Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Google redirections... Trojan.Win32.Patched.kl

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby senshi » November 14th, 2010, 11:28 am

Hi again.

CKScanner only says this:

CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
----- EOF -----



Here is the log from HiJackThis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:27:55, on 14-11-2010
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16711)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANOTIF.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Pedro\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Software\Mozila Firefox\firefox.exe
C:\Software\Mozila Firefox\plugin-container.exe
C:\Users\Pedro\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.ipatimup.pt:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Software\Video tools\Quicktime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Pedro\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: setup_9.0.0.722_28.10.2010_22-08 Kaspersky virus removal.lnk = C:\Software\PC Health\Virus Removal Tool\setup_9.0.0.722_28.10.2010_22-08 Kaspersky virus removal\startup.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Contrl Center of Storm Media (ccosm) - Unknown owner - C:\Software\Video tools\Codecs\Storm Codec\stormliv.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Software\Cisco Systems VPN\cvpnd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Software\CDBurnerXP\NMSAccessU.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

--
End of file - 7150 bytes


Thanks.
senshi
Regular Member
 
Posts: 19
Joined: November 4th, 2010, 6:34 am
Advertisement
Register to Remove

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby askey127 » November 14th, 2010, 5:28 pm

senshi,
------------------------------------------------
Download and Run Rkill
Please download and run the tool named Rkill, which may help in allowing other programs to run.
There are 4 different versions. If one of them won't run, then download and try to run one of the other ones.
Vista and Win7 users need to right click Rkill and choose "Run as Administrator".
You only need to get ONE of these to run, not all of them.
Please download Rkill from one of the following links and save to your Desktop:
Rkill.exe
RKill.com
RKill.scr
Rkill.pif
  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If ir does not, delete the desktop entry. Then download and use the one provided in the next link.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.
-----------------------------------------------------------
Download and Run a Diagnostic Tool (MGADiag.exe) from here and save this to your desktop.
http://go.microsoft.com/fwlink/?linkid=56062
* Double-click on MGADiag.exe
* When the program has finished, click on the Validation tab and then click on Copy to Clipboard.
* Please post the results in your next reply.
-----------------------------------------------------------
Download Microsoft Security Essentials from here: http://www.microsoft.com/security_essentials/
Install the program, have it update itself and run a full scan.

Let me know how it goes.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 13903
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby senshi » November 15th, 2010, 11:21 am

RKill log:

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Pedro on 15-11-2010 at 15:17:35.


Services Stopped:


Processes terminated by Rkill or while it was running:


C:\Users\Pedro\Desktop\rkill.exe


Rkill completed on 15-11-2010 at 15:17:38.




MGADiag log:

Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Status: Genuine
Validation Code: 0
Cached Online Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-4JJQP-TP64Y-RPFFV
Windows Product Key Hash: W7I5PeTN2iJuvTTU9QmIXc6iQqY=
Windows Product ID: 89578-OEM-7332157-00043
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.0.6000.2.00010300.0.0.003
ID: {9443C125-4026-42C3-9A91-B0570C64C325}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows Vista (TM) Home Premium
Architecture: 0x00000000
Build lab: 6000.vista_gdr.071023-1545
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: 6.0.6002.16398

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 103 Blocked VLK
Microsoft Office Enterprise 2007 - 103 Blocked VLK
2007 Microsoft Office system - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_B4D0AA8B-920-80070057

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\Software\Mozila Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{9443C125-4026-42C3-9A91-B0570C64C325}</UGUID><Version>1.9.0027.0</Version><OS>6.0.6000.2.00010300.0.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-RPFFV</PKey><PID>89578-OEM-7332157-00043</PID><PIDType>2</PIDType><SID>S-1-5-21-2553703031-1697210116-371060287</SID><SYSTEM><Manufacturer>ASUSTeK Computer Inc. </Manufacturer><Model>F3Sa </Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>302 </Version><SMBIOSVersion major="2" minor="4"/><Date>20080123000000.000000+000</Date></BIOS><HWID>6C323507018400FA</HWID><UserLCID>0816</UserLCID><SystemLCID>0816</SystemLCID><TimeZone>Hora padrão de GMT(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>103</Result><Products><Product GUID="{90120000-0030-0000-0000-0000000FF1CE}"><LegitResult>103</LegitResult><Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val>ACD7202654E586</Val><Hash>fFic3JgCreGGRxyF8uMWB4R4Jcg=</Hash><Pid>89388-707-1528066-65441</Pid><PidType>14</PidType></Product><Product GUID="{91120000-0031-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>2007 Microsoft Office system</Name><Ver>12</Ver><PidType>19</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="103"/><App Id="A1" Version="12" Result="103"/><App Id="BA" Version="12" Result="103"/></Applications></Office></Software></GenuineResults>

