Google redirect virus won't go away!

Inactive
By kbates120806
Jul 29, 2011
Topic Status:
Not open for further replies.
  1. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    No, you clicked on "Scan" button instead of "Fix" button.
    Please redo.
  2. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    OTL

    I'm sorry, I'm a little confused. The first instructions said to paste the red text in the custom scan, and hit Quick Scan. Do I now choose "Run Fix" and do I do that with or without the red text in custom scan box?
  3. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    Re-read my reply #19.

    Paste my code on custom scan box and then click on "Run Fix" button.
  4. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    OTL log

    I'm not sure why, but my computer is running extremely slow now. Here is the OTL log.




    All processes killed
    ========== OTL ==========
    Prefs.js: "127.0.0.1" removed from network.proxy.http
    Prefs.js: 63192 removed from network.proxy.http_port
    Prefs.js: 4 removed from network.proxy.type
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Folder C:\Documents and Settings\All Users\Application Data\STOPzilla!\ not found.
    C:\WINDOWS\System32\REN35.tmp deleted successfully.
    File C:\Documents and Settings\Piffany Copper\Application Data\9A36.C71 not found.
    File C:\Documents and Settings\All Users\Application Data\~16899876 not found.
    Folder C:\Documents and Settings\All Users\Application Data\STOPzilla!\ not found.
    Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:F7F48F12 .
    Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 .
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\\DisableMonitoring deleted successfully.
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Piffany Copper
    ->Temp folder emptied: 15673707 bytes
    ->Temporary Internet Files folder emptied: 281376 bytes
    ->Java cache emptied: 2027 bytes
    ->FireFox cache emptied: 43213576 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Flash cache emptied: 790 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 49152 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 160350 bytes

    Total Files Cleaned = 57.00 mb


    [EMPTYFLASH]

    User: Administrator
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService

    User: Piffany Copper
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.26.1 log created on 07312011_145815

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
  5. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    Give it another restart and let me know....
  6. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    slow

    I did a restart. The computer started up slowly. When I moved the mouse, it showed me the timer, and said "not responding." Then it went away. Also, when I was typing in my password, it took a minute before the letters showed up.
    Note: I have CCleaner installed. It runs when I start the computer. Is it possible that it is slowing it down during restart?
  7. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    Very possible.
    There is absolutely no reason to clean temporary files on each restart.
    Run it manually once a week.
    Make sure you don't touch registry part.
    That's why I prefer TFC.

    Disable CCleaner, restart and let me know how it goes.
  8. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    restart

    I will have to restart again to get to the CCleaner to adjust settings. When I go to Start menu, and All Programs, there are only a few things listed. I don't have Accessories or any of that any more. I don't know what to do to fix that. It was one of the reasons I thought I might need to do a system restore to get the computer back to normal. I also have things installed that I can't uninstall, like Migo Mobile. I don't know what it is, don't use it and it won't let me uninstall.
  9. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    Since we ran temporary file cleaner already, you'll have to restore those things manually.
    Do NOT use system restore anymore, because some restore points may be infected.
    We'll reset them, when we're totally done.

    You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:

    ===================================================================

    2nd part follows....
  10. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    To manually recreate "All Programs" entries, follow these steps...

    • Download App Paths
    • Double click on AppPaths.exe to run the program.
    • Keep the program open.

    In this example I'll recreate an entry for Avast antivirus program.
    • Go Start>All Programs.
    • Right click on Avast entry, click "Properties".

    [​IMG]
    NOTE. Make sure, you right click on Avast program, NOT on Avast folder.

    • You'll see this window:

    [​IMG]

    Due to the damage caused by the infection, you'll find "Target" box empty.

    • Go back to AppPaths window and find Avast entry.
    • Right click on Avast line, click "Edit".
    • A pop-up window will open:

    [​IMG]

    • Highlight everything in "Path" box, right click on it, click "Copy"
    • Go back to Avast "Properties" window, right click inside "Target" box, click "Paste".
    • IMPORTANT! Add quotation marks at the beginning of the path and at the end
    • Click OK and you're done.

