Inactive Google redirect virus won't go away!

Status
Not open for further replies.
OTL

I'm sorry, I'm a little confused. The first instructions said to paste the red text in the custom scan, and hit Quick Scan. Do I now choose "Run Fix" and do I do that with or without the red text in custom scan box?
 
Re-read my reply #19.

Paste my code on custom scan box and then click on "Run Fix" button.
 
OTL log

I'm not sure why, but my computer is running extremely slow now. Here is the OTL log.




All processes killed
========== OTL ==========
Prefs.js: "127.0.0.1" removed from network.proxy.http
Prefs.js: 63192 removed from network.proxy.http_port
Prefs.js: 4 removed from network.proxy.type
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Folder C:\Documents and Settings\All Users\Application Data\STOPzilla!\ not found.
C:\WINDOWS\System32\REN35.tmp deleted successfully.
File C:\Documents and Settings\Piffany Copper\Application Data\9A36.C71 not found.
File C:\Documents and Settings\All Users\Application Data\~16899876 not found.
Folder C:\Documents and Settings\All Users\Application Data\STOPzilla!\ not found.
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:F7F48F12 .
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 .
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\\DisableMonitoring deleted successfully.
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Piffany Copper
->Temp folder emptied: 15673707 bytes
->Temporary Internet Files folder emptied: 281376 bytes
->Java cache emptied: 2027 bytes
->FireFox cache emptied: 43213576 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 790 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 49152 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 160350 bytes

Total Files Cleaned = 57.00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService

User: Piffany Copper
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.26.1 log created on 07312011_145815

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
 
slow

I did a restart. The computer started up slowly. When I moved the mouse, it showed me the timer, and said "not responding." Then it went away. Also, when I was typing in my password, it took a minute before the letters showed up.
Note: I have CCleaner installed. It runs when I start the computer. Is it possible that it is slowing it down during restart?
 
Very possible.
There is absolutely no reason to clean temporary files on each restart.
Run it manually once a week.
Make sure you don't touch registry part.
That's why I prefer TFC.

Disable CCleaner, restart and let me know how it goes.
 
restart

I will have to restart again to get to the CCleaner to adjust settings. When I go to Start menu, and All Programs, there are only a few things listed. I don't have Accessories or any of that any more. I don't know what to do to fix that. It was one of the reasons I thought I might need to do a system restore to get the computer back to normal. I also have things installed that I can't uninstall, like Migo Mobile. I don't know what it is, don't use it and it won't let me uninstall.
 
I don't have Accessories or any of that any more. I don't know what to do to fix that
Since we ran temporary file cleaner already, you'll have to restore those things manually.
Do NOT use system restore anymore, because some restore points may be infected.
We'll reset them, when we're totally done.

You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:
  • Restore Accessories Program Files Menu with accrestore.zip for XP
    • Extract (unzip) the tool, double-click on it to run and ensure that the following check boxes are checked (as shown below):
    restore-start-menu-accessories-folder.png
    • Then click on the Restore button.

===================================================================

2nd part follows....
 
To manually recreate "All Programs" entries, follow these steps...

  • Download App Paths
  • Double click on AppPaths.exe to run the program.
  • Keep the program open.

In this example I'll recreate an entry for Avast antivirus program.
  • Go Start>All Programs.
  • Right click on Avast entry, click "Properties".

p4481214.gif

NOTE. Make sure, you right click on Avast program, NOT on Avast folder.

  • You'll see this window:

p4481211.gif


Due to the damage caused by the infection, you'll find "Target" box empty.

  • Go back to AppPaths window and find Avast entry.
  • Right click on Avast line, click "Edit".
  • A pop-up window will open:

p4481212.gif


  • Highlight everything in "Path" box, right click on it, click "Copy"
  • Go back to Avast "Properties" window, right click inside "Target" box, click "Paste".
  • IMPORTANT! Add quotation marks at the beginning of the path and at the end
  • Click OK and you're done.

p4481213.gif



In case, program's link shows as (empty):

p4481404.gif


  • Open Windows Explorer, navigate to Avast folder in Program Files
  • Right click on Avast ".exe" file, click "Create shortcut":

p4481405.gif


  • Copy that shortcut, go back to Start menu.
  • Right click on avast!Free Antivirus, click "Paste".
  • You'll see Avast shortcut recreated replacing (empty) entry.

Alternatively....
...you paste that shortcut in:
(XP) - C:\Documents and Settings\All Users\Start Menu\Programs\Avast
 
CCleaner, restart

I forgot I could go to msconfig and disable CCleaner from running at start up. I did that and restarted. When coming to this page, I moved the mouse and it showed me the timer again and froze for a minute. Then it returned to normal. Is there anything I can do to return the programs back to the start menu? I can't get to Accessories or anything. I assumed that problem was created by a virus and would return once the computer was virus free.
 
I think you didn't see my previous two replies.

When coming to this page, I moved the mouse and it showed me the timer again and froze for a minute.
Which browser?
 
Start Up

Here's my problem. I go to Start Up, and the only things showing up are McAfee, Firefox, Malewarebytes, HP Install Network Printer Wizard, and Adobe Reader X. All these things are available to me on my Desktop. Is there supposed to be more? Like Microsoft Word and such?
 
restore

Yes, I ran the Accessories Restore program, but nothing new showed up. I couldn't do the next step, because the things weren't there. The browser I'm using is Firefox.
 
Close Firefox. Go Start>All Programs>Mozilla Firefox, click on Mozilla Firefox (safe mode).
If you're using Firefox 4, or 5 go Help>Restart Firefox with Add-ons Disabled.
Same slowness?

Do you have Windows XP CD?
 
firefox

When I go to start, all programs and Firefox, there is not an option for safe mode. I do not have a Windows XP Cd. There is no place for a disc at all. I am running Firefox 5. Do I still need to restart Firefox with no add ons?
 
restart

Ok, I wasn't sure if I was supposed to do all the steps or one or the other. I restarted without add ons. The page didn't freeze, & didn't show me the timer.
 
Which means some of your add-ons is giving you fits.

You can investigate.
Start Firefox normally, manually disable all add-ons, but one.
Restart Firefox.
No lag?
Enable next add-on and so on until you find the culprit.
You can do the above on your free time.

For now I want you to run final steps...

Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:

Code:
:OTL
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post resulting log.

2. Now, we'll remove all tools, we used during our cleaning process

Clean up with OTL:

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

3. Make sure, Windows Updates are current.

4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC) weekly.

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. (Windows XP only) Run defrag at your convenience.

11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

13. Please, let me know, how your computer is doing.
 
OTL fix log

All processes killed
========== OTL ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Piffany Copper
->Temp folder emptied: 3134 bytes
->Temporary Internet Files folder emptied: 296554 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 43090460 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 456 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 41.00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService

User: Piffany Copper
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.26.1 log created on 07312011_193111

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
 
acc restore?

Thank you so much for all your help. I just ran the OTL clean up, and I'm about to download the WOT. Is there any thing else I can do to get my accessories back? I ran the acc restore, but it didn't restore anything.
 
windows xp CD

Oh wow. That's the only way to fix it? I have a Windows XP CD but this computer doesn't even have a place to put in a disc. I got it with my desktop...desktop won't boot up. So I guess I'm stuck.
 
Status
Not open for further replies.
Back