Spsys.log Content: 0x80070002

Licensing Data-->
Versão do serviço de licenciamento de software: 6.0.6000.16509
Nome: Windows(TM) Vista, HomePremium edition
Descrição: Windows Operating System - Vista, OEM_SLP channel
ID da Activação: bffdc375-bbd5-499d-8ef1-4f37b61c895f
ID da Aplicação: 55c92734-d682-4d71-983e-d6ec3f16059f
PID Expandido 89578-00146-321-500043-02-1033-6000.0000-1442008
ID da Instalação: 100333724023043796601941501572398023971816171301176766
URL de Certificado do Processador: http://go.microsoft.com/fwlink/?LinkId=57201
URL de Certificado do Computador: http://go.microsoft.com/fwlink/?LinkId=57203
URL da Licença de Utilização: http://go.microsoft.com/fwlink/?LinkId=57205
URL de Certificado da Chave do Produto: http://go.microsoft.com/fwlink/?LinkId=57204
Chave de Produto Parcial: RPFFV
Estado da Licença: Licenciado

Windows Activation Technologies-->
N/A

HWID Data-->
HWID Hash Current: QAAAAAEABgABAAEAAwABAAAABAABAAEAeqjO8sTd8p9iHZgR8GDWd0aDBNCOAwoz3tby9NRnesboBKxWOscqhQ==

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20000
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC A_M_I_ OEMAPIC
FACP A_M_I_ OEMFACP
DBGP A_M_I_ OEMDBGP
HPET A_M_I_ OEMHPET
BOOT A_M_I_ OEMBOOT
MCFG A_M_I_ OEMMCFG
SLIC _ASUS_ Notebook
ECDT A_M_I_ OEMECDT
OEMB A_M_I_ AMI_OEM
ATKG A_M_I_ OEMATKG
SSDT PmRef CpuPm
senshi
Regular Member
 
Posts: 19
Joined: November 4th, 2010, 6:34 am

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby senshi » November 15th, 2010, 1:02 pm

Microsoft Security Essentials found a threat in wininit.exe (please see attachment).
You do not have the required permissions to view the files attached to this post.
senshi
Regular Member
 
Posts: 19
Joined: November 4th, 2010, 6:34 am

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby senshi » November 15th, 2010, 1:03 pm

Oops, this was only a quick scan, I guess. I will do the full scan later today.
senshi
Regular Member
 
Posts: 19
Joined: November 4th, 2010, 6:34 am

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby askey127 » November 15th, 2010, 4:02 pm

First thing to do is to back up ALL your important data to Flash, DVD or external Hard drives.

This infection may break your system completely if you try to Fix the corrupt files..

Make sure you know how to do a complete manufacturer's System Recovery or full Re-installation of Windows before you tell Microsoft Security Essentials to fix the problem.
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 13903
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby senshi » November 15th, 2010, 5:41 pm

askey,

The full scan with Security Essentials revealed these:

Trojan: Java/Mesdeh
TrojanDownloader: Java/OpenStream.AM
Exploit: Java/CVE-2008-5353.TD
Exploit: Java/CVE-2008-5353.VW
Exploit: Java/CVE-2008-5353.TC
TrojanDownloader: Java/Rexec.B
senshi
Regular Member
 
Posts: 19
Joined: November 4th, 2010, 6:34 am

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby senshi » November 15th, 2010, 5:42 pm

Google redirections stopped.
senshi
Regular Member
 
Posts: 19
Joined: November 4th, 2010, 6:34 am

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby askey127 » November 15th, 2010, 8:03 pm

senshi,
Consider yourself very lucky.
This infection has broken other systems.
Now be sure to back up your data to outside media.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 13903
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby senshi » November 16th, 2010, 2:00 pm

Thank you very much askey127.

Do you think that the infection was totally removed?
senshi
Regular Member
 
Posts: 19
Joined: November 4th, 2010, 6:34 am

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby askey127 » November 16th, 2010, 4:59 pm

Did you tell MS Security essentials to "Clean the Computer".?
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 13903
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby senshi » November 17th, 2010, 6:28 am

I think so. MS Security Essentials now tells me that the computer is protected.

In the History all files were removed or desinfected.
However, when it desinfected wininit.exe (I suppose it is a file needed for windows to start) I had trouble to initiate Vista and I had to do a system restore. But after the restore everything was ok and the computer protected.
senshi
Regular Member
 
Posts: 19
Joined: November 4th, 2010, 6:34 am

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby askey127 » November 17th, 2010, 11:12 am

senshi,
You need to run another Full Scan with Microsoft Security Essentials, now that you did a restore.
Have it fix anything it finds. (Make a note of any infected files found if you can.)
Let me know how it turns out.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 13903
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby senshi » November 17th, 2010, 6:03 pm

Nothing found! :o :o
senshi
Regular Member
 
Posts: 19
Joined: November 4th, 2010, 6:34 am

Re: Google redirections... Trojan.Win32.Patched.kl

Unread postby askey127 » November 17th, 2010, 7:16 pm

You should be OK.
Let me know if any other issues.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 13903
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA
Advertisement
Register to Remove

PreviousNext

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 45 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware