTS.txt file contents, in your next reply.

Top
 Profile  
 
 Post subject: Re: Google search redirected
New postPosted: Tue 14 Feb, 2012 1:40 am 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Fri 18 Feb, 2005 2:14 am
Posts: 8817
Location: Jerusalem
If I don't hear from you within the next 24 hours I am sorry but I will have to close the topic.

Top
 Profile  
 
 Post subject: Re: Google search redirected
New postPosted: Tue 14 Feb, 2012 3:32 pm 
Offline
Regular Member

Joined: Wed 25 Jan, 2012 12:00 am
Posts: 20
Trendmicro keeps removing the OTS download

Thanks, Bill

Top
 Profile E-mail  
 
 Post subject: Re: Google search redirected
New postPosted: Tue 14 Feb, 2012 5:51 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Fri 18 Feb, 2005 2:14 am
Posts: 8817
Location: Jerusalem
Can you disable trend Micro for the time it takes to download the OTS and run it. Don't forget to reenable it again once it is done.

Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 42 posts ]  Go to page Previous  1, 2, 3  Next

All times are UTC [ DST ]


Who is online

Users browsing this forum: doby108 and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.

Member site: Alliance of Security Analysis Professionals | UNITE Against Malware

Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group