Google Redirect Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by tomkat2006, Dec 20, 2010.

  1. tomkat2006

    tomkat2006 Private E-2

    Ive got this on my XP system... and this system (Vista) its quite possibly the most annoying virus Ive ever come acrosss and just cant get rid of it. Im writing this thread to see if there's a definitive solution out there?

    Ive tried the following proggies to eliminate it:

    combofix
    spybot s&d
    superantispyware
    antimalware bytes
    avg scanner
    combofox & frontline registry solution
    hitman 3.5



    all the above find viruses and delete them... but on the reboot they're still there.
    Hitman 3.5 (which used to fix the issue) deletes windows files so when you reboot the system just restarts continouslly until you repair the windows folder with the original disc /r command.

    Ive no ideas left.

    Help!
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Please read ALL of this message including the notes before doing anything.

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!

    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message

    Then - Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and then attach the requested logs to your next reply when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    * Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated - our system works the oldest threads FIRST.
     
  3. tomkat2006

    tomkat2006 Private E-2

    logs...
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to attach the following logs from running the following for Dr Moriarty:

    • Malware Bytes
    • RootRepeal
    • MGTools ---> C:\MGlogs.zip
     
  5. tomkat2006

    tomkat2006 Private E-2

    malware bytes log
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you attach the last two logs that the READ & RUN ME and also Kestrel13! requested then dr.moriarty will be able to continue with you.
     
  7. tomkat2006

    tomkat2006 Private E-2

    ok when trying to obtain the rootrepeal log the system scans then crashes a few mins in, when restarting this error occurs:

    Windows could not start because the following file is missing or corrupy <windows root>/system 32/hal.dll
    PLease reinstall a copy of the above file.


    If I shut fown the PC via off button then back on, I can get back into windows, simply restarting shows in BIOS that my entire HDD is not visible at all under the SATA options - just thr CD ROM.

    Ive tried twice and cant get this part of the walkthrough to work.
    Advice to proceed please.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the READ & RUN ME instructions at the very beginning, just skip it and continue. ;)
     
  9. tomkat2006

    tomkat2006 Private E-2

    got it working now, must have been teatimer..
     

    Attached Files:

  10. tomkat2006

    tomkat2006 Private E-2

    had probs running this too, ran for around 30mins with nothing happening, mglogs is on the hd although no "finished" message came up at any point..
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because it never finished. Let's make sure you have the current version. Download this MGtools and save it to your Desktop. Then SHUTDOWN all protection software and make sure that you have disable UAC and rebooted at least once since disabling then run MGtools.exe by right clicking on it and selecting Run As Administrator. See if it runs to completion this time.


    By the way, Are you still having malware problems? TDSSkiller removed your redirect issue.
     
  12. tomkat2006

    tomkat2006 Private E-2

    still having issues yes, will try mgtools now...

    also same issue happening on a different pc (xp OS) so getting logs for those too, I ran tskiller first and it found nothing... yet the redirect virus is VERY prominant on that machine. Ill start a new thread for that one when I have the logs.
     
  13. tomkat2006

    tomkat2006 Private E-2

    mgtools worked this time, logs attached
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are both systems running through a router? Have you tried connecting directly to your modem and tell if the redirect issue stops?
     
  15. tomkat2006

    tomkat2006 Private E-2

    both are running through routers, can you explain what I need to do as I dont understand.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is a possibility your router is infected. Unplug your computer from the router (if you are not going wireless). Then plug it directly into your modem. If the redirects stop, then you need to reset the router. There is a small recessed button on either the back or the bottom to reset it to factory setting. If you had any security settings, you will need to re-enter that info.

    Also check this:
    Change Proxy Settings.
     
  17. tomkat2006

    tomkat2006 Private E-2

    its a dsl combo router would the same rule apply?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please start a new thread for your other PC. We can only work on one PC in a thread to avoid confusion.

    You need to go back to step 4 of the READ & RUN ME and complete the instructions for MSconfig that you skipped. Then reboot. After reboot, you need to do the below.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    What are the exact/specific current problems you are having with the PC we are currently working on in this thread. I see confusion already occurring now due to being side tracked with other topics that TimW is responding to. Please on work on one issue at a time.
     
  19. tomkat2006

    tomkat2006 Private E-2

    mgtools log
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach a log. Also you need to answer the question in my last message.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds