Author Topic: Win32:Malware-gen, Google search results redirect  (Read 11922 times)

0 Members and 1 Guest are viewing this topic.

blakewest

  • Guest
Re: Win32:Malware-gen, Google search results redirect
« Reply #15 on: December 05, 2011, 05:08:11 AM »
Please see attachment

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen, Google search results redirect
« Reply #16 on: December 05, 2011, 08:51:32 PM »
Could you download and run the MSFixit from here please http://support.microsoft.com/kb/299357

This will reset the TCPIP parameters, as all the reg entries are good and the files are present 

blakewest

  • Guest
Re: Win32:Malware-gen, Google search results redirect
« Reply #17 on: December 05, 2011, 10:04:01 PM »
Can I just run the command from the KB article?

netsh int ip reset c:\resetlog.txt

Also, do you need to see the logfile afterwards?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen, Google search results redirect
« Reply #18 on: December 05, 2011, 10:21:26 PM »
Yes you can do that

blakewest

  • Guest
Re: Win32:Malware-gen, Google search results redirect
« Reply #19 on: December 06, 2011, 05:04:04 AM »
TCP/IP still not working. See resetlog.txt.

Here is the exact error I get.

Windows IP Configuration
An Internal error occured: The request is not supported.
Please contact Microsoft Product Support Services for further help.

However, I did manage to get recovery console installed without TCP/IP working by following some instructions on the Combofix user guide page. Combofix ran afterwards and I have attached the log from that.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen, Google search results redirect
« Reply #20 on: December 06, 2011, 09:25:33 PM »
I have just been pointed to a similar situation where CookieGal was working - so I have pinched a batch file from her to look at all associted registry entries

Go to Start - Run and copy and paste the following:

regedit /e C:\look.txt "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services"

You won't see anything happen and it will only take a second. You will find the report it creates at C:\look.txt. Please open it in Notepad and then zip it and upload the zipped file to mediafire and post the sharing link

blakewest

  • Guest

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen, Google search results redirect
« Reply #22 on: December 07, 2011, 09:31:37 PM »
Ta will take me a while to run through this

blakewest

  • Guest
Re: Win32:Malware-gen, Google search results redirect
« Reply #23 on: December 08, 2011, 06:24:25 PM »
I did not have a Windows XP installation disc, but I have a friend who does. Could I use this disc to do a repair on the OS and fix the TCP/IP issue?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen, Google search results redirect
« Reply #24 on: December 08, 2011, 09:42:23 PM »
Yes you could run a repair install - details here  http://www.geekstogo.com/forum/topic/138-how-to-repair-windows-xp/

It would definitely be faster.. I am about halfway through decoding the hex files now ;D

blakewest

  • Guest
Re: Win32:Malware-gen, Google search results redirect
« Reply #25 on: December 08, 2011, 09:56:30 PM »
If I do perform a repair, and assuming it fixes my TCP/IP problem, what should I do immediately afterward in terms of scans or pulling updates from Microsoft?

I still have OTL, malwarebytes, and the avast malware tool on the machine.

Thanks!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen, Google search results redirect
« Reply #26 on: December 08, 2011, 10:08:48 PM »
Prior to doing the repair download the latest copy of your AV to the desktop
After the repair and before you update the system install said AV
You will need to get the latest updates from MS, the number required will depend on the age of the CD

blakewest

  • Guest
Re: Win32:Malware-gen, Google search results redirect
« Reply #27 on: December 08, 2011, 10:20:01 PM »
Thanks. I should be able to do this tonight and I will report back with results.

DonZ63

  • Guest
Re: Win32:Malware-gen, Google search results redirect
« Reply #28 on: December 08, 2011, 11:42:58 PM »
You might give this "FixIT" a try since you are planning to do a repair installation. It has worked for me in the past. It will repair Winsock issues.

http://support.microsoft.com/kb/811259

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen, Google search results redirect
« Reply #29 on: December 09, 2011, 09:10:10 PM »
Good ploy that I have the entire centre installed on my system just in case
http://fileforum.betanews.com/detail/Microsoft-Fix-it-Center/1271432341/1