Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Google Redirect Virus  (Read 20164 times)

0 Members and 2 Guests are viewing this topic.

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Google Redirect Virus
« Reply #15 on: April 06, 2012, 05:11:36 PM »
I'm stumped. I'm going to check with a colleague about this problem.
Windows 8 and Windows 10 dual boot with two SSD's

nathdep

    Topic Starter


    Rookie

    • Experience: Experienced
    • OS: Windows XP
    Re: Google Redirect Virus
    « Reply #16 on: April 06, 2012, 06:53:58 PM »
    Ok. Thank you.

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Google Redirect Virus
    « Reply #17 on: April 07, 2012, 12:26:16 PM »
    Please download MiniToolBox to Desktop and run it.



    Checkmark the following boxes:

      • Flush DNS
      • Report IE Proxy Settings
      • Reset IE Proxy Settings
      • List content of Hosts
      • List IP Configuration
      • Lst Last 10 Event Viewer Errors
      • List Users, Partitions and Memory Size
      • [/b]
      Click Go and copy/paste the log (Result.txt) into your next post.
      Windows 8 and Windows 10 dual boot with two SSD's

      nathdep

        Topic Starter


        Rookie

        • Experience: Experienced
        • OS: Windows XP
        Re: Google Redirect Virus
        « Reply #18 on: April 07, 2012, 06:28:20 PM »
        MiniToolBox by Farbar  Version: 18-01-2012
        Ran by USER (administrator) on 07-04-2012 at 20:27:20
        Microsoft Windows XP Professional Service Pack 3 (X86)
        Boot Mode: Normal
        ***************************************************************************

        ========================= Flush DNS: ===================================


        Windows IP Configuration



        Successfully flushed the DNS Resolver Cache.


        ========================= IE Proxy Settings: ==============================

        Proxy is not enabled.
        No Proxy Server is set.

        "Reset IE Proxy Settings": IE Proxy Settings were reset.
        ========================= Hosts content: =================================

        127.0.0.1       localhost

        ========================= IP Configuration: ================================

        Intel(R) 82562V-2 10/100 Network Connection = Local Area Connection (Connected)


        # ----------------------------------
        # Interface IP Configuration         
        # ----------------------------------
        pushd interface ip


        # Interface IP Configuration for "Local Area Connection"

        set address name="Local Area Connection" source=dhcp
        set dns name="Local Area Connection" source=dhcp register=PRIMARY
        set wins name="Local Area Connection" source=dhcp


        popd
        # End of interface IP configuration




        Windows IP Configuration



                Host Name . . . . . . . . . . . . : user-ffe079d9b5

                Primary Dns Suffix  . . . . . . . :

                Node Type . . . . . . . . . . . . : Unknown

                IP Routing Enabled. . . . . . . . : No

                WINS Proxy Enabled. . . . . . . . : No



        Ethernet adapter Local Area Connection:



                Connection-specific DNS Suffix  . :

                Description . . . . . . . . . . . : Intel(R) 82562V-2 10/100 Network Connection

                Physical Address. . . . . . . . . : 00-21-9B-0B-BC-88

                Dhcp Enabled. . . . . . . . . . . : Yes

                Autoconfiguration Enabled . . . . : Yes

                IP Address. . . . . . . . . . . . : 192.168.1.4

                Subnet Mask . . . . . . . . . . . : 255.255.255.0

                Default Gateway . . . . . . . . . : 192.168.1.1

                DHCP Server . . . . . . . . . . . : 192.168.1.1

                DNS Servers . . . . . . . . . . . : 192.168.1.1

                Lease Obtained. . . . . . . . . . : Saturday, April 07, 2012 8:27:13 PM

                Lease Expires . . . . . . . . . . : Sunday, April 08, 2012 8:27:13 PM

        Server:  UnKnown
        Address:  192.168.1.1

        Name:    google.com
        Addresses:  74.125.226.196, 74.125.226.197, 74.125.226.198, 74.125.226.199
             74.125.226.200, 74.125.226.201, 74.125.226.206, 74.125.226.192, 74.125.226.193
             74.125.226.194, 74.125.226.195



