Author Topic: [In Active] Redirect searches  (Read 5545 times)

0 Members and 1 Guest are viewing this topic.

Offline cedarguy

  • Bronze Member
  • Posts: 40
Re: [In Progress] Redirect searches
« Reply #45 on: April 12, 2010, 03:10:36 PM »
k27, here's the log for file hrblretf.sys...cedarguy

VirSCAN.org Scanned Report :
Scanned time   : 2010/04/12 15:46:19 (CDT)
Scanner results: Scanners did not find malware!
File Name      : hrbl.nfo
File Size      : 6014628 byte
File Type      :
MD5            : e5de84e66f043d929790e2ee69023fac
SHA1           : 3e5b9215e334bfa62c78ac02f812ebf2a1c9a84d
Online report  : http://virscan.org/report/b35fe782c4aac8824caf6df7bfefa477.html

Scanner        Engine Ver      Sig Ver           Sig Date    Time   Scan result
a-squared      4.5.0.8         20100413043122    2010-04-13  0.08   -
AhnLab V3      2010.04.11.00   2010.04.11        2010-04-11  0.08   -
AntiVir        8.2.1.210       7.10.6.64         2010-04-12  0.25   -
Antiy          2.0.18          20100412.4183175  2010-04-12  0.02   -
Arcavir        2009            201004121326      2010-04-12  0.10   -
Authentium     5.1.1           201004121504      2010-04-12  1.31   -
AVAST!         4.7.4           100412-1          2010-04-12  0.24   -
AVG            8.5.720         271.1.1/2806      2010-04-12  0.23   -
BitDefender    7.81008.5613128 7.31178           2010-04-13  3.61   -
ClamAV         0.95.3          10730             2010-04-12  0.24   -
Comodo         3.13.579        4580              2010-04-12  0.08   -
CP Secure      1.3.0.5         2010.04.13        2010-04-13  0.27   -
Dr.Web         5.0.2.3300      2010.04.13        2010-04-13  6.52   -
F-Prot         4.4.4.56        20100412          2010-04-12  1.27   -
F-Secure       7.02.73807      2010.04.12.10     2010-04-12  10.70  -
Fortinet       4.0.14          11.689            2010-04-12  0.08   -
GData          19.10986/19.881 20100412          2010-04-12  0.08   -
ViRobot        20100412        2010.04.12        2010-04-12  0.08   -
Ikarus         T3.1.01.80      2010.04.12.75611  2010-04-12  5.67   -
JiangMin       13.0.900        2010.04.12        2010-04-12  0.08   -
Kaspersky      5.5.10          2010.04.11        2010-04-11  0.03   -
KingSoft       2009.2.5.15     2010.4.12.21      2010-04-12  0.08   -
McAfee         5400.1158       5945              2010-04-08  0.02   -
Microsoft      1.5605          2010.04.12        2010-04-12  0.08   -
Norman         6.04.11         6.04.00           2010-04-12  6.01   -
Panda          9.05.01         2010.04.12        2010-04-12  0.08   -
Trend Micro    9.120-1004      6.992.01          2010-04-12  0.02   -
Quick Heal     10.00           2010.04.12        2010-04-12  0.08   -
Rising         20.0            22.43.00.04       2010-04-12  0.08   -
Sophos         3.06.0          4.52              2010-04-13  3.43   -
Sunbelt        3.9.2412.2      6167              2010-04-12  0.08   -
Symantec       1.3.0.24        20100412.003      2010-04-12  0.13   -
nProtect       20100412.03     7941349           2010-04-12  0.08   -
The Hacker     6.5.2.0         v00259            2010-04-12  0.08   -
VBA32          3.12.12.4       20100408.2021     2010-04-08  2.79   -
VirusBuster    4.5.11.10       10.124.6/2045053  2010-04-12  2.51   -

Offline cedarguy

  • Bronze Member
  • Posts: 40
Re: [In Progress] Redirect searches
« Reply #46 on: April 12, 2010, 03:12:44 PM »
K27, here the logfile for ugwlqgve.sys...thanks - cedarguy

