![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I've been having some virus issues on the computer my kids use, mostly because they like to play online games, and I can't stop them from clicking on those "you might have won" pages. We are working on that. In the meantime, they got this "Incredibar" on google chrome that won't install in any of the usual ways, and was not caught by any of the virus scans I did. I tried to manually uninstall, and that worked on Firefox and IE, but not on Google Chrome. I'll post my logs.
|
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
More Logs
|
|
#3
|
||||
|
||||
|
iLivid <--- Uninstall using Revo Uninstaller. (Instructions below)
Try Revo Uninstaller. Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished): Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
After clicking Fix exit HJT. Download and run OTM. Download OTM by Old Timer and save it to your Desktop.
Code:
:reg
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54B02808-B60E-44CD-A72D-9865117E4E62}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}]
:Files
C:\ProgramData\SpeedMaxPc
:Commands
[emptytemp]
[Reboot]
NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#4
|
|||
|
|||
|
This came up in a window when I had a reboot.
All processes killed ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54B02808-B60E-44CD-A72D-9865117E4E62}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54B02808-B60E-44CD-A72D-9865117E4E62}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. |
|
#5
|
|||
|
|||
|
Here is the log from MGTools
|
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Hi, again,
Its still on Google Chrome. Also, there is this Babylon thing on my IE. The only thing that works perfectly is my Firefox browser. There are no other signs of weirdness on my computer at this point. At one point, however, the Firewall was disabled. My husband fixed it some how, but I'm wondering if that is related. Thanks! |
|
#7
|
|||
|
|||
|
OK. I decided to do things another way. I uninstalled and reinstalled both Firefox and Chrome. I used Revo uninstaller to remove each browser, and then reinstalled them. Now, they seem to be clean. At least, they are going much faster and no more Incredibar. I still have "babylon" in IE, but it only comes up as the automatic search if I type an incomplete URL. There is no way to change the default and I cannot delete the "Babylon" reference from the IE menu.
|
|
#8
|
|||
|
|||
|
Never mind. Its back. Downloading Chrome worked, but now the incredibar is back again. It shows up with I do a search.
|
|
#9
|
||||
|
||||
|
Now let's flush the Java Cache
Now let's flush the FireFox Cache To flush your FireFox Cache:
Now let's flush the Internet Explorer Cache To flush your Internet Explorer Cache:
Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
to the registry. If you do not get a success message, it definitely did not work. For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Enter System Recovery Options. To enter System Recovery Options from the Advanced Boot Options:
To enter System Recovery Options by using Windows installation disc:
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Oh the irony - Google Chrome won't load Google Search | ithryn | Software | 1 | 04-26-12 17:09 |
| Google redirect virus but only in google chrome... | zdavies | Malware Removal | 5 | 08-12-11 15:11 |
| Google Chrome/Firefox google search redirect virus help. | time_warrior66 | Malware Removal | 3 | 07-12-11 11:54 |
| Google Redirect malware in Google Chrome browser only | zicozak | Malware Removal | 10 | 04-05-11 20:59 |
| Google Chrome Won't Load, Google Search re-directing.... | geoffclark | Malware Removal | 25 | 05-22-10 22:20 |