This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Google links being redirected to other sites

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have tried a couple Malwarebytes antimalware and ad-aware which seemed to clean my system out quite a bit. I originally had a dpmodemx32.dll (along with some others) that were really bogging down my system. It is now running quickly again, but I keep getting redirected to wierd sites when I am doing google searches. I cannot seem to get rid of this! Any help sure would be appreciated! Here are the logs: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/12/16 17:30 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xAC28A000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xBA64E000 Size: 8192 File Visible: No Signed: - Status: - Name: nwfilter.sys Image Path: nwfilter.sys Address: 0xBA4BC000 Size: 15808 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA863F000 Size: 49152 File Visible: No Signed: - Status: - SSDT ——————- #: 025 Function Name: NtClose Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04b2f #: 034 Function Name: NtCreateDirectoryObject Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04b5b #: 037 Function Name: NtCreateFile Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04b8f #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04be3 #: 063 Function Name: NtDeleteKey Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04c27 #: 071 Function Name: NtEnumerateKey Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04c53 #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04c93 #: 079 Function Name: NtFlushKey Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04cd3 #: 105 Function Name: NtMakeTemporaryObject Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04cff #: 108 Function Name: NtMapViewOfSection Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04d2b #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04d7b #: 125 Function Name: NtOpenSection Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04daf #: 151 Function Name: NtQueryInformationFile Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04de3 #: 160 Function Name: NtQueryKey Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04e1f #: 177 Function Name: NtQueryValueKey Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04e5b #: 183 Function Name: NtReadFile Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04e9b #: 224 Function Name: NtSetInformationFile Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04ee7 #: 229 Function Name: NtSetInformationThread Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04f23 #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04f5b #: 267 Function Name: NtUnmapViewOfSection Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04f9b #: 274 Function Name: NtWriteFile Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04fcb ==EOF==

Attachments:

[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI