Can't get rid of google redirect, help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Swisher, Nov 26, 2010.

  1. Swisher

    Swisher Private E-2

    Hello,

    I am another victim of the google redirect problem...your help would be greatly appreciated. I've researched and tried many things, but nothing is working. :cry

    Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    After doing the above, if you still have problems, continue with the below.

    Please read ALL of this message including the notes before doing anything.


    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide

    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Swisher

    Swisher Private E-2

    Hello,

    I spent all day downloading and running all the programs requested and unfortunately, I'm still having problems :( I had success running all programs except for Root Repeal. After scanning for a while, an empty error box would pop up (meaning the top of the box said error, but no message.) I tried running the program three times, no success. I will attach however, all of the other logs from the other programs. Please let me know if I've forgotten something, or what you think I can do to successfully run Root Repeal. I will reply with one additional attachment.
    I am still getting the google redirect. For example, I've tried to click on facebook and this is what pops up in the google redirect search box
    http://01641774626.98.channel.faceb...tic.ak.fbcdn.net/rsrc.php/zU/r/RSB9Uj_VkQG.js
    It seems pretty random on whatever I'm searching or clicking on. I'd say this problem has been occurring for about a month.
    Thanks for your help!
     

    Attached Files:

  4. Swisher

    Swisher Private E-2

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what the problem is! That is a link to this thread.

    Do you have a router connected? There are many infections known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    Did that help? If not, what browser are you using when being redirected? Have you tried more than one browser? Also try booting in safe mode and tell me if you still get redirected.

    You have multiple antivirus programs installed. As stated at the beginning of the READ & RUN ME, you MUST NOT do this. You have Microsoft Security Essentials and McAfee installed. You need uninstall one of these immediately and then reboot. If you decided that you want to remove McAfee then make sure you uninstall both of the below:
    • McAfee Security Scan Plus
    • McAfee SecurityCenter
    What is the below for?
    O4 - Startup: RT-Updater.lnk = C:\Users\Luevano\Desktop\Desktopshit\VCDS\VCDS.EXE
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One more observation. I see the below in your c:\windows\win.ini file. Do you know what this is for? If not, you may want to delete these lines and reboot.
     
  7. Swisher

    Swisher Private E-2

    Ok, I do not have a router connected, so no help there. I use internet explorer as my browser and have not tried using another browser however I did reboot in safe mode and seemed to have no problems, no redirects at all.

    Also, I did uninstall Microsoft Security Essentials yesterday. I had actually done it before I sent the logs to you, so I am now just running McAfee.

    The program that you enquiried about O4 - Startup: RT-Updater.lnk = C:\Users\Luevano\Desktop\Desktopshit\VCDS\VCDS.EXE is a program we installed. It's an electronic diagnostic/service manual for our vehicles.

    I did delete the lines you posted from my c:\windows\win.ini file and it didn't help either...still redirects.
    I also notice that my recycle bin has disappeared? Also, there are now 2 notepade icons on my desktop named desktop.ini??

    Thanks for the help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then something you are running in normal mode is the source of your problem. Are you sure it is really redirects? Give an exact example of what you do and exactly what happens? And where you are redirected too?

    Have your tried running IE with no Add-ons. Right Click on the IE icon and select Start Without Add-ons

    Not according to the logs you attached! It was still installed and running in them.


    Nothing deleted your Recycle Bin. It still shows in your logs in your C folder. Perhaps you some how have elected not to show it on your Desktop. Try the below.

    Right-click on the Desktop, click Personalize, and in the left pane, click Change desktop icons. In the Desktop Icon Settings dialog, enable the Recycle Bin checkbox
    Click OK.


    Normal at this time because hidden files are enabled for viewing and the one from your account and the one from the All Users account are both showing.
     
  9. Swisher

    Swisher Private E-2

    Hello,

    I tried running IE with no add-ons and I don't seem to get the redirects.
    The re-directs are very random. I could click on a favorite link, or just type in and address or click something on a web page and get redirected. All of a sudden it will redirect to google's website telling me that "my search didn't match any documents" and it has the web address I'm trying to go to. I've attached an example of what it says.

    Thanks.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. Swisher

    Swisher Private E-2

    Finally!!! I think it is gone! Sorry it's been so long since I replied, but it took quite a while to trial and error and do some browsing for a while to see if it worked for good. Thank you so, so much for all of your assistance. You guys are great. Can you tell me what settings I need to change back that we adjusted through this process please? For example, I still have the two desktop.ini files on my desktop... Cheers!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Which addon was the source of the problem?



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds