Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Google redirect
![]() |
|
|
|
Thread Tools |
|
#21
|
||||
|
||||
|
yes you should. I am just curious as I would like to recommend the program more often.
If it does, post a fresh hijackthis log - i wanna see if it clears those appinetdll's. If not - just let me know |
|
#22
|
|||
|
|||
|
It didn't give me the option to quarantine. I'll attach the log just in case you want to see it.
|
|
|
|
#23
|
||||
|
||||
|
Sorry for running you around a bit. We will move forward, so you understand what we are up against.
The AppInit_DLLs registry value contains a list of dlls that will be loaded when user32.dll is loaded. As most Windows executables use the user32.dll, that means that any DLL that is listed in the AppInit_DLLs registry key will be loaded also. This makes it very difficult to remove the DLL as it will be loaded within multiple processes, some of which can not be stopped without causing system instability. The user32.dll file is also used by processes that are automatically started by the system when you log on. This means that the files loaded in the AppInit_DLLs value will be loaded very early in the Windows startup routine allowing the DLL to hide itself or protect itself before we have access to the system. ================================================ Run CFScript Open notepad and copy/paste the text in the code box below into it: NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it. Also .. Pay particular attention to this :- Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it) Quote:
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below. ![]() This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log. Last edited by Blind Dragon; 11-27-2008 at 01:52 PM.. |
|
#24
|
|||
|
|||
|
You're not running me around. Believe me, I'm very grateful for the help!
Logs requested are attached. |
|
#25
|
||||
|
||||
|
Almost there
OTMoveit3 by OldTimer
Last edited by Blind Dragon; 11-27-2008 at 01:52 PM.. |
|
#26
|
|||
|
|||
|
Did as asked, attached log.
Would've done this last night but realised it was 4.30am and I needed some sleep. Sorry! |
|
#27
|
||||
|
||||
|
No problem, I went to bed as well. One more time - then we can clean up -
Are you attached to Mcafee? Or would you be willing to consider some free alternatives? I know they have definitions on this one, but it doesn't seem to be doing anything about it =================================================== OTMoveit3 by OldTimer
Last edited by Blind Dragon; 11-27-2008 at 01:51 PM.. |
|
#28
|
|||
|
|||
|
I was running Avira, but changed to McAfee because I was given a free 12 month subscription. Funnily enough, it was the day I changed over that I started to get these problems. Thinking maybe I should have stayed with Avira!
Have attached the log as requested. |
|
#29
|
||||
|
||||
|
I need to get a 2nd opinion and see if we missed anything - also scan some sections I can't see
Run Kaspersky Online AV ScannerIn order to use it you have to use Internet Explorer. Go to Kaspersky and click the Accept button at the end of the page. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
|
|
|
|
#30
|
|||
|
|||
|
Sorry that's taken so long. Log is attached.
|
|
#31
|
||||
|
||||
|
Run CFScript
Open notepad and copy/paste the text in the code box below into it: NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it. Also .. Pay particular attention to this :- Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it) Quote:
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below. ![]() This will start ComboFix again. ================================================= I would switch your security from Mcafee back to Avira, and you should also use a firewall such as Zone Alarm or Comodo Firewalls Here are some firewalls which are free for personal use and most commonly used: Comodo <-Vista Compatible Zonealarm <-Vista Compatible Anti-Virus Avast Free Avira Free <- My recommendation ================================================= Uninstall Combofix * Click START then RUN * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter. * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ----------------------------------------------------------------------- OTCleanit! by Oldtimer
--------------------------------------------------------------------------- Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
here are some additional utilities that will enhance your safety
__________________
INFECTED? Free Virus and Malware Removal
|
|
#32
|
|||
|
|||
|
Thank you! You are an absolute angel, everything seems to be running perfectly now. I cannot tell you how much I appreciate all your help with this. Thank you!
|
|
#33
|
||||
|
||||
|
Anytime, let me know if anything else comes up
![]() |
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Google Redirect | Virus & Malware removal | 1 | 10-17-2008 04:27 AM | |
| Google Redirect Virus? | Virus & Malware removal | 1 | 09-20-2008 07:08 PM | |
| Google search redirect to nothing IP 85.255.120.226 | Virus & Malware removal | 28 | 04-27-2008 03:17 AM | |
| Google redirect | Virus & Malware removal | 10 | 05-15-2007 06:14 PM | |
| Google redirect | Virus & Malware removal | 17 | 03-01-2007 10:06 PM | |
All times are GMT -4. The time now is 10:58 AM.




Run Kaspersky Online AV Scanner