    [​IMG]


    In case, program's link shows as (empty):

    [​IMG]

    • Open Windows Explorer, navigate to Avast folder in Program Files
    • Right click on Avast ".exe" file, click "Create shortcut":

    [​IMG]

    • Copy that shortcut, go back to Start menu.
    • Right click on avast!Free Antivirus, click "Paste".
    • You'll see Avast shortcut recreated replacing (empty) entry.

    Alternatively....
    ...you paste that shortcut in:
    (XP) - C:\Documents and Settings\All Users\Start Menu\Programs\Avast
  11. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    CCleaner, restart

    I forgot I could go to msconfig and disable CCleaner from running at start up. I did that and restarted. When coming to this page, I moved the mouse and it showed me the timer again and froze for a minute. Then it returned to normal. Is there anything I can do to return the programs back to the start menu? I can't get to Accessories or anything. I assumed that problem was created by a virus and would return once the computer was virus free.
     
  12. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    I think you didn't see my previous two replies.

    Which browser?
  13. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    Start Up

    Here's my problem. I go to Start Up, and the only things showing up are McAfee, Firefox, Malewarebytes, HP Install Network Printer Wizard, and Adobe Reader X. All these things are available to me on my Desktop. Is there supposed to be more? Like Microsoft Word and such?
  14. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    In my reply #34 and #35 I told you how to restore missing items.
  15. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    restore

    Yes, I ran the Accessories Restore program, but nothing new showed up. I couldn't do the next step, because the things weren't there. The browser I'm using is Firefox.
  16. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    Close Firefox. Go Start>All Programs>Mozilla Firefox, click on Mozilla Firefox (safe mode).
    If you're using Firefox 4, or 5 go Help>Restart Firefox with Add-ons Disabled.
    Same slowness?

    Do you have Windows XP CD?
  17. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    firefox

    When I go to start, all programs and Firefox, there is not an option for safe mode. I do not have a Windows XP Cd. There is no place for a disc at all. I am running Firefox 5. Do I still need to restart Firefox with no add ons?
  18. Broni

    Broni Malware Annihilator Posts: 46,341   +252

  19. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    restart

    Ok, I wasn't sure if I was supposed to do all the steps or one or the other. I restarted without add ons. The page didn't freeze, & didn't show me the timer.
  20. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    Which means some of your add-ons is giving you fits.

    You can investigate.
    Start Firefox normally, manually disable all add-ons, but one.
    Restart Firefox.
    No lag?
    Enable next add-on and so on until you find the culprit.
    You can do the above on your free time.

    For now I want you to run final steps...

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
  21. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    OTL fix log

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Piffany Copper
    ->Temp folder emptied: 3134 bytes
    ->Temporary Internet Files folder emptied: 296554 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 43090460 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Flash cache emptied: 456 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 41.00 mb


    [EMPTYFLASH]

    User: Administrator
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService

    User: Piffany Copper
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb

    Restore points cleared and new OTL Restore Point set!

    OTL by OldTimer - Version 3.2.26.1 log created on 07312011_193111

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
  22. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    acc restore?

    Thank you so much for all your help. I just ran the OTL clean up, and I'm about to download the WOT. Is there any thing else I can do to get my accessories back? I ran the acc restore, but it didn't restore anything.
  23. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    I'm afraid we'll need Windows XP CD.
  24. kbates120806

    kbates120806 Newcomer, in training Topic Starter Posts: 38

    windows xp CD

    Oh wow. That's the only way to fix it? I have a Windows XP CD but this computer doesn't even have a place to put in a disc. I got it with my desktop...desktop won't boot up. So I guess I'm stuck.
  25. Broni

    Broni Malware Annihilator Posts: 46,341   +252

    Any chance you could get hold of an external USB CD drive?
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.