VirSCAN.org Scanned Report :
Scanned time   : 2010/04/12 16:02:55 (CDT)
Scanner results: Scanners did not find malware!
File Name      : ugw.nfo
File Size      : 1417170 byte
File Type      :
MD5            : 9c66cd87c4231dbe0124b0f95332c5eb
SHA1           : 0d9fea7e1d38e5080e49a4cc15e084c0e776cc19
Online report  : http://virscan.org/report/4696c39df9043f5c50bc234479ca3ebe.html

Scanner        Engine Ver      Sig Ver           Sig Date    Time   Scan result
a-squared      4.5.0.8         20100413043122    2010-04-13  0.08   -
AhnLab V3      2010.04.11.00   2010.04.11        2010-04-11  0.08   -
AntiVir        8.2.1.210       7.10.6.64         2010-04-12  0.26   -
Antiy          2.0.18          20100412.4183175  2010-04-12  0.02   -
Arcavir        2009            201004121326      2010-04-12  0.04   -
Authentium     5.1.1           201004121504      2010-04-12  1.33   -
AVAST!         4.7.4           100412-1          2010-04-12  0.07   -
AVG            8.5.720         271.1.1/2806      2010-04-12  0.23   -
BitDefender    7.81008.5613128 7.31178           2010-04-13  3.56   -
ClamAV         0.95.3          10730             2010-04-12  0.11   -
Comodo         3.13.579        4580              2010-04-12  0.08   -
CP Secure      1.3.0.5         2010.04.13        2010-04-13  0.07   -
Dr.Web         5.0.2.3300      2010.04.13        2010-04-13  6.57   -
F-Prot         4.4.4.56        20100412          2010-04-12  1.33   -
F-Secure       7.02.73807      2010.04.12.10     2010-04-12  0.32   -
Fortinet       4.0.14          11.689            2010-04-12  0.08   -
GData          19.10986/19.881 20100412          2010-04-12  0.08   -
ViRobot        20100412        2010.04.12        2010-04-12  0.09   -
Ikarus         T3.1.01.80      2010.04.12.75611  2010-04-12  5.67   -
JiangMin       13.0.900        2010.04.12        2010-04-12  0.08   -
Kaspersky      5.5.10          2010.04.11        2010-04-11  0.04   -
KingSoft       2009.2.5.15     2010.4.12.21      2010-04-12  0.08   -
McAfee         5400.1158       5945              2010-04-08  0.02   -
Microsoft      1.5605          2010.04.12        2010-04-12  0.08   -
Norman         6.04.11         6.04.00           2010-04-12  6.01   -
Panda          9.05.01         2010.04.12        2010-04-12  0.09   -
Trend Micro    9.120-1004      6.992.03          2010-04-12  0.02   -
Quick Heal     10.00           2010.04.12        2010-04-12  0.08   -
Rising         20.0            22.43.00.04       2010-04-12  0.08   -
Sophos         3.06.0          4.52              2010-04-13  3.38   -
Sunbelt        3.9.2412.2      6167              2010-04-12  0.08   -
Symantec       1.3.0.24        20100412.003      2010-04-12  0.07   -
nProtect       20100412.03     7941349           2010-04-12  0.08   -
The Hacker     6.5.2.0         v00259            2010-04-12  0.09   -
VBA32          3.12.12.4       20100408.2021     2010-04-08  2.81   -
VirusBuster    4.5.11.10       10.124.6/2045053  2010-04-12  2.40   -

Offline K27

  • Malware Removal Staff
  • Gold Member
  • Posts: 2342
    • Go Good IT Solutions
Re: [In Progress] Redirect searches
« Reply #47 on: April 12, 2010, 03:17:19 PM »
can you tel me where the files were if they were not in the c:\windows\system32\drivers\ folder
SpywareHammer - Knowledgebase

The internet is the new age battle of the old age clash between good and evil

Offline cedarguy

  • Bronze Member
  • Posts: 40
Re: [In Progress] Redirect searches
« Reply #48 on: April 12, 2010, 03:45:00 PM »
Right they were located here: \??\c:\windows\system32\drivers - cedarguy

Offline K27

  • Malware Removal Staff
  • Gold Member
  • Posts: 2342
    • Go Good IT Solutions
Re: [In Progress] Redirect searches
« Reply #49 on: April 12, 2010, 03:50:52 PM »
OK, please upload them from there.

