Author Topic: Google Redirect  (Read 27771 times)

0 Members and 1 Guest are viewing this topic.

jeffce

  • Guest
Re: Google Redirect
« Reply #15 on: June 03, 2012, 02:13:40 AM »
Hi,

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
Code: [Select]
:filefind
*xstlvmxf.dll
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

JPF810

  • Guest
Re: Google Redirect
« Reply #16 on: June 03, 2012, 02:31:51 AM »
Here's the log

jeffce

  • Guest
Re: Google Redirect
« Reply #17 on: June 03, 2012, 02:42:23 AM »
Let's see if we can get file fixed up.

Do you have your Windows disk available if we need it?  :)

JPF810

  • Guest
Re: Google Redirect
« Reply #18 on: June 03, 2012, 02:49:22 AM »
I believe so.

jeffce

  • Guest
Re: Google Redirect
« Reply #19 on: June 03, 2012, 02:54:29 AM »
Get it out as we may need this during the following steps:
  • Click on Start, type cmd in the Start Search bar.
  • Right click on Command Prompt at the top of the window and select Run as Administrator.
  • In the Command Prompt Window, type (or copy and paste) sfc /scannow and press Enter.
The scan may take some time, so be patient. Windows will repair any corrupted or missing files that it finds. If information from the installation CD is needed to repair the problem, you may be prompted to insert your Windows 7 CD.

Reboot your system when done and see if that notification pops up again.  :)

JPF810

  • Guest
Re: Google Redirect
« Reply #20 on: June 03, 2012, 03:07:24 AM »
Verification 100% complete.
Windows Resource Protection did not find any integrity violations.

JPF810

  • Guest
Re: Google Redirect
« Reply #21 on: June 03, 2012, 03:07:56 AM »
Rebooting be right back.

JPF810

  • Guest
Re: Google Redirect
« Reply #22 on: June 03, 2012, 03:15:49 AM »
Still pops up.  Window says:

Run Dll (on title of window)
There was a problem starting C:\users\Filip\AppData\Local\Temp\MicrosoftHelp\xstlvmxf.dll

The specified module could not be found (in window)


jeffce

  • Guest
Re: Google Redirect
« Reply #23 on: June 03, 2012, 04:25:57 AM »
Ok...lets get some updates.

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then

    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
        Java Runtime Environment (JRE) version for your computer.
----------

Let me know if you have any problems with the instructions above and I will be looking for a solution for the popup you are getting.  :)

JPF810

  • Guest
Re: Google Redirect
« Reply #24 on: June 03, 2012, 05:21:19 AM »
Did everything you said, your instructions were good. Installed new Java runtime environment.

DonZ63

  • Guest
Re: Google Redirect
« Reply #25 on: June 03, 2012, 03:37:48 PM »
Jeff - check this out: http://www.prevx.com/filenames/X45623044934701293-X1/XSTLVMXF.DLL.html

I suspect there is an entry for this in startup reg key still exists and that is why OP is getting the missing message at boot time?

jeffce

  • Guest
Re: Google Redirect
« Reply #26 on: June 03, 2012, 04:15:15 PM »
@ DonZ63 >>  Thanks for that.  I have been on the ledge with that entry.  It's going to go.  :)

Hi,

Run a new backup with ERUNT and then do the following...

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

Code: [Select]
:Services

:OTL
O4 - HKU\.DEFAULT..\Run: [Microsoft Help] C:\Users\Filip\AppData\Local\Temp\Microsoft Help\xstlvmxf.dll (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [Microsoft Help] C:\Users\Filip\AppData\Local\Temp\Microsoft Help\xstlvmxf.dll (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Microsoft Help] C:\Users\Filip\AppData\Local\Temp\Microsoft Help\xstlvmxf.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1370244251-421495555-1663435379-1000..\Run: [Microsoft Help] C:\Users\Filip\AppData\Local\Temp\Microsoft Help\xstlvmxf.dll (Microsoft Corporation)

:Files
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
In your next reply let me know how your system is running and if there is the popup any longer.  Also attach the new OTL log that is made.  :)

JPF810

  • Guest
Re: Google Redirect
« Reply #27 on: June 03, 2012, 06:54:48 PM »
Perfection. 

You, good sir, are a genius. 

That run Dll error is gone and everything seems to be running smoothly.

Thank you so much for guiding me through all this.

Posting OTL log now.  Again, all my thanks!!

jeffce

  • Guest
Re: Google Redirect
« Reply #28 on: June 03, 2012, 11:59:07 PM »
Hi,

Providing there are no other malware related problems...

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D  SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees.  As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
----------

Clean up with OTL:
  • Right-click and Run as Administrator OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
----------

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Enable Protected Mode in Internet Explorer.  This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code.  To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly.  A tutorial on firewalls can be found here[/color].  **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

5. Make sure you keep your Windows OS currentWindows XP users can visit Windows update   regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems.  Without these you are leaving the back door open.

6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites.  WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

7.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
 
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

JPF810

  • Guest
Re: Google Redirect
« Reply #29 on: June 04, 2012, 07:27:06 AM »
I am more than satisfied with everything you've done for me here, I truly thank you for everything.

You may mark the problem as resolved. SUPER JOB!!! No other way to say it...YOU ARE AWESOME.

Thanks again!!