nenena: (Default)
nenena ([personal profile] nenena) wrote2009-03-11 07:48 pm

Plea for HALP!

Well, I've got the Google Installer virus. Have since yesterday. (Three guesses why). I've spent hours this evening trying to fix it myself, but no dice. Here's what's going down:

1. I can't fill out any sort of forms in Firefox, including entering search terms into Google, making posts or comments on LJ or any other forum, etc.

2. Internet Explorer is working fine, though.

3. Pretty much every malware removal, anti-hijack, or anti-virus help website that I can find via Google is BLOCKED (fake-404'd) by the virus. Yes, it's one of those motherfuckers.

4. When I reboot in Safe Mode, the internet is completely inaccessible, regardless of what browser I'm using.

5. AVG is up-to-date but can't find the virus or any trace of it when I run a scan. Spybot crashes when I try to start it up. So does HijackThis.

And yes, I know that it's the Google Installer virus, because I keep getting error messages that "Google Installer.exe" has crashed or whatever. I have no idea where Google Installer.exe is located on my computer, though. Windows Search can't actually find ANY files with the words "google" or "installer" in their file names (hmmmmmmmm, that can't be right), so Windows's Search feature has apparently been compromised, too. This is true in normal or in Safe mode, either way.

I've just wasted five hours trying to fix this crap, and I literally have no idea what to do next. I can't generate an HT log, I can't visit any spyware removal forums, so I'm totally stuck.

If anybody reading this could offer some helpful advice, it would be muuuuuuch appreciated. Or hey, if any kind soul would be willing to do a search for "Google Installer removal" and C&P me the helpful results in the comments here, that would be awesome. I've been searching using Google and Yahoo, and apparently there are a LOT of helpful-looking results for that particular search string... It's just that every single link I click on reverts me to the fake-404 error. Dammit.

Edit of TRIUMPH: Yaaaaaaay, fixed!!! Thank you, [livejournal.com profile] spirit_albarn!!!

[identity profile] spirit-albarn.livejournal.com 2009-03-11 11:31 am (UTC)(link)
This is from a thread on Google's Chrome forums:

"Just an update-- removal by just deleting the registry key:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ "GoogleUpdate.exe"
did it for me.. no more problems there following a restart. "

"This is a result of spyware. I was on another forum and got some advice. I used a proxy site www.opencity.us or www.boomproxy.com to find anti-spyware cos the spyware would crash Internet Explorer everytime most times when I searched for anti-spyware. I found SuperAntiSpyware which i downloaded and ran a few times. Removed all the spyware and now i'm using Google Chrome as I type this. Alternatively you can use AntispywareBot which i've just downloaded and am going to scan with just to crosscheck nothing is left on my pc. If you already have anti-spyware, it's best to remove it when downloading a new one cos they can interfere with each other unless they are ones you don't have to download but can run from the web."


One of the Google employees responded and said that the two above posts were the correct routes to take. Kick that virus' ass!

ext_6355: (Default)

[identity profile] nenena.livejournal.com 2009-03-11 11:59 am (UTC)(link)
(I'm operating with System Restore disabled, FTR.)

I still can't run HT, so I tried using RegEdit to delete the GoogleUpdate key. After several reboots, it's still there.

I tried downloading SuperAntiSpyware, but it crashes when I try to open it. But! This idea of using a proxy to access anit-spyware sites is EXTREMELY useful, and I feel stupid for not thinking of it before. I'm surfing around now, trying to see what I can find.

AntispywareBot actually is spyware, I wouldn't recommend it to anyone. ^^;;

Anyway, thank you so much for your help! I haven't kicked any virus ass yet, but I appreciate being pointed in the right direction.
ext_6355: (Default)

[identity profile] nenena.livejournal.com 2009-03-11 12:23 pm (UTC)(link)
Update: ComboFix did the trick. I WIN!

And it is very, very much thanks to you. I tip my hat to you, kind stranger from the internet. Thank you!!

[identity profile] spirit-albarn.livejournal.com 2009-03-11 09:19 pm (UTC)(link)
It's only what I owe you~

[identity profile] saw-mouth.livejournal.com 2009-03-11 06:01 pm (UTC)(link)
wow that is creepy and stalker-like of you and I DIDN'T KNOW OF THIS JOURNAL UNTIL I READ THIS POST

way to keep me on the same page

chainsaw gtfo

[identity profile] spirit-albarn.livejournal.com 2009-03-11 08:20 pm (UTC)(link)
Look I knew you were in bed already so who else was gonna help her? I HAVE NO REGRETS.

[identity profile] lost-angelwings.livejournal.com 2009-03-11 02:40 pm (UTC)(link)
Yay! I'm glad you fixed it! :] I know one of the scariest times for me is the moments when I have a virus and I dunno how to get rid of it or what to do and I'm just sitting there panicking :(

[identity profile] the-terrible.livejournal.com 2009-03-11 11:57 pm (UTC)(link)
O.O;; I wasn't aware of a Google Installer virus... thanks for making me aware of it!

[identity profile] hauntedreality.livejournal.com 2009-03-12 12:11 am (UTC)(link)
Eck! That sounds awful. I had really aggressive adware once that I had to completely wipe my computer and start over because of. Not cool. Viruses are eeeevil.