Thanks
SpywareHammer - Knowledgebase

The internet is the new age battle of the old age clash between good and evil

Offline cedarguy

  • Bronze Member
  • Posts: 40
Re: [In Progress] Redirect searches
« Reply #50 on: April 12, 2010, 04:20:24 PM »
I don't know how to access those files from the Browse function on the virus scanner...cedarguy

Offline K27

  • Malware Removal Staff
  • Gold Member
  • Posts: 2342
    • Go Good IT Solutions
Re: [In Progress] Redirect searches
« Reply #51 on: April 12, 2010, 04:35:04 PM »
OK, please run an online scan with kaspersky, that will tell us if them drivers are malicious,

Please remember to disable all active protection before running the scan

Run an online virus scan called Kaspersky from HERE.
    1. At the main page. Press on "
Accept". After reading the contents.
2. At the next window Select  Update. Allow the Database to update.
Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run.
3. Once the Database has finished, under the Scan icon Select My Computer to start the scan. The scan may take a few minutes to complete.
4. Select Scan Report.
5. If any threats were found they will appear in the report
6. Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select text .txt
Save it to your Desktop.

Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.[/list]
SpywareHammer - Knowledgebase

The internet is the new age battle of the old age clash between good and evil

Offline cedarguy

  • Bronze Member
  • Posts: 40
Re: [In Progress] Redirect searches
« Reply #52 on: April 13, 2010, 05:21:40 PM »
K27, I had trouble getting Kaspersky to work right - I was trying it with IE8 and it was taking a very long time - looked like it would be 36-48 hours to do a full scan. Then IE8 crashed at one point. Kaspersky did flag a couple of files as being infected before it crashed.

I switched to Firefox and ran a Critical Area scan (that took 7 1/2 hours to complete). That scan came up clean, here's the log from that - (HTML file, which was what Kaspersky called for). I can try to run a complete scan but it looks like it might take 24 hours or more to run...cedarguy


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/1999/REC-html401-19991224/loose.dtd">

<html>
<head>
<title>KASPERSKY ONLINE SCANNER 7.0: scan report</title>
<meta http-equiv='Content-Type' content='text/html; charset=utf-8'>
<style type='text/css'>
   .pagetitle { font-size:20px; color:#FFFFFF; font-family: Arial, Geneva, sans-serif; }
   .text { font-size:11px; font-family: Arial, Geneva, sans-serif; }
   TD { font-size:11px; font-family: Arial, Geneva, sans-serif; }
</style>

</head>

<body>
   <table width='100%' border='0'>
      <tr align='center' bgcolor='#005447'>
         <td colspan='2' height='30px' class='pagetitle'>
            <b>KASPERSKY ONLINE SCANNER 7.0: scan report</b>
         </td>
      </tr>
      <tr>
         <td colspan='2' height='70px'>
            Tuesday, April 13, 2010<br>
            Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)<br>
            Kaspersky Online Scanner version: 7.0.26.13<br>
            Last database update: Tuesday, April 13, 2010 08:08:41<br>
            Records in database: 3938991<br>
         </td>
      </tr>
      <tr>
         <td colspan='2' height='10px'>
         </td>
      </tr>
   </table>
   <table width='100%' border='0'>
      <tr bgcolor='#EFEBDE'>
         <td colspan='2' height='20px'><b>Scan settings</b></td>
      </tr>
      <tr>
         <td height='15px' width='250px'>scan using the following database</td>
         <td>extended</td>
      </tr>
      <tr>
         <td height='15px'>Scan archives</td>
         <td>yes</td>
      </tr>
      <tr>
         <td height='15px'>Scan e-mail databases</td>
         <td>yes</td>
      </tr>
      <tr>
         <td colspan='2' height='10px'>
         </td>
      </tr>
      <tr bgcolor='#EFEBDE'>
         <td height='20px'><b>Scan area</b></td>
         <td>Critical areas</td>
      </tr>
      <tr>
         <td colspan='2' height='20px'>
            C:\Documents and Settings\All Users\Start Menu\Programs\Startup<br>
            C:\Documents and Settings\Doug Hovelson\Start Menu\Programs\Startup<br>
            C:\Program Files<br>
            C:\windows
         </td>
      </tr>
      <tr>
         <td colspan='2' height='10px'>
         </td>
      </tr>
      <tr bgcolor='#EFEBDE'>
         <td colspan='2' height='20px'><b>Scan statistics</b></td>
      </tr>
      <tr>
         <td height='15px'>Objects scanned</td>
         <td>129615</td>
      </tr>
      <tr>
         <td height='15px'>Threats found</td>
         <td>0</td>
      </tr>
      <tr>
         <td height='15px'>Infected objects found</td>
         <td>0</td>
      </tr>
      <tr>
         <td height='15px'>Suspicious objects found</td>
         <td>0</td>
      </tr>
      <tr>
         <td height='15px'>Scan duration</td>
         <td>07:14:31</td>
      </tr>
   </table>
   <br>
   <table width='100%%' border="0">
<tr><td colspan='3' height='20px'><b>No threats found. Scanned area is clean.</b></td></tr>
<tr><td colspan='3' height='20px'><b>
Selected area has been scanned.</td></tr></table>
</body>
</html>

