Hello and
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.
I am checking over your log , I will post back shortly with instructions.
You have uTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.
P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.
Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.
I would recommend that you uninstall uTorrent, via Control Panel -> Add or Remove Programs.
However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.
–Next–
Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT"entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Click NO
In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
Now click the Scan button. Once the scan is complete, you may receive another notice about rootkit activity.
Click OK.
GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop
To post in your next reply:
1. GMER log.
2. Is the google redirection happens on all your browsers (eg. Internet Explorer, Mozilla, Opera, etc)?
When I ran the scan I got an error at the first second "C:\Windows\system32\config\system: The process cannot access the file because it is being used by another process."
I also don't know if it is happening with other browsers. It happens very randomly and I just use firefox for day to day items to I don't notice it in other browsers.
The result of the scan is GMER hasn't found any system modification. The file I saved was blank.
Am still not seeing anything malicious on your system. Please bear with me as we will be doing another diagnostic scan. Thank you.
Please do the following:
Download OTL to your desktop.
Right click on the icon and select "Run as administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
–Next–
Are you still experiencing google redirection? Can you post the links to the URL that you are trying to go from google?
Aside from google redirection, are there any other problems occurring in your computer?
Also, can you note then post what those dll files that comodo are notifying you of?
The website in the url actually is google. Thats one of the weirdest things I've found with it. The sites themselves aren't exactly malicious either. They just aren't google.
I'll try to get a list together of the dll's i'm having it block. I really don't know whether or not they are entirely related.
OLT.txt
OTL logfile created on: 11/21/2009 12:07:19 PM - Run 1
OTL by OldTimer - Version 3.1.6.1 Folder = F:\Calvin Hopkins Data\Downloads\Firefox Downloads
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 145.00 Gb Total Space | 96.43 Gb Free Space | 66.51% Space Free | Partition Type: NTFS
Drive D: | 200.00 Gb Total Space | 40.24 Gb Free Space | 20.12% Space Free | Partition Type: NTFS
Drive E: | 219.99 Gb Total Space | 76.10 Gb Free Space | 34.59% Space Free | Partition Type: NTFS
Drive F: | 200.00 Gb Total Space | 117.27 Gb Free Space | 58.64% Space Free | Partition Type: NTFS
Drive G: | 98.09 Gb Total Space | 94.74 Gb Free Space | 96.59% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: THESWAN
Current User Name: Calvin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
OTL Extras logfile created on: 11/21/2009 12:07:19 PM - Run 1
OTL by OldTimer - Version 3.1.6.1 Folder = F:\Calvin Hopkins Data\Downloads\Firefox Downloads
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 145.00 Gb Total Space | 96.43 Gb Free Space | 66.51% Space Free | Partition Type: NTFS
Drive D: | 200.00 Gb Total Space | 40.24 Gb Free Space | 20.12% Space Free | Partition Type: NTFS
Drive E: | 219.99 Gb Total Space | 76.10 Gb Free Space | 34.59% Space Free | Partition Type: NTFS
Drive F: | 200.00 Gb Total Space | 117.27 Gb Free Space | 58.64% Space Free | Partition Type: NTFS
Drive G: | 98.09 Gb Total Space | 94.74 Gb Free Space | 96.59% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: THESWAN
Current User Name: Calvin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{16622757-3724-4DA8-A5CC-3CE75636E8B9}" = COMODO EasyVPN
"{29C93182-34F6-3275-A18D-59326851CD57}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools
"{2BFA9B05-7418-4EDE-A6FC-620427BAAAA3}" = Crystal Reports Basic Runtime for Visual Studio 2008 (x64)
"{50822200-2E95-4E62-A8D8-41C3B308DF5E}" = Microsoft SQL Server VSS Writer
"{5DE154DF-A55E-4FA5-BE59-32E78FCACF3E}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{62EED300-E841-4083-A1D6-60B906271804}" = Microsoft Windows SDK for Visual Studio 2008 Tools
"{64D5BBC6-5270-3711-AA39-31C1087AF4E6}" = Microsoft Visual Studio 2008 Remote Debugger - ENU
"{66F644DA-4ED8-4D03-83D2-A7156AA562BC}" = ESET NOD32 Antivirus
"{6E740973-8E71-42F9-A910-C18452E60450}" = Microsoft SQL Server Native Client
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{85EA529C-CCBD-464D-8163-4313B116DAB1}" = Start Killer
