TechSpot

Followed 8 steps to remove Google redirect. Still need help

By beechadr
Jan 5, 2010
  1. I have followed the 8 steps and have my logs saved, but I really don't know how to read them. I have no idea about how program stuff works, but I can follow step by step directions. I am still being redirected in Google searches.
     

    Attached Files:

  2. Tmagic650

    Tmagic650 TS Ambassador Posts: 20,929   +167

    You need to delete the one thing found in the Mbam scan...

    Delete or fix these Hijackthis lines:

    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O4 - HKCU\..\Run: [YouSendIt.exe] C:\Program Files\YouSendIt\Express\YouSendIt.exe -ui none
    O4 - HKLM\..\Run: [C0130Mon.exe] C:\WINDOWS\C0130Mon.exe
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
     
  3. beechadr

    beechadr TS Rookie Topic Starter

    Thank you! This seems to have done the trick. I am not being redirected now. I appreciate you taking the time to respond.
     
  4. Tmagic650

    Tmagic650 TS Ambassador Posts: 20,929   +167

    You're welcome,
    be sure to keep those temp and cookie files under control. Use Advanced SystemCare free, if your not using anything now
     
  5. beechadr

    beechadr TS Rookie Topic Starter

    Tmagic650, I spoke too soon. everything was fine all day, then the redirect went crazy again. Now I am all redirects. How does it go away then come back?
     
  6. Tmagic650

    Tmagic650 TS Ambassador Posts: 20,929   +167

    Run this:
    Virus Scan

    Directions:
    Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
    c:\windows\system32\userinit.exe
    Click on the Upload button
    If a pop-up appears saying the file has been scanned already, please select the ReScan button.
    Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
    Paste the contents of the Clipboard in your next reply.
    Also scan these,

    C:\WINDOWS\explorer.exe
    C:\WINDOWS\System32\svchost.exe

    If this scan runs for you, please paste the log in next reply.
     
  7. beechadr

    beechadr TS Rookie Topic Starter

    Userinit.exe file results:
    VirSCAN.org Scanned Report :
    Scanned time : 2010/01/09 01:13:43 (CST)
    Scanner results: Scanners did not find malware!
    File Name : userinit.exe
    File Size : 26112 byte
    File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
    MD5 : a93aee1928a9d7ce3e16d24ec7380f89
    SHA1 : 513f8bdf67a5a9e09803cfb61f590b39f2683853
    Online report : http://virscan.org/report/88bf8192c5cb7e4aab4dd362d3970e6e.html

    Scanner Engine Ver Sig Ver Sig Date Time Scan result
    a-squared 4.5.0.8 20100108223830 2010-01-08 5.00 -
    AhnLab V3 2010.01.09.00 2010.01.09 2010-01-09 1.20 -
    AntiVir 8.2.1.130 7.10.2.150 2010-01-08 0.30 -
    Antiy 2.0.18 20100108.3621411 2010-01-08 0.12 -
    Arcavir 2009 201001071543 2010-01-07 0.03 -
    Authentium 5.1.1 201001081421 2010-01-08 1.29 -
    AVAST! 4.7.4 100108-0 2010-01-08 0.01 -
    AVG 8.5.288 270.14.130/2607 2010-01-08 0.33 -
    BitDefender 7.81008.4843382 7.29779 2010-01-08 4.13 -
    CA (VET) 35.1.0 7223 2010-01-07 13.83 -
    ClamAV 0.95.2 10272 2010-01-08 0.01 -
    Comodo 3.13.579 3409 2010-01-08 1.29 -
    CP Secure 1.3.0.5 2010.01.08 2010-01-08 0.04 -
    Dr.Web 4.44.0.9170 2010.01.08 2010-01-08 8.36 -
    F-Prot 4.4.4.56 20100107 2010-01-07 1.33 -
    F-Secure 7.02.73807 2010.01.08.09 2010-01-08 0.14 -
    Fortinet 11.350- 11.350 2010-01-08 0.20 -
    GData 19.9842/19.665 20100108 2010-01-08 7.64 -
    ViRobot 20100108 2010.01.08 2010-01-08 0.45 -
    Ikarus T3.1.01.80 2010.01.08.74917 2010-01-08 4.23 -
    JiangMin 13.0.900 2010.01.08 2010-01-08 8.31 -
    Kaspersky 5.5.10 2010.01.08 2010-01-08 0.11 -
    KingSoft 2009.2.5.15 2010.1.8.23 2010-01-08 0.81 -
    McAfee 5.3.00 5855 2010-01-08 3.35 -
    Microsoft 1.5302 2010.01.08 2010-01-08 12.07 -
    Norman 6.01.09 6.01.00 2010-01-08 4.04 -
    Panda 9.05.01 2010.01.08 2010-01-08 2.04 -
    Trend Micro 9.120-1004 6.756.02 2010-01-08 0.03 -
    Quick Heal 10.00 2010.01.08 2010-01-08 1.43 -
    Rising 20.0 22.29.04.04 2010-01-08 0.59 -
    Sophos 3.03.0 4.49 2010-01-08 4.08 -
    Sunbelt 3.9.2388.2 5606 2010-01-07 2.67 -
    Symantec 1.3.0.24 20100102.020 2010-01-02 0.05 -
    nProtect 20100108.01 6819996 2010-01-08 7.91 -
    The Hacker 6.5.0.3 v00141 2010-01-08 1.14 -
    VBA32 3.12.12.1 20100106.1141 2010-01-06 2.52 -
    VirusBuster 4.5.11.10 10.118.25/2004768 2010-01-08 3.43 -


