Google redirect virus(please help)

Discussion in 'Malware Help (A Specialist Will Reply)' started by drp5018, Jul 18, 2010.

  1. drp5018

    drp5018 Private E-2

    I have the google redirect malware/virus infectin my computer. I have followed all previous steps that comply with the windows 7 (64-bit) malware removal instructions in the removal guide and still no luck. Could you please help me fix this annoying problem? Any logs needed I will supply upon request and direction of getting said logs.

    Thanks for your time and support
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the requested logs:
    SAS
    MBAM
    C:\MGLogs.zip
     
  3. drp5018

    drp5018 Private E-2

    Thank you for helping me with this problem. Attached are my logs. I have noticed the frequency of the redirect dramtically decreased with the running of the SAS and cleaning my computer. If this info helps the address in the address bar goes something like redirect5.google. when the redirect problem occurs. Also I am running Windows 7 64-bit and when I run the MGtools a non compatable issue arises then it runs the program and gives me the MGtools.zip file and creates a MGtools folder in my C drive. I attached a copy of the command prompt and what it says while it ran if that is of any use. Finally I am unable to update the Malware bytes program for some odd reason so my definitions are the 4-29-2010 version.

    Thank you for your time and support.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If the MGTools folder was created, try running this:
    C:\MGtools\GRK64.bat

    Does that run to completion?
     
  5. drp5018

    drp5018 Private E-2

    Thanks that actually work and ran and I got the runkeys and they are now attached.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  7. drp5018

    drp5018 Private E-2

    The program finally ran even though a compatablity window popped up twice and got the zip file.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What browser are you using when this occurs and does it occur in other browsers?
     
  9. drp5018

    drp5018 Private E-2

    I was using the Firefox and IE browsers. The fire fox browser was always giving me the redirect so I uninstalled it and deleted the trace remains from the hard drive. The IE8(32-bit) browser would occasionally (like 1 out of every two times)redirect me and the IE8(64-bit) would rarely redirect me (I'd say 1 out of every 10 times) redirect me. I've noticed that only google will give me this problem all other browsers like msn, bing, and yahoo weren't affected.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have a google toolbar installed?
     
  11. drp5018

    drp5018 Private E-2

    No I don't have a google toolbar on IE.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So to be clear, you only have redirects when doing a search in IE or FF if you are searching thru google?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have the current version of MGtools. This issue was fixed on 07/14/2010. Please download and run the current version of MGtools
     
  14. drp5018

    drp5018 Private E-2

    That is correct the only time im redirected is when i use ie or ff and only on google. Here is my upgraded mgtools.zip file.
     

    Attached Files:

    Last edited: Jul 22, 2010
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Type this into your browser address bar and tell me if it takes you to google. If so, do you still get redirects?

    74.125.95.103
     
  16. drp5018

    drp5018 Private E-2

    It does take me to google but I didn't get any redirects. Though the redirects have become more sparse since I have began regular scans of super anti spyware. Also I've noticed a peculiar trait at the shutdown and rebotting of my computer. When I boot up my system the hidden files are shown so I turn this off in my control panel and apply the changes then after I shutdown my computer and boot it up the next time it'll show my hidden files again. This happens on occasion. Not sure if it'll help but at least it's more info to go off of.
     
    Last edited: Jul 23, 2010
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you were previously going to google by way of a bookmark, then delete that bookmark. Let me know if you get redirected again.
     
  18. drp5018

    drp5018 Private E-2

    Just got hit with some trojan Kapersky said it was from MGtools said it was the Trojan-Dropper.Win32.Agent.cmdw . Kapersky took care of it but is there something wrong with MGtools? Should I worry?
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is nothing wrong with MGTools. It is a false positive from Kaspersky. Are you still having problems?
     
  20. drp5018

    drp5018 Private E-2

    Still getting the redirects with the 32 bit version of ie8.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try uninstalling it, then run CCleaner ( both the cleaner and the registry--> make the backup when prompted) and then reinstall it. See if that works.
     
  22. drp5018

    drp5018 Private E-2

    Sorry it took a long time to respond but I unistalled the browsers and used ccleaner and still redirects are occuring.Any other ideas?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is IE the only browser that is giving you re-directs now? Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  24. drp5018

    drp5018 Private E-2

    IE8 is still giving me the problem also it's the only web browser that i have installed at the moment.here are the zip logs
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Please check these instructions for resetting your proxy settings ( delete them ):
    Change Proxy Settings.

    Now download and install Firefox to see if that also gives you redirects:

    Get it here: Mozilla FireFox

    Tell me how that goes.
     
  26. drp5018

    drp5018 Private E-2

    I did do all the required things and still getting redirects but only from google. I read about people's modems being infected is this a possibility?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually it is routers that are being infected since they have the ability to provide DNS functions.

    If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds