Avast didn't catch "AllCheapPrice" virus. Need help removing.

I may have hard-deleted the file. It’s not on C:\ and it’s not in my Recycle Bin.

Things appear to be stable now since I ran FixMBR, but now I’m having to undo the damage left behind.

I’ve discovered that Internet Explorer no longer recognizes “Google.com” nor my bookmark/favorite to it. Clicking the link or typing the URL by hand does absolutely nothing (if you recall, the virus redirected every search result to “4shared.com”). Google still works in Firefox though.

Not sure how to fix this.

Do you have a proxy set ?
Has your Host file been corrupted ?

Not using a Proxy. Not sure how to check the Host file or where it even is. :frowning:

Run a quick scan with OTL and I will check

Download OTL to your Desktop
Secondary link

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif

[*]Select All Users
[]Select LOP and Purity
[
]Under the Custom Scan box paste this in

netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir “%systemdrive%*” /S /A:L /C
/md5start
rpcss.dll
/md5stop
CREATERESTOREPOINT

[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs

Thanks. I’ve attached the OTL.txt log. No “Extras.txt” was created.

No proxies or host hijack there, I would recommend that you reset IE and see if that clears the error

Control Panel > Internet Options > Advanced tab

That worked, thanks.

(The virus also made other changes that I was able to fix, like disabling “show file extensions”. What a nasty & annoying piece of… well, you know.)

Thx.

Any further problems ?

So far, so good. Though it did take me a few days to discover that one remnant.

ATM, my biggest concern is only how to prevent it from happening again. Despite being a well-experienced tech, having Avast installed and doing the occasional spyware sweep, something nasty still managed to find its way onto my PC

Set Avast to hardened mode and scan for PUP’s

If you download programmes from places like CNet then Unchecky would be useful

A small tool that may help when you download programmes

http://unchecky.com/

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder

Right click on the Unchecky_setup
http://i1059.photobucket.com/albums/t432/cinjo23/uncheckysetupicon.png
or folder and choose to Run as Administrator

Once open click the Install button.

http://i1059.photobucket.com/albums/t432/cinjo23/uncheckysetupwindow.png

Then click on Finish

http://i1059.photobucket.com/albums/t432/cinjo23/uncheckyfinishsetupwindow.png

Unchecky is now installed and will help you keep unwanted check boxes unchecked :wink:

Thanks. Looks like a useful program. I’m pretty good about catching those unwanted app checkboxes when installing new software, but bear in mind, this took place attempting to simply download from a website without the software ever actually being downloaded because it was no longer available (can’t even remember what it was now.)

Once you are happy then remove the tools on the system

Subject to no further problems :slight_smile:

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Download and run Delfix

https://dl.dropboxusercontent.com/u/73555776/delfix.JPG

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG

Malwarebytes.

Update and run weekly to keep your system clean

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe :wave:

Thanks. I’ll update the post if anything else turns up.