    Explorer.exe results:
    VirSCAN.org Scanned Report :
    Scanned time : 2010/01/09 01:13:43 (CST)
    Scanner results: Scanners did not find malware!
    File Name : userinit.exe
    File Size : 26112 byte
    File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
    MD5 : a93aee1928a9d7ce3e16d24ec7380f89
    SHA1 : 513f8bdf67a5a9e09803cfb61f590b39f2683853
    Online report : http://virscan.org/report/88bf8192c5cb7e4aab4dd362d3970e6e.html

    Scanner Engine Ver Sig Ver Sig Date Time Scan result
    a-squared 4.5.0.8 20100108223830 2010-01-08 5.00 -
    AhnLab V3 2010.01.09.00 2010.01.09 2010-01-09 1.20 -
    AntiVir 8.2.1.130 7.10.2.150 2010-01-08 0.30 -
    Antiy 2.0.18 20100108.3621411 2010-01-08 0.12 -
    Arcavir 2009 201001071543 2010-01-07 0.03 -
    Authentium 5.1.1 201001081421 2010-01-08 1.29 -
    AVAST! 4.7.4 100108-0 2010-01-08 0.01 -
    AVG 8.5.288 270.14.130/2607 2010-01-08 0.33 -
    BitDefender 7.81008.4843382 7.29779 2010-01-08 4.13 -
    CA (VET) 35.1.0 7223 2010-01-07 13.83 -
    ClamAV 0.95.2 10272 2010-01-08 0.01 -
    Comodo 3.13.579 3409 2010-01-08 1.29 -
    CP Secure 1.3.0.5 2010.01.08 2010-01-08 0.04 -
    Dr.Web 4.44.0.9170 2010.01.08 2010-01-08 8.36 -
    F-Prot 4.4.4.56 20100107 2010-01-07 1.33 -
    F-Secure 7.02.73807 2010.01.08.09 2010-01-08 0.14 -
    Fortinet 11.350- 11.350 2010-01-08 0.20 -
    GData 19.9842/19.665 20100108 2010-01-08 7.64 -
    ViRobot 20100108 2010.01.08 2010-01-08 0.45 -
    Ikarus T3.1.01.80 2010.01.08.74917 2010-01-08 4.23 -
    JiangMin 13.0.900 2010.01.08 2010-01-08 8.31 -
    Kaspersky 5.5.10 2010.01.08 2010-01-08 0.11 -
    KingSoft 2009.2.5.15 2010.1.8.23 2010-01-08 0.81 -
    McAfee 5.3.00 5855 2010-01-08 3.35 -
    Microsoft 1.5302 2010.01.08 2010-01-08 12.07 -
    Norman 6.01.09 6.01.00 2010-01-08 4.04 -
    Panda 9.05.01 2010.01.08 2010-01-08 2.04 -
    Trend Micro 9.120-1004 6.756.02 2010-01-08 0.03 -
    Quick Heal 10.00 2010.01.08 2010-01-08 1.43 -
    Rising 20.0 22.29.04.04 2010-01-08 0.59 -
    Sophos 3.03.0 4.49 2010-01-08 4.08 -
    Sunbelt 3.9.2388.2 5606 2010-01-07 2.67 -
    Symantec 1.3.0.24 20100102.020 2010-01-02 0.05 -
    nProtect 20100108.01 6819996 2010-01-08 7.91 -
    The Hacker 6.5.0.3 v00141 2010-01-08 1.14 -
    VBA32 3.12.12.1 20100106.1141 2010-01-06 2.52 -
    VirusBuster 4.5.11.10 10.118.25/2004768 2010-01-08 3.43 -

