Jump to content

Fix my PC


AshTheGamer

Recommended Posts

AshTheGamer

I have now reformated, I installed Windows Live Messenger (The new vista kinda one) and Adobe flash player ( A link from youtube)

And now it has returned...

Link to comment
Share on other sites


  • Replies 40
  • Views 2.5k
  • Created
  • Last Reply
I have now reformated, I installed Windows Live Messenger (The new vista kinda one) and Adobe flash player ( A link from youtube)

And now it has returned...

What has returned?

Link to comment
Share on other sites


I have now reformated, I installed Windows Live Messenger (The new vista kinda one) and Adobe flash player ( A link from youtube)

And now it has returned...

The popups? redirect?

Are you accepting any files off anyone through msn?

Link to comment
Share on other sites


I've had this virus because my girlfriend downloaded a codec. But it is very simple to get rid off.

Simple rename the Malwarebytes installer to anything you wish and it will open up. I think the virus blocks all familiar AV names. When it installs it wont run, so you need to change the .exe to another name as well. I think its originally called mbam.exe.. I just changed mine to mbama.exe

It will run. If you need to surf pages from site such as google. You will need to click on the "Cache" link opposed to the original blue link. This is will open the page.

In your processes menu, You will find it automatically opens Internet Explorer without your knowledge and thee is a process called iedw.exe. Terminate those processes and after you will need to goto the registry.

Press "Ctrl + F" and it will open a find menu. Put in IEDW.exe and it shoud have 4 - 5 entries (Remember to click Find Next F3). After that no problem.

Also, IEDW.exe is found in the Internet Explorer folder in Program Files. I havent tried to delete it since but it didnt allow me to at first.

Link to comment
Share on other sites


  • Administrator

It would also be an idea to let us know of the site you are "redirected" to.

Link to comment
Share on other sites


It directs you to many sites for example ebay.co.uk..

Also im not sure what they are called by when you failed to type the correct URL and sometimes it takes you to a page full of links but you know they're all bogus. I hope you get my drift.

Link to comment
Share on other sites


AshTheGamer

Thanks vin3e, That trick worked and I am now doing a full scan!

Link to comment
Share on other sites


As I already suggested, Malwarebytes' Anti-Malware would work in Safe Mode, but this trick is also good. It would be nice to post your log if this tool find anything so we can see what malware was causing this and maybe it can help to someone else with the same problem. Also, if you get rid of the problem, you should use real-time protection of this product.

Cheers ;)

Link to comment
Share on other sites


Disable System Restore

Download Gmer Anti rootkit & run a scan also

http://www.gmer.net/

and also

Process Explorer v11.33

http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

do also a scan at Ewido online

http://www.ewido.net/en/onlinescan/

good luck

Link to comment
Share on other sites


AshTheGamer

Downloaded them, I also done a full system scan with Malwarebytes' Anti-Malware and nothing found O.o

Link to comment
Share on other sites


This is where im trumped too lol. which resorted me to just giving windows 7 a try.. didnt turn out too well lol.

I seriously have no more explanations so goodluck!

Link to comment
Share on other sites


Downloaded them, I also done a full system scan with Malwarebytes' Anti-Malware and nothing found O.o

Try the well known antivirus programs like Norton Internet Security 2009 trial, this is very good at removing any viruses/spyware:

Norton Internet Security 2009 trial for 90 days

Also, try Ad-Aware Pro 8, this is one of the best but only for removal of viruses/spyware, I sent you PM for this one. :yes:

Link to comment
Share on other sites


Yup I suggest you use AdAware. This sounds like you installed a toolbar or something of that sort & that's whats redirecting you. I dont think that you used combofix, try that. If not, use what donizme said...

Link to comment
Share on other sites


try spybot s&d

Link to comment
Share on other sites


  • Administrator

It would still be really nice to know the website you are redirected too.

Link to comment
Share on other sites


It would still be really nice to know the website you are redirected too.

He said that he is redirected to random site.. But I think you want more specific links?

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...