Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Redirect virus + problems downloading software
   
BullGuard Antivirus Forum > Bullguard zone > BullGuard Trial users > Redirect virus + problems downloading software  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : Redirect virus + problems downloading software
[ << Previous Thread | Next Thread >> ]

Kaz
New Member


Date Joined Aug 2008
Total Posts : 7
 
   Posted 8-27-2008 7:21 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
I'm hoping you can help me as you have helped others with similar problems.
 
My problems are:
- clicking on google links redirects me to either other random sites (most often lesser known search engines) or I get IE cannot display webpage message
- can get to some websites (i.e. yours) by typing in URL but cannot access others (i.e. www.bleepingcomputer.com). Again get IE cannot display webpage message (annoyingly this also happened the first time I posted this log & I am now having to use a different pc)
- unable to download software i.e. CCleaner, SuperAntispyware, Malwarebytes' Anti Malware - get either IE cannot display webpage error or .exe is not a valid win32 application error
 
I am running XP SP2 but do not have the latest security updates due to the 3rd reason above.
 
I also got infected with Antivirus XP 2008 and removed it manually using instructions provided elsewhere (incl reg settings). I originally thought this was what was causing the other problems but it appears not! The same problems were occurring before I manually removed Antivirus XP 2008.
 
I have a Hosts file which I originally got from MVPS & this looks ok.
 
Here's my HijackThis log - are you able to help or am I beyond it??
 
