A couple of days ago I got the dreaded google redirect problem and discovered that it was most likely the result of a rootkit infection. With help from friends who are reasonbly experienced in this area I arrived at a process that I thought had cured my system of this bug. I had also been in contact with representatives of GMER via their website and email address firstname.lastname@example.org.
The process I followed was this
Ran a full scan with McAfee Security Centre (Full Subscription Service) - no log file but I can post the report if necessary
Ran TDSSKiller which found an additional trojan and removed it. (can remember if I saved the log file on this occasion.)
Ran GMER which didn't find anything. At this time I contacted them via email as I was still experiencing redirects from google under Firefox
Under instruction from GMER via e-mail I ran MBAM and e-mail them the log. It didn't seem to fix the problem so they advised a new step
Ran aswMBR.exe with full avast signatures and provided them with the log again. At this it found lykon.exe in one of my c:\users folders. I manually SHIFT+del this file after instructions from the GMER rep.
Overnight I ran CC Cleaner with all options on including Wipe Free Space etc. This morning I ran the registry cleaner of CC Cleaner and then flushed my DNS and changed my TCP/IP to DHCP options
I then tested the results by doing some random google searches. It seemed to have fixed the problem. I shut down as I had to go out.
I returned to boot up my PC only to find that I was again experiencing google redirects.
I am currently running MBAM again with their latest db update, not that I think it'll find anything.
It's starting to get a bit tiresome as I've been at this for 3 days and wish I'd found this forum at that time rather than a few hours ago.
Any further help would be appreciated. I'm happy to start the process again or post all the logs I have of the various scans I've run.
Some other symptoms of the infection include
Disabled Windows Firewall - I was unable to start it up again until this morning after my google searches began working temporarily
Redirects generally go to www.goingonearth.com (with a search query string in the url bar)
System Windows Vista Home Premium SP2 - Updates Current
Mozilla Firefox 5
Dell XPS 630i
Edited by pangea, 22 July 2011 - 07:21 PM.