        Pinging google.com [74.125.226.231] with 32 bytes of data:



        Reply from 74.125.226.231: bytes=32 time=34ms TTL=53

        Reply from 74.125.226.231: bytes=32 time=33ms TTL=53



        Ping statistics for 74.125.226.231:

            Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

        Approximate round trip times in milli-seconds:

            Minimum = 33ms, Maximum = 34ms, Average = 33ms

        Server:  UnKnown
        Address:  192.168.1.1

        Name:    yahoo.com
        Addresses:  72.30.38.140, 98.139.183.24, 209.191.122.70



        Pinging yahoo.com [209.191.122.70] with 32 bytes of data:



        Reply from 209.191.122.70: bytes=32 time=76ms TTL=50

        Reply from 209.191.122.70: bytes=32 time=75ms TTL=50



        Ping statistics for 209.191.122.70:

            Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

        Approximate round trip times in milli-seconds:

            Minimum = 75ms, Maximum = 76ms, Average = 75ms

        Server:  UnKnown
        Address:  192.168.1.1

        Name:    bleepingcomputer.com
        Address:  208.43.87.2



        Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:



        Reply from 208.43.87.2: Destination host unreachable.

        Reply from 208.43.87.2: Destination host unreachable.



        Ping statistics for 208.43.87.2:

            Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

        Approximate round trip times in milli-seconds:

            Minimum = 0ms, Maximum = 0ms, Average = 0ms



        Pinging 127.0.0.1 with 32 bytes of data:



        Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

        Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



        Ping statistics for 127.0.0.1:

            Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

        Approximate round trip times in milli-seconds:

            Minimum = 0ms, Maximum = 0ms, Average = 0ms

        ===========================================================================
        Interface List
        0x1 ........................... MS TCP Loopback interface
        0x2 ...00 21 9b 0b bc 88 ...... Intel(R) 82562V-2 10/100 Network Connection - Agnitum firewall miniport
        ===========================================================================
        ===========================================================================
        Active Routes:
        Network Destination        Netmask          Gateway       Interface  Metric
                  0.0.0.0          0.0.0.0      192.168.1.1     192.168.1.4     20
                127.0.0.0        255.0.0.0        127.0.0.1       127.0.0.1     1
              192.168.1.0    255.255.255.0      192.168.1.4     192.168.1.4     20
              192.168.1.4  255.255.255.255        127.0.0.1       127.0.0.1     20
            192.168.1.255  255.255.255.255      192.168.1.4     192.168.1.4     20
                224.0.0.0        240.0.0.0      192.168.1.4     192.168.1.4     20
          255.255.255.255  255.255.255.255      192.168.1.4     192.168.1.4     1
        Default Gateway:       192.168.1.1
        ===========================================================================
        Persistent Routes:
          None

        ========================= Event log errors: ===============================

        Application errors:
        ==================
        Error: (04/04/2012 04:28:33 PM) (Source: Application Hang) (User: )
        Description: Fault bucket -1413921487.

        Error: (04/04/2012 04:28:31 PM) (Source: Application Hang) (User: )
        Description: Hanging application firefox.exe, version 11.0.0.4454, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

        Error: (04/03/2012 06:33:04 PM) (Source: Application Error) (User: )
        Description: Fault bucket -1391902482.
        The Wep key exchange did not result in a secure connection setup after 802.1x authentication.  The current setting has been marked as failed and the Wireless connection will be disconnected.

        Error: (04/03/2012 06:33:01 PM) (Source: Application Error) (User: )
        Description: Faulting application FlashPlayerUpdateService.exe, version 11.2.202.228, faulting module FlashPlayerUpdateService.exe, version 11.2.202.228, fault address 0x0000abd8.
        Processing media-specific event for [FlashPlayerUpdateService.exe!ws!]

        Error: (04/01/2012 09:00:55 PM) (Source: Application Hang) (User: )
        Description: Fault bucket 1217514343.