"{88EB92AB-ABD3-E13C-3AEE-B7518354B55A}" = ATI Catalyst Install Manager
"{9aa5f39c-a8de-46b0-919a-0248f8bc8490}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
"{A992BBAA-723D-4574-A07F-983BF8FAA3E1}" = Microsoft Windows SDK for Visual Studio 2008 Win32 Tools
"{D3E39E77-0EB4-36FB-B97A-8C8AB21B9A45}" = Visual Studio .NET Prerequisites - English
"{EF8B1A2E-9CCB-3AB2-91E3-4EEDAB1294E1}" = Microsoft Device Emulator (64 bit) version 3.0 - ENU
"COMODO Internet Security" = COMODO Internet Security
"MatlabR2009a" = MATLAB R2009a
"Microsoft Visual Studio 2008 Remote Debugger - ENU" = Microsoft Visual Studio 2008 Remote Debugger - ENU
"WinRAR archiver" = WinRAR archiver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B9E27C7-9ECD-4362-B311-030EA48F8E72}" = Crystal XI
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{20AEA7B1-6155-44A2-B58E-430F2C9F4ABD}" = AMD OverDrive
"{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{2E5C075E-11AB-4BDD-918C-7B9A68953FF8}" = Microsoft SQL Server Compact 3.5 Design Tools ENU
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.2
"{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}" = Microsoft SQL Server Compact 3.5 ENU
"{C23B8C30-E05E-4CB5-8188-F27CC3B2DD3E}" = Sibelius 5
"{CE9CAAD2-A4CA-48CC-B0C2-07254867FAD4}" = Cadence License Manager
"{D7DAD1E4-45F4-3B2B-899A-EA728167EC4F}" = Microsoft Visual Studio 2008 Professional Edition - ENU
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse
"{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
"{FF29527A-44CD-3422-945E-981A13584000}" = VC Runtimes MSI
"{FF9312A2-9810-40E2-9954-617DDE7B123F}" = Release OrCAD 16.0
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CCleaner" = CCleaner (remove only)
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DVD Flick_is1" = DVD Flick 1.3.0.7
"ERUNT_is1" = ERUNT 1.1j
"FileHippo.com" = FileHippo.com Update Checker
"FlashGet" = FlashGet 1.9.6.1073
"Foxit Reader" = Foxit Reader
"GOM Player" = GOM Player
"HijackThis" = HijackThis 2.0.2
"ImgBurn" = ImgBurn
"Impulse" = Impulse
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.0.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaMonkey_is1" = MediaMonkey 3.1
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Microsoft Visual Studio 2008 Professional Edition - ENU" = Microsoft Visual Studio 2008 Professional Edition - ENU
"MKVtoolnix" = MKVtoolnix 2.2.0
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"Mozilla Sunbird (0.9)" = Mozilla Sunbird (0.9)
"Mozilla Thunderbird (3.0b4)" = Mozilla Thunderbird (3.0b4)
"MyPorts_is1" = MyPorts - build 1.01.03 - If an older version of MyPorts is alr
"Neuratron PhotoScore Ultimate Demo" = Neuratron PhotoScore Ultimate Demo
"ObjectDock Plus" = ObjectDock Plus
"PandoraSaver (standalone)_is1" = PandoraSaver 1.008e (standalone)
"PowerISO" = PowerISO
"QuicktimeAlt_is1" = QuickTime Alternative 2.7.0
"Rainmeter" = Rainmeter (remove only)
"RealAlt_is1" = Real Alternative 1.9.0 Lite
"Revo Uninstaller" = Revo Uninstaller 1.83
"Speaker Workshop" = Speaker Workshop
"Taskbar Activate" = Taskbar Activate
"TeamViewer 4" = TeamViewer 4
"uTorrent" = µTorrent
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"VLC media player" = VLC media player 1.0.1
"WinPatrol" = WinPatrol 2009
========== HKEY_CURRENT_USER Uninstall List ==========
[ System Events ]
Error - 11/18/2009 9:46:06 PM | Computer Name = TheSwan | Source = DCOM | ID = 18213
Description =
Error - 11/19/2009 4:24:25 PM | Computer Name = TheSwan | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter
Error - 11/19/2009 4:24:25 PM | Computer Name = TheSwan | Source = atikmdag | ID = 43029
Description = Display is not active
Error - 11/19/2009 4:33:08 PM | Computer Name = THESWAN | Source = BugCheck | ID = 1001
Description =
Error - 11/19/2009 4:33:02 PM | Computer Name = TheSwan | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter
Error - 11/19/2009 4:33:02 PM | Computer Name = TheSwan | Source = atikmdag | ID = 43029
Description = Display is not active
Error - 11/20/2009 12:14:04 PM | Computer Name = TheSwan | Source = DCOM | ID = 18213
Description =
Error - 11/20/2009 12:14:04 PM | Computer Name = TheSwan | Source = DCOM | ID = 18213
Description =
Error - 11/20/2009 12:14:04 PM | Computer Name = TheSwan | Source = DCOM | ID = 18213
Description =
Error - 11/20/2009 12:14:04 PM | Computer Name = TheSwan | Source = DCOM | ID = 18213
Description =
< End of report >
I'll try to keep a running tab of dll's that it blocks. I just recently purged the log of things that were in it and I'm not sure which are the ones I'm looking for right now. I'll make another post and update it with dll's that I find.