Offline cedarguy

  • Bronze Member
  • Posts: 40
Re: [In Progress] Redirect searches
« Reply #53 on: April 13, 2010, 06:32:37 PM »
K27, okay, I'm running a full Kaspersky scan now - cedarguy

Offline cedarguy

  • Bronze Member
  • Posts: 40
Re: [In Progress] Redirect searches
« Reply #54 on: April 14, 2010, 12:20:07 PM »
K27, Firefox crashed while running Kaspersky scan - I got about 27% of the way through after 12 hours, no infections detected to that point. I will restart now. - thanks - cedarguy

Offline K27

  • Malware Removal Staff
  • Gold Member
  • Posts: 2342
    • Go Good IT Solutions
Re: [In Progress] Redirect searches
« Reply #55 on: April 14, 2010, 01:00:11 PM »
cedarguy,

There is no need to continue with the kapersky scan, I am happy that your machine is free from infection, please report back how your machine is running, we will do some housekeeping and then you should be good to go.

Let me know,

K27
SpywareHammer - Knowledgebase

The internet is the new age battle of the old age clash between good and evil

Offline K27

  • Malware Removal Staff
  • Gold Member
  • Posts: 2342
    • Go Good IT Solutions
Re: [In Progress] Redirect searches
« Reply #56 on: April 16, 2010, 11:22:22 PM »
cedarguy,

We have some important housekeeping to do before we finish this thread up, please post a fresh HJT log if you would to compleat the final stages of the cleanup.

Thanks,
K27
SpywareHammer - Knowledgebase

The internet is the new age battle of the old age clash between good and evil

Offline K27

  • Malware Removal Staff
  • Gold Member
  • Posts: 2342
    • Go Good IT Solutions
Re: [Inactive] Redirect searches
« Reply #57 on: April 19, 2010, 12:54:22 PM »
This Topic is Inactive......

If you are the originator of this Topic and would like it reopened please send Me, a Moderator or Admin a personal message and we will move it back.

The fixes in this topic were written specifically for this user, following them may cause harm to your machine and render it a brick (useless), Any one else needing help please go to this board http://spywarehammer.com/simplemachinesforum/index.php?board=10.0 and read all the pinned topic's and please follow the instructions in this topic http://spywarehammer.com/simplemachinesforum/index.php?topic=88.0
SpywareHammer - Knowledgebase

The internet is the new age battle of the old age clash between good and evil

Offline K27

  • Malware Removal Staff
  • Gold Member
  • Posts: 2342
    • Go Good IT Solutions
Re: [Inactive] Redirect searches
« Reply #58 on: April 20, 2010, 05:25:36 AM »
Topic Reopened at request from cedarguy:


cedarguy,

Please post a fresh HJT report and please let me know how your machine is now running, are you still being redirected?

Thanks,
K27
SpywareHammer - Knowledgebase

The internet is the new age battle of the old age clash between good and evil

Offline K27

  • Malware Removal Staff
  • Gold Member
  • Posts: 2342
    • Go Good IT Solutions
Re: [In Progress] Redirect searches
« Reply #59 on: April 25, 2010, 03:24:54 PM »
cedarguy,

As requested, this topic has been reopened, please advise if you would like it kept open, if I hear nothing by tomorrow,  I will move it back to the "Inactive Topics" board.

Thanks,
K27
SpywareHammer - Knowledgebase

The internet is the new age battle of the old age clash between good and evil