Google redirect virus

By kaseycs
Jun 9, 2010
  1. I have already removed AVG and I am running Avira scan now.

    What do I need to do after I compete this to get rid of this virus?
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    If you would like us to check for malware, Please follow the Preliminary Virus and Malware Removal Steps HERE.

    When you have finished, please leave the logs in your next reply for review.

    Please do not use any other cleaning program or scans while I am helping you unless I direct you to. Do not use a Registry cleaner or make any changes in the Registry.
  3. kaseycs

    kaseycs TS Rookie Topic Starter

    Logs are attached

    Hope you can help

    Attached Files:

  4. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Okay, for the record: there is no Google redirect virus! Most malware prevents the user from accessing sites they want and most people us Google to search. I have found that some people who think they are getting redirected, are just being blocked by their security from loading a bad site. That isn't a redirect, it's a security block.

    My bottom line is that I have a problem when people don't give me any information on what they are experiencing, what's happening with their system, if it's happening all of the time with all browsers and all search engines from the address bar, the search box, shortcuts and Favorites or Bookmarks.

    You originally said you removed one antivirus program and put another on on. Did you scan with the new program? Did it find anything? What did it do with what it found?

    It appears that you had McAfee security somewhere along the line and it has processes still loading. Please run this: McAfee Removal
    Reboot when finished.

    You have a Rootkit malware infection. I will write some script that should remove it. You need to run the following first:

    Please download ComboFix from Here and save to your Desktop.

    • [1]. Do NOT rename Combofix unless instructed.
      [2].Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      [3].Close any open browsers.
      [4]. Double click combofix.exe & follow the prompts to run.
    • NOTE: Combofix will disconnect your machine from the Internet as soon as it starts. The connection is automatically restored before CF completes its run. If it does not, restart your computer to restore your connection.
      [5]. If Combofix asks you to install Recovery Console, please allow it.
      [6]. If Combofix asks you to update the program, always allow.
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      [7]. A report will be generated after the scan. Please post the C:\ComboFix.txt in next reply.
    Note: Do not mouseclick combofix's window while it's running. That may cause it to stall.
    Note: Make sure you re-enable your security programs, when you're done with Combofix..
    Run Eset NOD32 Online AntiVirus Scanner HERE
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the Active X control to install
    • Disable your current Antivirus software. You can usually do this with its Notification Tray icon near the clock.
    • Click Start
    • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is checked
    • Click Scan
    • Wait for the scan to finish
    • Re-enable your Antivirus software.
    • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.
    Please leave the 2 logs in your next reply. IT would be helpful to have a description of what you are noticing.
  5. kaseycs

    kaseycs TS Rookie Topic Starter

    Removal tool link says error

    I do not go to a removal tool. When I ran the new virus program nothing came back as infected.
  6. kaseycs

    kaseycs TS Rookie Topic Starter


    Here are the logs you requested. At this time everything is working.

    Attached Files:

  7. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Custom CFScript

    • [1]. Close any open browsers.
      [2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      [3]. Open notepad and copy/paste the text in the code below into it:
    c:\program files\Hitman Pro 3.5\HitmanPro35.exe
    c:\documents and settings\All Users\Application Data\Hitman Pro
    c:\program files\Hitman Pro 3.5
    "USRpdA"= -
    "HitmanPro35"= -
    C:\WINDOWS\ServicePackFiles\i386\atapi.sys | C:\Windows\System32\drivers\atapi.sys
    Save this as CFScript.txt, in the same location as ComboFix.exe

    Referring to the picture above, drag CFScript into ComboFix.exe

    When finished, it will produce a log for you at C:\ComboFix.txt . Please attach to your next reply.
    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
    Are you aware of and still using this download from 2003? There are 21 program folders for it.
    Visio 2003 Sample: 20 Sample Diagrams
    If you are not using them, I can add them to script to be removed, so let me know:
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...