I don't really know if anything else is going on. Comodo crashes every once in a while. I'm not sure whether its getting tied up. Or that is actualy something that is a problem. Every once and a while I'll have multiple explorer.exe running and ill close them all and start them all back up again. And occasionally when I close an explorer tab I will get an "Explorer.exe has stopped running properly" error. and I'll have to restart that. Whether these are by the same problem I don't know. And yes I still do get a google misdirect every once and a while. As I said before it seems to be completely random.
Hello. So I've been tracking the dll's that are launched. They all are from the C:\Program Files (x86)\Common Files\Business Objects\3.0\bin but i haven't been able to find any information about them online at all. Would they be safe? or am I right to deny them to run.
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan. [external image: Posted Image]
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.
–Next–
Please do a scan with Kaspersky Online Scanner or from Here.
Click on the Accept button and install any components it needs.
The program will install and then begin downloading the latest definition files.
After the files have been downloaded on the left side of the page in the Scan section select My Computer.
This will start the program and scan your system.
The scan will take a while, so be patient and let it run. (At times it may appear to stall)
Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save asprompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.
[external image: Posted Image]
To post in your next reply:
1. OTL result log.
2. Malwarebytes log.
3. Kaspersky log.
4. How is your computer doing at the moment?
OTL LOGAll processes killed
========== OTL ==========
No active process named explorer.exe was found!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7b128a40-b6b2-11de-9654-001d92b448e3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7b128a40-b6b2-11de-9654-001d92b448e3}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7b128a40-b6b2-11de-9654-001d92b448e3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7b128a40-b6b2-11de-9654-001d92b448e3}\ not found.
File K:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\L\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\L\ not found.
File L:\AUTORUN\SPLASH.EXE not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\L\ not found.
File L:\SETUP.EXE not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Calvin
->Temp folder emptied: 10244700 bytes
->Temporary Internet Files folder emptied: 945093 bytes
->Java cache emptied: 30372969 bytes
->FireFox cache emptied: 48949628 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
Windows Temp folder emptied: 56408891 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 136709 bytes
Total Files Cleaned = 140.29 mb
OTL by OldTimer - Version 3.1.6.1 log created on 11242009_002137
Files\Folders moved on Reboot…
C:\Users\Calvin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot…
Malwarebytes log
Malwarebytes' Anti-Malware 1.41
Database version: 3221
Windows 6.1.7600
11/24/2009 12:40:36 AM
mbam-log-2009-11-24 (00-40-36).txt
Scan type: Quick Scan
Objects scanned: 95520
Time elapsed: 1 minute(s), 57 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
The first link for kapersky gave me this error:
Update has failed The program could not be started. Please close the window of Kaspersky Online Scanner 7.0 and start the program again from the web site of Kaspersky Lab.
Successful updating of Kaspersky Online Scanner 7.0 and scanning of your computer requires uninterrupted Internet connection. Please make sure that the Internet connection is established. [ERROR: Scanning could not be started. [0x80004005]]
I then went to the second link and it said: The current Kaspersky Online Scanner is unavailable - we apologize for the inconvenience.
My computer seems to be doing about the same. For 90% of the time it performs great however 1 out of every ten times I go on the internet and try to access Google it fails miserably. Sometimes it is just Firefox. Sometimes it is more browsers. I haven't gotten any redirects within the past two days but I have gotten blocked from going to it. Then I've logged onto another computer and have had google work on the other computer right away (same internet connection through same router).
You are getting blocked from going to google? So far we are not seeing anything malicious on your system.
Let's try uninstalling Firefox then downloading a fresh copy from here then reinstalling it. Let's see if that can atleast solve some of the problems.
–Next–
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
Please download JavaRa to your desktop and unzip it to its own folder
Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
The latest update is Java 6 update 17
Now to Clean out the Java cache:
Go into the Control Panel and double-click the Java Icon.
Under Temporary Internet Files, click the Settings… button
click the Delete Files button.
There are two options in the window to clear the cache - Leave both Checked Applications and Applets Trace and Log Files
Click OK on Delete Temporary Files Window Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
Click OK to leave the Temporary Files Settings
Click OK to leave the Java Control Panel.
–Next–
Go here to run an online scanner from ESET.
Note: You will need to use Internet explorer for this scan
Turn off the real time scanner of any existing antivirus program while performing the online scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activeX control to install
Click Start
Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
Copy and paste that log as a reply to this topic and also let me know how things are now.
Also, please advise again on how your computer is doing at the moment. Thank you.
Here is the log:
ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
esets_scanner_update returned -1 esets_gle=53251
esets_scanner_update returned -1 esets_gle=53251
esets_scanner_update returned -1 esets_gle=53251
It said the scan completed in 0:00:00. I'm doubtful that it ever ran. I disabled Comodo, ESET, and Windows Defender during the period. I haven't been having any troubles with google. Right now all the problems are with explorer.exe. I think that might just be a compatibility issue with windows 7 and WinRAR though cause it only ever happens with that. Google hasn't given me any problems recently though.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI