Author Topic: Very stealthy redirect  (Read 17074 times)

0 Members and 1 Guest are viewing this topic.

FrankW

  • Guest
Very stealthy redirect
« on: August 02, 2011, 01:15:36 AM »
Have run at least a dozen antivirus tools (mbam, anvir, avg, gmer, blacklight, drweb, sophos, HMP, ESET, combofix, TDSSKiller etc) and can't seem to shake the google redirect. Also deleted/ reinstalled Firefox, removed Java, cleared temp files and web cache, ran fixboot and fixmbr.

A number of viruses have been cleared including Hiloti, Java/Agent.U, TR/Fakealert.47.308(found in a .jar file), TR/Dldr.Murlo.laz

Current symptoms: Google searches are redirecting.

Not sure what to do next. Any help would be greatly appreciated.
« Last Edit: August 02, 2011, 01:18:52 AM by FrankW »

FrankW

  • Guest
Re: Very stealthy redirect
« Reply #1 on: August 02, 2011, 08:52:34 AM »
Previously I ran GMER and TDSSKiller without picking up any error. When I twice tried to run Combofix (including safe mode) the system appeared to hang for >1 hour so I rebooted.

However I may be starting to get somewhere: Just tried GMER again and got a BSOD in atapi.sys. I've read that file is sometimes targetted by google redirect viruses.

Will have a crack at running SFC /SCANNOW then try GMER again and report back.

FrankW

  • Guest
Re: Very stealthy redirect
« Reply #2 on: August 02, 2011, 09:52:30 AM »
SFC /SCANNOW prompted for the install cd about a dozen times so I guess it replace that many files. Whether the virus was able to overcome this I don't know.

follow advice given via a link in my last comment pls.

The instructions in that link are for Kaspersky Virus Removal Tool version 10. The latest on the website is V11 which has a very different interface. Do you suggest selecting "automatic scan" or "Manual Disinfection."?

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48805
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Very stealthy redirect
« Reply #3 on: August 02, 2011, 11:21:11 AM »
shreyas murali,

Some of the programs you're asking customers to use can be dangerous in the wrong hands.

What are your qualifications ???
Where did you get your training ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

shreyas murali

  • Guest
Re: Very stealthy redirect
« Reply #4 on: August 02, 2011, 11:22:50 AM »
well,

before joining the malware removal team at systematics we were first trained to deal with malware cases remotely and also at hand irrespective of our knowledge. ;D 8)

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48805
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Very stealthy redirect
« Reply #5 on: August 02, 2011, 11:27:01 AM »
well,

before joining the malware removal team at systematics we were first trained to deal with malware cases remotely and also at hand irrespective of our knowledge. ;D 8)
Who is "we" ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

shreyas murali

  • Guest
Re: Very stealthy redirect
« Reply #6 on: August 02, 2011, 11:28:57 AM »
we.....are the people who came to join systematics.... 8)

systematics is a workshop for virus removal,hardware problems,software problems,computer repairs etc.....where i work on the malware removal team. 8)
« Last Edit: August 02, 2011, 11:32:32 AM by shreyas murali »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48805
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Very stealthy redirect
« Reply #7 on: August 02, 2011, 11:38:03 AM »
You are talking in generalities how about some specifics.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

shreyas murali

  • Guest
Re: Very stealthy redirect
« Reply #8 on: August 02, 2011, 11:40:23 AM »
this is not in general.....at systematics u are trained individually and given personal attention...they then allow us to guide people remotely under supervision at training.... ;)

The training is a session of hardwork of 3 to 4 months...u will have to slog to join systematics... :)
« Last Edit: August 02, 2011, 11:43:13 AM by shreyas murali »

Offline CraigB

  • Avast Überevangelist
  • Serious Graphoman
  • *****
  • Posts: 11256
  • No support PM's thanks
Re: Very stealthy redirect
« Reply #9 on: August 02, 2011, 12:51:50 PM »
this is not in general.....at systematics u are trained individually and given personal attention...they then allow us to guide people remotely under supervision at training.... ;)

The training is a session of hardwork of 3 to 4 months...u will have to slog to join systematics... :)
So have you finished your training ? is there a direct link to this systematics ?

shreyas murali

  • Guest
Re: Very stealthy redirect
« Reply #10 on: August 02, 2011, 01:00:01 PM »
well,we dont have any website...i am sorry..but i have competed the training and currenty working there.....this workshop is famous i can say....i found some related info about its existance:

http://maps.google.co.in/maps/place?hl=en&bav=on.2,or.r_gc.r_pw.&biw=1280&bih=705&um=1&ie=UTF-8&q=systematics+at+vasai&fb=1&gl=in&hq=systematics+at&hnear=0x3be7ae956bc1587b:0x864f53a94baa5145,Vasai,+Maharashtra&cid=12484270293370353312
« Last Edit: August 02, 2011, 01:05:10 PM by shreyas murali »

Offline CraigB

  • Avast Überevangelist
  • Serious Graphoman
  • *****
  • Posts: 11256
  • No support PM's thanks
Re: Very stealthy redirect
« Reply #11 on: August 02, 2011, 01:22:42 PM »
well,we dont have any website...i am sorry..but i have competed the training and currenty working there.....this workshop is famous i can say....i found some related info about its existance:

http://maps.google.co.in/maps/place?hl=en&bav=on.2,or.r_gc.r_pw.&biw=1280&bih=705&um=1&ie=UTF-8&q=systematics+at+vasai&fb=1&gl=in&hq=systematics+at&hnear=0x3be7ae956bc1587b:0x864f53a94baa5145,Vasai,+Maharashtra&cid=12484270293370353312
I still fail to see any evidence of your qualifications and just taking your word for it is not is not a wise choice imo, i would think that someone who has the correct training and professionalism would have introduced themselves to the viruses forum and have stated directly there qualifications and experience, i think some evaluation process by senior members and the mods might be in order here.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89611
  • No support PMs thanks
Re: Very stealthy redirect
« Reply #12 on: August 02, 2011, 02:55:40 PM »
Shreyas Murali has been banned for trying to circumvent an existing ban on com155. Based on forum information, they are one and the same.
« Last Edit: August 02, 2011, 02:58:18 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free  24.8.6127 (build 24.8.9372.862) UI 1.0.814/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67185
Re: Very stealthy redirect
« Reply #13 on: August 02, 2011, 02:59:35 PM »
Shreyas Murali has been banned for trying to circumvent an existing ban on com155. Based on forum information, they are one and the same.
I think thee next step will be deleting all the posts of them.
Nothing will show him more as his posts are useless and he is losing time...
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89611
  • No support PMs thanks
Re: Very stealthy redirect
« Reply #14 on: August 02, 2011, 03:04:59 PM »
The problem being is deleting 'all' the posts will leave many topics looking disjointed.
« Last Edit: August 02, 2011, 03:10:03 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free  24.8.6127 (build 24.8.9372.862) UI 1.0.814/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security