        Error: (04/01/2012 09:00:52 PM) (Source: Application Hang) (User: )
        Description: Hanging application SysProt.exe, version 1.0.1.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

        Error: (04/01/2012 08:59:56 PM) (Source: Application Hang) (User: )
        Description: Fault bucket 1217514343.

        Error: (04/01/2012 08:59:53 PM) (Source: Application Hang) (User: )
        Description: Hanging application SysProt.exe, version 1.0.1.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

        Error: (03/31/2012 08:14:17 PM) (Source: Application Error) (User: )
        Description: Faulting application oasrv.exe, version 5.5.0.1557, faulting module oasrv.exe, version 5.5.0.1557, fault address 0x00004a6f.
        Processing media-specific event for [oasrv.exe!ws!]

        Error: (03/21/2012 11:36:57 AM) (Source: Application Hang) (User: )
        Description: Hanging application firefox.exe, version 11.0.0.4454, hang module hungapp, version 0.0.0.0, hang address 0x00000000.


        System errors:
        =============
        Error: (04/07/2012 08:27:08 AM) (Source: Dhcp) (User: )
        Description: The IP address lease 0.0.0.0 for the Network Card with network address 00219B0BBC88 has been
        denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

        Error: (04/07/2012 08:27:05 AM) (Source: Dhcp) (User: )
        Description: The IP address lease 192.168.1.2 for the Network Card with network address 00219B0BBC88 has been
        denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

        Error: (04/01/2012 03:01:13 PM) (Source: Service Control Manager) (User: )
        Description: The SAS Core Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds: Restart the service.


        Microsoft Office Sessions:
        =========================
        Error: (04/04/2012 04:28:33 PM) (Source: Application Hang)(User: )
        Description: -1413921487

        Error: (04/04/2012 04:28:31 PM) (Source: Application Hang)(User: )
        Description: firefox.exe11.0.0.4454hungapp0.0.0.0000 00000

        Error: (04/03/2012 06:33:04 PM) (Source: Application Error)(User: )
        Description: -1391902482

        Error: (04/03/2012 06:33:01 PM) (Source: Application Error)(User: )
        Description: FlashPlayerUpdateService.exe11.2.202.22 8FlashPlayerUpdateService.exe11.2.202.2 280000abd8

        Error: (04/01/2012 09:00:55 PM) (Source: Application Hang)(User: )
        Description: 1217514343

        Error: (04/01/2012 09:00:52 PM) (Source: Application Hang)(User: )
        Description: SysProt.exe1.0.1.0hungapp0.0.0.00000000 0

        Error: (04/01/2012 08:59:56 PM) (Source: Application Hang)(User: )
        Description: 1217514343

        Error: (04/01/2012 08:59:53 PM) (Source: Application Hang)(User: )
        Description: SysProt.exe1.0.1.0hungapp0.0.0.00000000 0

        Error: (03/31/2012 08:14:17 PM) (Source: Application Error)(User: )
        Description: oasrv.exe5.5.0.1557oasrv.exe5.5.0.15570 0004a6f

        Error: (03/21/2012 11:36:57 AM) (Source: Application Hang)(User: )
        Description: firefox.exe11.0.0.4454hungapp0.0.0.0000 00000


        ========================= Memory info: ===================================

        Percentage of memory in use: 24%
        Total physical RAM: 3326.1 MB
        Available physical RAM: 2521.16 MB
        Total Pagefile: 5210.32 MB
        Available Pagefile: 4515.76 MB
        Total Virtual: 2047.88 MB
        Available Virtual: 1974.96 MB

        ========================= Partitions: =====================================

        1 Drive c: () (Fixed) (Total:298.08 GB) (Free:280.93 GB) NTFS

        ========================= Users: ========================================

        User accounts for \\USER-FFE079D9B5

        Administrator            Guest                    HelpAssistant           
        Sharon DePuy             SUPPORT_388945a0         USER                     


        **** End of log ****

        hi150248



          Newbie

          • Experience: Beginner
          • OS: Unknown
          Re: Google Redirect Virus
          « Reply #19 on: April 25, 2012, 12:08:12 PM »
          Comments removed.
          « Last Edit: April 25, 2012, 12:19:59 PM by SuperDave »