Logfile of HijackThis v1.99.1
Scan saved at 17:49:21, on 27/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\blueyonder\PCguard\fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ActivCard\acautoreg.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Napster\napster.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\Program Files\Microsoft Money\System\reminder.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ig?hl=en
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\blueyonder\PCguard\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\blueyonder\PCguard\FBHR.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [msserv] C:\WINDOWS\System32\lvsrev.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QuickPassword] C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O15 - Trusted Zone: http://www.croatianholiday.co.uk
O16 - DPF: {0089F6EE-ED54-11D5-B0E7-00508B014C1D} (ExWebClientUtils Class) - http://exweb.exchange.uk.com/clientbinaries/texInfo.CAB
O16 - DPF: {034DA761-EDB7-11D7-A20A-000802318089} (EWGPHI.desInput) - http://exweb.exchange.uk.com/clientbinaries/EWGPHI.CAB
O16 - DPF: {090EC279-1378-44B7-B521-888980212E7E} (Complist3 Class) - http://exweb.exchange.uk.com/clientbinaries/eXwebCListCtl3.CAB
O16 - DPF: {0F026C11-5A66-4C2B-87B5-88DDEBAE72A1} (ComponentOne FlexGrid 8.0 (Light)) - https://www.aequosonline.com/aqolwebv2/activex/vsflex8l.ocx
O16 - DPF: {0FA8E95B-C23A-11D5-8F5F-0008C7E9C2C6} (Pensions.desInput) - http://exweb.exchange.uk.com/clientbinaries/PensionsPhase2.CAB
O16 - DPF: {2F6A847E-2EC2-11D3-AE1B-00508B014C1D} (Parser Class) - http://exweb.exchange.uk.com/clientbinaries/XMLParser.CAB
O16 - DPF: {397F65A6-FD3C-438B-A7EB-3D2C0655189C} (EWGPensions.desInput) - http://exweb.exchange.uk.com/clientbinaries/EWGPensions.CAB
O16 - DPF: {511835FF-EDC9-11D7-A20A-000802318089} (EWGWholeLife.desInput) - http://exweb.exchange.uk.com/clientbinaries/EWGWholeLife.CAB
O16 - DPF: {59A910DE-EE9A-11D7-A20A-000802318089} (EWGCombinedTerm.desInput) - http://exweb.exchange.uk.com/clientbinaries/EWGTermAssurance.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152298804828
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153336022984
O16 - DPF: {7B5A1CB7-2E01-11D7-90C1-0008C7E9C2C6} (PHI.desInput) - http://exweb.exchange.uk.com/clientbinaries/PHI.CAB
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://exweb.exchange.uk.com/clientbinaries/msxml4.CAB
O16 - DPF: {8E95B0CA-EB6F-11D3-979B-00508B64538B} (VersionInfo.clsVersionInfo) - http://exweb.exchange.uk.com/clientbinaries/VersionInfo.CAB
O16 - DPF: {91F82BFF-F70C-11D2-BB68-0008C7E9C2C6} (TEXNBSHELL.ProposalForm) - http://exweb.exchange.uk.com/texonline/core_services/new_business_processing/texnbshell.cab
O16 - DPF: {A32DBCA3-4BFD-11D3-B9E4-008048FCE443} (Complist Class) - file://D:\CAB\eXwebCListCtl.cab
O16 - DPF: {A74D724A-AB17-11D2-A96A-006097E20477} (eXwebUtils.HTMLUtils) - http://exweb.exchange.uk.com/clientbinaries/eXwebUtils.CAB
O16 - DPF: {A98277A1-A141-11D5-98B9-00508B64538B} (Complist2 Class) - http://exweb.exchange.uk.com/clientbinaries/eXwebCListCtl2.CAB
O16 - DPF: {A9F86998-BB62-11D2-A988-006097E20477} (eXwebUtils.clsVersionInfo) - file://D:\CAB\eXwebUtils.cab
O16 - DPF: {A9F869B2-BB62-11D2-A988-006097E20477} (eXwebOccList.clsVersionInfo) - file://D:\CAB\eXwebOcc.cab
O16 - DPF: {A9F869C0-BB62-11D2-A988-006097E20477} (PHIHelpText.clsVersionInfo) - file://D:\CAB\PHIHelpText.cab
O16 - DPF: {A9F869CE-BB62-11D2-A988-006097E20477} (PHIToolTips.clsVersionInfo) - file://D:\CAB\PHIToolTips.cab
O16 - DPF: {AB5ED3AE-DE26-11D3-AD7A-0050044495F0} (WholeLife.clsVersionInfo) - file://D:\CAB\wholelife.cab
O16 - DPF: {AB5ED422-DE26-11D3-AD7A-0050044495F0} (WholeLife.desWOLBlank) - http://exweb.exchange.uk.com/clientbinaries/WholeLife.CAB
O16 - DPF: {ABF92614-EBA5-11D3-A315-006008134E84} (Annuities.dsrMain) - http://exweb.exchange.uk.com/clientbinaries/ann_GD.CAB
O16 - DPF: {B539A417-0C5E-11D4-97CF-00508B64538B} (Bonds.GLBI030) - file://D:\CAB\Bonds.cab
O16 - DPF: {B5805B24-2D86-11D0-ADA6-00400520799C} (ProtoView Calendar Control) - file://D:\CAB\pvcalctl.cab
O16 - DPF: {B6C10489-FB89-11D4-93C9-006008A7EED4} (TeeChart Pro Activex control v5) - https://www.aequosonline.com/aqolwebv2/activex/TeeChart5.ocx
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - https://www.telewest.co.uk/motive/files/MotivePreQual.cab
O16 - DPF: {CC696B63-4159-11D0-BDCB-0020A90B183A} (Infragistics Date Edit Control) - file://D:\CAB\pvdate2.cab
O16 - DPF: {DB1F089D-F410-11D3-A316-006008134E84} (CombinedTerm.desInput) - http://exweb.exchange.uk.com/clientbinaries/TermAssurance.CAB
O16 - DPF: {DB1F08C5-F410-11D3-A316-006008134E84} (CombinedTerm.desUserDefaultsGrid) - file://D:\CAB\TermAssurance.cab
O16 - DPF: {DBA9E4A1-885A-11D3-8919-0050049D81F4} (TexPHIDS.dsrPHIInput) - file://D:\CAB\TexPHIDS.cab
O16 - DPF: {DDECE2F5-AF1F-44E7-B37F-96B6630F5C60} (PrintComponent.clsVersionInfo) - http://exweb.exchange.uk.com/clientbinaries/printdll.CAB
O16 - DPF: {E5CFA957-1CD1-11D2-85AD-006097B42E68} (TEXCList.ctlCompanyList) - file://D:\CAB\eXwebCList.cab
O16 - DPF: {E7FF5332-854E-11D2-A952-006097E20477} (eXwebOccList.clsOccRes) - http://exweb.exchange.uk.com/clientbinaries/eXwebOcc.CAB
O16 - DPF: {E9C9692E-F93C-11D1-ABB0-0040054FC6FB} (ProtoView DataTable Control 7.0 (OLEDB)) - file://D:\CAB\pvdt70.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ActivCard Gold Autoregister (acautoreg) - ActivCard S.A. - C:\Program Files\Common Files\ActivCard\acautoreg.exe
O23 - Service: ActivCard Gold service (Accoca) - ActivCard - C:\Program Files\Common Files\ActivCard\accoca.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\blueyonder\PCguard\fws.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
 