    Svchost.exe results:
    VirSCAN.org Scanned Report :
    Scanned time : 2010/01/09 01:22:58 (CST)
    Scanner results: Scanners did not find malware!
    File Name : svchost.exe
    File Size : 14336 byte
    File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
    MD5 : 27c6d03bcdb8cfeb96b716f3d8be3e18
    SHA1 : 49083ae3725a0488e0a8fbbe1335c745f70c4667
    Online report : http://virscan.org/report/0b4f2cb08dbc3cb8217cbe347d8b1130.html

    Scanner Engine Ver Sig Ver Sig Date Time Scan result
    a-squared 4.5.0.8 20100108223830 2010-01-08 4.52 -
    AhnLab V3 2010.01.09.00 2010.01.09 2010-01-09 1.68 -
    AntiVir 8.2.1.130 7.10.2.150 2010-01-08 0.24 -
    Antiy 2.0.18 20100108.3621411 2010-01-08 0.12 -
    Arcavir 2009 201001071543 2010-01-07 0.03 -
    Authentium 5.1.1 201001081421 2010-01-08 1.25 -
    AVAST! 4.7.4 100108-0 2010-01-08 0.00 -
    AVG 8.5.288 270.14.130/2607 2010-01-08 0.31 -
    BitDefender 7.81008.4843382 7.29779 2010-01-08 4.11 -
    CA (VET) 35.1.0 7223 2010-01-07 11.66 -
    ClamAV 0.95.2 10272 2010-01-08 0.01 -
    Comodo 3.13.579 3409 2010-01-08 1.18 -
    CP Secure 1.3.0.5 2010.01.08 2010-01-08 0.04 -
    Dr.Web 4.44.0.9170 2010.01.08 2010-01-08 8.82 -
    F-Prot 4.4.4.56 20100107 2010-01-07 1.57 -
    F-Secure 7.02.73807 2010.01.08.09 2010-01-08 9.51 -
    Fortinet 11.350- 11.350 2010-01-08 0.29 -
    GData 19.9842/19.665 20100108 2010-01-08 9.74 -
    ViRobot 20100108 2010.01.08 2010-01-08 0.56 -
    Ikarus T3.1.01.80 2010.01.08.74917 2010-01-08 6.15 -
    JiangMin 13.0.900 2010.01.08 2010-01-08 40.13 -
    Kaspersky 5.5.10 2010.01.08 2010-01-08 0.07 -
    KingSoft 2009.2.5.15 2010.1.8.23 2010-01-08 0.69 -
    McAfee 5.3.00 5855 2010-01-08 3.41 -
    Microsoft 1.5302 2010.01.08 2010-01-08 8.36 -
    Norman 6.01.09 6.01.00 2010-01-08 4.01 -
    Panda 9.05.01 2010.01.08 2010-01-08 3.32 -
    Trend Micro 9.120-1004 6.756.02 2010-01-08 0.03 -
    Quick Heal 10.00 2010.01.08 2010-01-08 13.17 -
    Rising 20.0 22.29.04.04 2010-01-08 2.99 -
    Sophos 3.03.0 4.49 2010-01-08 2.92 -
    Sunbelt 3.9.2388.2 5606 2010-01-07 3.10 -
    Symantec 1.3.0.24 20100102.020 2010-01-02 0.79 -
    nProtect 20100108.01 6819996 2010-01-08 6.86 -
    The Hacker 6.5.0.3 v00141 2010-01-08 1.54 -
    VBA32 3.12.12.1 20100106.1141 2010-01-06 2.34 -
    VirusBuster 4.5.11.10 10.118.25/2004768 2010-01-08 2.36 -

    in addition to the redirect, i'm experiencing very slow response from the computer, i'm not sure if that is being effected by changing any of these files, but in the case that it is useful information its draggin a bit more than usual.

    thanks Tmagic!
    you're awesome!
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.