Google Redirect Virus

Miss Kristy

Miss Kristy

Posted 02 January 2011 - 02:22 PM

I have a classic browser or google redirect virus. When I click on an internet link, I am often redirected to an affiliate's website. Please help! The problem began around 12/27 or 12/28. Thank you in advance my friends!


Noviciate


Posted 02 January 2011 - 04:07 PM

Good evening. :)

Take a trip to this webpage for download links and instructions for running Combofix by sUBs.*

  • Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
  • Let me know how the PC is behaving.
* There are two points to note from the instructions page:

1) The Recovery Console.

It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete some, but not all, of it's removal tasks without the installation of the Console so, should you choose not to allow the installation, you may not get the results you hoped for.

2) Disabling your Anti-Virus.

CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for either.

So long, and thanks for all the fish.



Miss Kristy

Miss Kristy
Posted 04 January 2011 - 10:47 PM

I ran combofix and it seems to have stopped the redirecting, which is odd (but wonderful) because I ran it previous to my post and it still redirected. At any rate, it seems to be fixed....here is the log just in case I end up having problems again in the near future....thanks bleeping computer!

Miss Kristy

Miss Kristy
Posted 04 January 2011 - 11:20 PM

Bleeping Computer I spoke to soon; I am still being redirected when I click on just about any link from a search engine :( Attached is the combofix log....

Noviciate


Posted 05 January 2011 - 03:04 PM

Good evening. :)

Download TDSSKiller.zip from Kaspersky from here and save it to your Desktop.
  • You will then need to extract the file(s) from the zipped folder.

  • To do this: Right-click on the zipped folder and from the menu that appears, click on Extract All...
    In the Extraction Wizard window that opens, click on Next> and in the next window that appears, click on Next> again.
    In the final window, click on Finish

  • Please close all open programs as this may result in a reboot being necessary.
  • Double click TDSSKiller.exe to begin.
  • Click Start scan and allow the tool to do just that.
  • One the scan has completed, if the tool has identified anything allow it to carry out it's default action(s) - you'll need to click Continue where appropriate.
  • Finally, if it prompts you to reboot your machine, please click Reboot Now and ensure that your machine does so.

  • If the scan finds nothing, please click the Report button and let me have a copy of the text file that opens.
  • If you reboot your machine, the log, which i'd like to see, will be located at the root of you hard drive as C:\TDSSKiller.Version_Date_Time_log.txt.
    Please check that you get the one with the right date and time. :)

So long, and thanks for all the fish.



Miss Kristy

Miss Kristy
Posted 07 January 2011 - 04:14 PM

The scan did find a malicious item called rootkit_win32.exe. I allowed it to fix it and voila! Good as new! Thanks so much for your help, I had tried EVERY spyware removal known to man and TDSSKiller is the only one that worked :dance:

Noviciate


Posted 10 January 2011 - 03:12 PM

As this issue appears to have been resolved, this thread is now closed.

So long, and thanks for all the fish.