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13861
 
   Posted 8-29-2008 5:23 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Hello smile
 
 
Run a scan with HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):
O4 - HKLM\..\Run: [msserv] C:\WINDOWS\System32\lvsrev.exe
 
 
Reboot to safe mode:
 
 
SHOW HIDDEN FILES 
1. Click Start button, then go to Programs, Accessories and click on Windows Explorer.
2. Select the Tools menu and click Folder Options.
3. Select the View Tab.
4. Under the "Hidden files and folders" heading please check Show hidden files and folders.
5. Uncheck the Hide protected operating system files (Recommended) option.
6. Click Yes to confirm.
7. Click OK.
 
 Delete these files:

C:\WINDOWS\System32\lvsrev.exe
C:\Windows\System32\drivers\InvisibleDrvNT.sys
 
Reboot normally, post new hijackthis log and tell how things are running ?


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Post Edited (Touch) : 29-08-2008 04:50:49 GMT

Back to Top
 

Kaz
New Member


Date Joined Aug 2008
Total Posts : 7
 
   Posted 8-30-2008 8:15 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Thanks for your help.
 
I have followed your instructions but don't have an lvsrev.exe file appearing either in HijackThis or C:\WINDOWS\System32. I don't have an InvisibleDrvNT.sys file in the drivers folder either.
 
I do however have a xx_lvsrev.exe file in the System32 folder.
There are also xx_apigrab.dll and xx_wartsvr.exe
 
Shall I get rid of some/all of these?
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13861
 
   Posted 8-30-2008 8:55 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Ok. There are probably more infected files, I´ll therefore suggest you run ->
 
Run Kaspersky WebScanner
  • Please go here: http://www.kaspersky.com/virusscanner
  • and click Kaspersky Online Scanner
  • Read and Accept the Agreement
  • You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • If you see a Windows dialog asking if you want to install this software, click the Install button.
  • The program will launch and then begin downloading the latest definition files,
  • When the "Update progress" line changes to "Ready" and the "NEXT ->" button becomes available, please click on it.
  • Click on the Scan Settings button, and in the next window select the Extended database, and click Ok.
  • Under "Please select a target to scan:", click My Computer to start the scan.


  • When the scan is finished, click the "Save as Text" button, and save the file as kavscan.txt to your Desktop, close the Kaspersky On-line Scanner window.
  • Paste kaspersky log in next reply.


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

Kaz
New Member


Date Joined Aug 2008
Total Posts : 7
 
   Posted 8-30-2008 12:27 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Unfortunately virus(es) I have prevent me from downloading software from the internet. If I use your link I get IE cannot display webpage error.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13861
 
   Posted 8-31-2008 5:09 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Ok. I´ve found a new link for Malwarebyte, see if you can download it from there ->
 
 
Please download Malwarebytes' Anti-Malware:
 
 to your desktop.
 
Double-click mbam-setup.exe and follow the prompts to install the program.
                     
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch


Malwarebytes' Anti-Malware, then click Finish.
                     
If an update is found, it will download and install the latest version.
                     
Once the program has loaded, select Perform full scan, then click Scan.
                     
When the scan is complete, click OK, then Show Results to view the results.
 
Be sure that everything is checked, and click Remove Selected.
 
When completed, a log will open in Notepad. Please save it to a convenient location.
 
Copy and Paste that log into your next reply, along with fresh hijackthis log.
 
 
NB: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

Kaz
New Member


Date Joined Aug 2008
Total Posts : 7
 
   Posted 8-31-2008 9:44 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Cannot download from here either. Same problem: IE cannot display webpage.

Shall I try removing the files (& any registry settings) for the original stuff I found & see what happens?
(xx_lvsrev.exe file in the System32 folder & also xx_apigrab.dll and xx_wartsvr.exe)

Let me know what you think.
Thanks
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13861
 
   Posted 8-31-2008 11:20 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Yes, try to delete the files. You´ll probably have to do it from safe mode. If you can´t delete them, then see if they can be renamed to - filename.old.
 
Reboot.
You should be able to download malwarebyte from her:
Click on Download now



Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

Kaz
New Member


Date Joined Aug 2008
Total Posts : 7
 
   Posted 8-31-2008 2:50 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Deleted files ok but made no difference. Have rebooted pc. Can see the Malawarebytes site & able to save the exe to my c:\ but when I try to run the setup exe I get an 'exe is not a valid win32 application' error. Same thing happens if I try to run it from the website.

