Persistant Google Redirect Malware

Hello everyone. I have been infected with malware! It initially began with some aggressive advertising through the computer audio and something called "windows defender" or something like that telling me about "critical issues" that had to be fixed. I ran a google search that told me about the malware. I then downloaded many anti-virus programs and removal kits.

I think the fall out from the removal kits and anti-virus programs removed the virus, but there are some lingering issues that need to be fixed. I think there are some bad files still on my computer. Google still re-directs me when I click on a search result. It redirects me to what appears to be random websites but I am not sure. I have 2 logs that I copy and pasted below. Any help would be very much appreciated!

I hope this stuff helps! Please let me know whatever I can do to help.


I am operating Windows Vista!

Is there anyone out there who would be willing to assist me?

A new "rogue security" item opened, listed as "vista security 2011". I'm running a whole mess of anti-virus programs to try and fix it (namely ParetoLogic PC and AVG) but neither seem to be catching the key problem!

A little more background on my situation. I have TDSSKiller, which I have tried to run (it would not load). I tried to re-name it and also change the extension from .exe to .com, it still did not run. Initially, around April 11 perhaps, I must have been infected. All of my files went hidden (even start menu). I've since corrected that so that I can see my files again. AVG, when ran, said volsnap.sys perhaps has been infected. I ran a program called Malwarebytes Anti-Malware today; 1-2 trojans are found and eliminated. I think the Vista Security 2011 may have been eliminated, but the re-direct persists. I've deleted the Java history earlier today as well. I'm going to run CCleaner as well to clear out temp internet files and all else that it can wash out (except for the log files, I will keep those). I've ran rkill also before running TDSSKiller (which I have since renamed to 123abc.com and also taxseason.exe). I downloaded combofix and tried to run that, however the last time I ran it I received a BSOD so I am now thinking that it IS a rootkit and if I were to run it again (even though... I ran a scan for it, now the name escapes me,... but a scan I ran came back showing "0" rootkits on the system. There is an online scan called EMET or SMET or something of the likes that I am going to try next. If that scan does not work then I may try to re- download and install combofix, although I would rather wait until I hear a response. But I, like everyone else on these boards, is at the end of my rope computer-virus-wise and am willing to take on more risk and go to desperate measures! I'm going to keep at it, and will be able to actively respond to any questions or requests from anyone who will help. I work bankers hours out of the midwest, so after 5PM is the best chance to get me by the home computer. Some background on the machine: I'm running Windows Vista Home Premium and it is an HP, 32bit operating system. Thank you! -Kevin

ESET is the name of the online scanner. I also just now received a Internet Explorer Script Error "http://cdn.onescreen.net/os/static/pixels/miva2.js"

I think the most frustrating thing right now is not being able to run TDSSKiller.exe. I keep reading that this is the fix for the issue I am having! I just tried to run it in safe mode but to no avail.

Ok last update before I go to bed. I was reading this link: My link and it told me to look in the device manager for a tdss component. I couldn't find one, but I did see under storage volume shadow copies about 26 copies of the generic volume shadow copy. I also saw 2 storage volumes. I don't know whether that means anything pertaining to this but I have a feeling that the volsnap.sys is the culprit here. I have to go to bed. Sorry for my persistence.. I feel like I'm doing more harm than good, but despite all the frustration... I have to admit I am enjoying learning about how everything works.

Goodnight Bleepingcomputer!

I ran ESET Online Scanner and it found the following: C:\Windows\System32\Drivers\volsnap.sys has a threat associated with it. Win32/Olmasco.E trojan. It is unable to clean.

Another update: I ran Microsoft Windows Malicious Software Removal Tool - Apr. 2011 which has identified and partially removed "Virus: Win32/Alureon.K". Man this computer is infected!

Posted 08 May 2011 - 02:11 PM

Microsoft Consumer Security Support Center fixed my problem free of charge in about 2 hours time. I appreciate all the work that everyone does here, but this may be a good place to re-direct some of the high volume of issues that this wonderful forum sees!

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
