Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Another Google Redirection Problem/Virus [Solved]


  • This topic is locked This topic is locked

#1
TechnicallyImpaired

TechnicallyImpaired

    New Member

  • Member
  • Pip
  • 4 posts
Im very good with the internet, but Im terrible when it actually comes to working with computers.
So I have no idea what is going on. I tried to search online for answers, but I found that yahoo and google searches dont work at all!!! It always redirects me to some other site and my internet is painfully slow even though I have a very fast connection...

I have tried to update my windows..but it has failed
I have tried to download something to my computer...but it has failed
I have tried to do system restore...but it has failed
I have basically tried everything possible in the Malware and Spyware Cleaning Guide

Also, what is a good free mal ware software I can download???
My systematic antivirus has stopped working completely...
that is probably why I received this virus in the first place.

Please help me... :)

Edited by TechnicallyImpaired, 18 October 2009 - 12:44 AM.

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi could you run these two programmes so that I can see what you have

Please save this file to your desktop. Double-click on it to run a scan. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.

We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive.
  • Open Posted Image on your desktop.
  • Click the Posted Image tab.
  • Click the Posted Image button.
  • Check all seven boxes: Posted Image
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the Posted Image button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.

  • 0

#3
TechnicallyImpaired

TechnicallyImpaired

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Win32xDiag:

Running from: C:\Users\Aaron\Downloads\Win32kDiag.exe

Log file at : C:\Users\Aaron\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\Windows'...



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl




When I ran root repel I received an Error message:

RootRepel Error
FOPS - DeviceIoContro Error! Error Code = 0xc000024
Extended Info (0x000000d8)

Under details it says:

FOPS - DeviceIoContro Error! Error Code = 0xc000024 Extended Info (0x000000d8) 18:48
DeviceIoContro Error! Error Code =0x1e7 18:49
FOPS - DeviceIoContro Error! Error Code = 0xc000024 Extended Info (0x000000d8)18:49

And when I try to scan an Error Message also comes up:

Could not initialize driver! Pleas contact the author!

And then when I click ok for that error message another one popped up:

Error Dumping SSDT (0xc0000024)!

After this, the scanning progress bar lit up green for a second.
Then i tried to access report again and another error message popped up:


Attempt to read from address: 0x00000004

Then I clicked ok and another error message popped up:

DeviceIoControl Error! Code = 0x0


I also found this (saved as a notepad document) on my desktop:

ROOTREPEAL CRASH REPORT
-------------------------
Windows Version: Windows Vista SP0
Exception Code: 0xc0000005
Exception Address: 0x00422bf2
Attempt to read from address: 0x00000004

There are also two more things saved on my desktop (but these will not open):

RootRepeal.dmp
Settings.dat


What should I do? :)
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets run with a different programme

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • Reg - Shell Spawning
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on Posted Image to insert the attachment into your post

  • 0

#5
TechnicallyImpaired

TechnicallyImpaired

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
My dad heard that I had a virus.
He gave me IobitSecurity360 and he has fixed all my problems.
This program found several viruses on my comp and got rid of them in just two hours.

Thanks for all your help, but I think my computer is completely fixed. :)
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
If you are happy then it is not a problem :)
  • 0

#7
TechnicallyImpaired

TechnicallyImpaired

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Ok, thanks a bunch.
If I have another problem I will ask you again. :)
  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Any time - I will close this now
  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP