BleepingComputer.com: Help with removing Google Redirect virus

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Help with removing Google Redirect virus

#16 User is offline   DrifterUK 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 21
  • Joined: 14-August 11

Posted 20 August 2011 - 06:39 PM

Ok, results of the ESET scan

Quote

C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\2ea9168f-3e5e3f31 multiple threats deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\4995624f-3a0561ba a variant of Java/TrojanDownloader.OpenStream.NBF trojan deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\b207791-15301d28 multiple threats deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\2f03ffdd-14fe0733 Java/TrojanDownloader.OpenStream.NCA trojan deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\4507c520-572e6fa9 multiple threats deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\1713d0c4-2ad2c6d3 multiple threats deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\473a5bc4-2f07f077 Java/TrojanDownloader.OpenStream.NCA trojan deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\1eeb5e69-45275205 Java/TrojanDownloader.OpenStream.NCA trojan deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\775a696b-67ff3f23 Java/TrojanDownloader.OpenStream.NCA trojan deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\75429a70-6ce4d1be Java/TrojanDownloader.OpenStream.NCA trojan deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\6e97d631-3ff1baf3 Java/TrojanDownloader.OpenStream.NCA trojan deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\375bfbf5-31a0349c multiple threats deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\39dc42c6-1b216197 multiple threats deleted - quarantined
C:\Users\Drifter\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\d8bba49-533c899e multiple threats deleted - quarantined


#17 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 20 August 2011 - 06:48 PM

Update Adobe Reader

You can download it from http://www.adobe.com/products/acrobat/readstep2.html
After installing the latest Adobe Reader, uninstall all previous versions.
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.

====================================================================

Your computer is clean Posted Image

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll remove all old restore points and create fresh, clean restore point.

Turn system restore off.
Restart computer.
Turn system restore back on.

If you don't know how to do it...
Windows XP: http://support.microsoft.com/kb/310405
Vista and Windows 7: http://www.howtogeek.com/howto/windows-vista/disable-system-restore-in-windows-vista/

2. Make sure, Windows Updates are current (including Service Pack 1 installation!!!)

3. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

4. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

5. Run Temporary File Cleaner (TFC) weekly.

6. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

7. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

8. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

9. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#18 User is offline   DrifterUK 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 21
  • Joined: 14-August 11

Posted 21 August 2011 - 04:22 AM

Ok thats all done. My laptops now running faster than it has been for a while :thumbsup:

Thankyou so much for all your help with this :) I would have never been able to get rid of that stuff without your help

#19 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 21 August 2011 - 10:44 AM

You're very welcome Posted Image
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users