Can you think of anything else I could try before I try re-installing XP?
Thanks again

(By the way I checked Winsock and that seems to be ok)
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13861
 
   Posted 8-31-2008 4:36 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
I have two more things you can try. Rename Malwarebytes' Anti-Malware to Malwarebytes' Anti-Malware.bat
 
 
See if you can run it now. The other thing, have you tried a systemrestore ?


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

Kaz
New Member


Date Joined Aug 2008
Total Posts : 7
 
   Posted 8-31-2008 6:00 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
That didn't work either.
Can't do a system restore as can't restore to anything before the current month & have been on holiday for most of Aug so no decent points to restore back to.

I'll leave it a couple of days before I re-install XP so let me know if you have any other suggestions.
Thanks for all your help
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13861
 
   Posted 9-1-2008 4:08 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Ok. It looks like you´ve got a bagle- infection.
 
 
 and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
 and save it to your desktop.

When you have done this, please boot into Safe Mode (Tap F8 during startup).

Open the extracted folder  - C:\ SDFix  and doubleclick on RunThis.bat to start the script.

Type Y to begin the script. It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot. When you hit any key, your computer will reboot. Your system will take longer that normal to restart as the fixtool will be running and removing files.

When your desktop loads, the utility will complete the removal and display Finished. Press any key again to end the script and load your desktop icons.
 
 
Open the SDFix folder on your desktop and copy and paste the contents of Report.txt 
 
Otherwise Download RootRepeal ->
 
 
Follow the instructions and post the log it produce
 
 


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

Kaz
New Member


Date Joined Aug 2008
Total Posts : 7
 
   Posted 9-2-2008 7:24 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
Don't suppose any of this comes with any manual instructions as I cannot run anything downloaded from the internet (not win32 application error)?

Also, I do not have the right software to unpack the rootrepeal.rar file & I cannot download software from the internet etc etc!
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13861
 
   Posted 9-3-2008 4:45 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
It don´t look to good rolleyes
 
 
See if you get the - not win32 application error
  - when you will run one of these ->
 
 
 
 
 
If you can, I´ll give you instructions in next reply.


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

stacksofamber
New Member


Date Joined Sep 2008
Total Posts : 1
 
   Posted 9-9-2008 6:14 (GMT +1)    Quote: Redirect virus + problems downloading softwareAlert an admin about: Redirect virus + problems downloading software
 
I'm having the exact same problems as Kaz.  However, for some reason, now when I went to the site you gave below (under safe mode), I receive an error box that says "The setup files are corrupted.  Please obtain a new copy of the program."  I used to receive the same messages as Kaz.  Do you have any ideas for me?  I'm really going nuts here.
Touch said...
Ok. I´ve found a new link for Malwarebyte, see if you can download it from there ->
 
 
Please download Malwarebytes' Anti-Malware:
 
 to your desktop.
 
Double-click mbam-setup.exe and follow the prompts to install the program.
                     
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch


Malwarebytes' Anti-Malware, then click Finish.
                     
If an update is found, it will download and install the latest version.
                     
Once the program has loaded, select Perform full scan, then click Scan.
                     
When the scan is complete, click OK, then Show Results to view the results.
 
Be sure that everything is checked, and click Remove Selected.
 
When completed, a log will open in Notepad. Please save it to a convenient location.
 
Copy and Paste that log into your next reply, along with fresh hijackthis log.
 
 
NB: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Back to Top
 
New Topic Locked Topic Printable version of : Redirect virus + problems downloading software
 
Forum Information
Currently it is Thursday, December 04, 2008 8:19 PM (GMT +1)
There are a total of 64.634 posts in 15.923 threads.
In the last 3 days there were 21 new threads and 135 reply posts. View Active Threads
Who's Online
This forum has 27355 registered members. Please welcome our newest member, bigstu.
49 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Virtrigger removal (27)04-12-2008 19:02:53 (JHT)
About a worm "recycled/boot.com" (0)04-12-2008 18:27:11 (Wello)
Vundo. BG & Generic 10.AMUY Trojan Horse...How do I get rid of them? (6)04-12-2008 17:25:37 (arusell)
Used MBAM to remove Virtrigger... But (2)04-12-2008 17:24:19 (Churrosgomoo)
Command Service (10)04-12-2008 17:21:11 (yogendra)