This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect Virus

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I will post the log from the ESET Online Scanner which returned a few threats, however MBAM came up with none. IE and Mozilla seem to opening pages without any signs of malicious redirects or popups too. ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.7600.16385 (win7_rtm.090713-1255) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial= # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-03-28 07:32:09 # local_time=2010-03-28 06:32:09 (+1000, AUS Eastern Daylight Time) # country="United States" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1029 16777213 100 93 0 11672219 0 0 # compatibility_mode=2560 16777215 100 0 0 0 0 0 # compatibility_mode=5893 16776574 100 94 11702219 21382932 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=236778 # found=3 # cleaned=0 # scan_time=12047 D:\Downloads\AVG.Anti-Virus.9.0.663.1703\AVG.Anti-Virus.9.0.663.1703.rar a variant of Win32/HackTool.Patcher.A application 00000000000000000000000000000000 I D:\usbak\UniServer\udrive\autorun.inf INF/Autorun virus 00000000000000000000000000000000 I D:\usbak\Work\from steve\Java\JavaScript\javascript for the world wide web Share Accelerator.zip Win32/Adware.Toolbar.Shopper application 00000000000000000000000000000000 I
Hi,

The only one I would delete is the zipped java share accelerator just to be cautious. The other two appear to be based on heuristics. So navigate to that file on your D:\ drive, right click and delete it.

we just have some housekeeping to do now:

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


NEXT

You Java is out of date - it should be version 6 update 18

Press the Windows Key + R to open a run box > copy/paste the following text into the open run box > javacpl.cpl
> Press Enter > Select the Update tab > Click Update now

Now go to Programs and features and uninstall Java version 6 update 16 if it is still there (it should have been overwritten by update 17 but is still showing as on your system for some reason?)


NEXT


Set a new restore point

  • press the Win key on the keyboard, type Restore then press enter to get to the System Restore section.
  • Click "Create a restore point" Click on the "Create" button to create a new restore point. You may be prompted for permission to continue - ALLOW it to continue. You'll be prompted for a name, and you might want to give it a useful name that you'll be able to easily identify later.
  • Click the Create button, and then the system will create the restore point.
  • When it's all finished, you'll get a message saying it's completed successfully.
  • You will now have a new restore point

Then remove all previous Restore Points
  • Click Win key on the keyboard, type cleanmgr to access the disk cleanup
  • choose all files on the computer, then choose the C: drive, press OK Disk cleanup calculates the files, this takes a few minutes > another menu will pop up.
  • At the top, click on the More Options tab, under System Restore and Shadow Copies group,
  • Click the Clean up button,
  • Vista will ask you if you’re sure, click on the Delete button, click OK > Delete Files

NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.



    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.


  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Before I start on all of those tasks, I will paste the contents of that autorun. Looks pretty malicious :P autorun.inf [AUTORun] AcTIoN=Open folder to view files SHeLlExEcUtE=zoUwUo.exe iCon=%sysTEmRooT%\systEm32\SHeLl32.dll,4 uSEaUTOPlAY=1 Should I delete it?
Sorry I didn't read all of your post, thank you very much for your time and I hope that I can repay you for your gratitude one day. I will delete that file since I don't need it, and it seems like it is calling a malicious file that doesn't exist anymore. Thank you again, CatByte. Cheers, Tim.
Hi,

I need to add one more thing for you to do:

After resetting your router, it is important to set a non-default password, and if possible, username, on the router. This will assist in eliminating the possibility of the router being hijacked again.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI