Google Redirection Problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sall, Aug 17, 2011.

  1. sall

    sall Private E-2

    Hi
    I was wondering if anyone could help me get rid of the google redirection virus. I've done the steps mentioned in chaslang's "Fixing Google Redirection/hijacking and other redirection problems" guide and unfortunately the virus is still on my computer.
    Attached are my logs. Any advice/help would be much appreciated!
    Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this drive:
    298 GB \\.\PhysicalDrive1 MBR Code Faked!

    Is it a second hard drive or an external hard drive?
     
  3. sall

    sall Private E-2

    Yeah, that's my external hard drive. Is that where the problem is?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am assuming you don't have an installation disc. You can create a disc to access the Recovery Environment from here ( choose the one that corresponds with your system IE 64bit or 32bit):
    http://digiex.net/downloads/downloa.../2660-windows-7-64-bit-x64-recovery-disc.html

    http://digiex.net/downloads/downloa.../2659-windows-7-32-bit-x86-recovery-disc.html

    You can use ImageBurn to create the disc.

    Boot to the bios and change the boot order to cd/dvd as first boot device. Put in the disc and reboot. Once you are in the Recovery Environment, type this at the command prompt:
    bootrec.exe /fixmbr \device\harddisk1

    Then type exit and reboot to normal mode. Re-run MBRCheck and attach the new log.
     
  5. sall

    sall Private E-2

    Ok I did the steps you said and entered the command prompt. But when I did the MBR check it still said the same thing (MBR code faked)...

    Here is my log:
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 1 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.
     
  7. sall

    sall Private E-2

    Alright here are my logs:
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That also did not work. About the only way to remove the infection is to repartition the drive. So save your data to another drive and use one of these tools to repartition the drive:

    diskpart.exe - from the Windows Recovery Console
    Examples of using Windows diskpart.exe >> http://support.microsoft.com/kb/300415

    GParted - http://gparted.sourceforge.net/livecd.php - MGs link: GParted Live

    Parted Magic - http://partedmagic.com/doku.php

    Partition Logic -http://partitionlogic.org.uk/

    Cute Partition Manage - http://www.cutepm.com/
     
  9. sall

    sall Private E-2

    I've downloaded and setup Gparted but I'm a little lost about what I need to to do. Can you give me some guidance maybe about how to repartition? I'm really not that knowledgable about how this all works and don't want to make it worse or anything...
    Thanks for your help so far by the way!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please post in the software forum for assistance with running that program and or assistance with repartitioning the drive. This is not really under the purview of the malware forum. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds