TechSpot

Plethora of Malware (Google Redirect, too) 8 Steps

By Liam414
Nov 18, 2009
  1. I've been trying to figure out how to fix this for a few days now. I have the annoying Google Redirect Virus, as well as something that prevents my computer from rebooting in Safe Mode. Any help is GREATLY appreciated.
     
  2. raybay

    raybay TS Evangelist Posts: 7,241   +9

    A plethora is a lot.
    You have at least 7 registry items infected, two folders, and two files. 10 serious Spam,
    I would run these programs again, then try SAFE MODE once more...
    Looks like they are jumping back in from memory at time of reboot.
     
  3. Liam414

    Liam414 TS Rookie Topic Starter

    I reran the programs, nothing new popped up, still no dice on safe mode. When I try to boot in safe mode I get a blue screen of death and then the computer restarts. :/
     
  4. raybay

    raybay TS Evangelist Posts: 7,241   +9

    Do new scans still show the infestations?
     
  5. kritius

    kritius TS Guru Posts: 2,084

    Download ComboFix from one of these locations:

    Link 1
    Link 2


    * IMPORTANT !!! Save ComboFix.exe to your Desktop


    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


    [​IMG]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [​IMG]


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
     
  6. Liam414

    Liam414 TS Rookie Topic Starter

    As requested.
     
  7. Liam414

    Liam414 TS Rookie Topic Starter

    Update: I can now reboot in safe mode. I went into safe mode and ran Malwarebytes and Super AntiSpyware - Malwarebytes didn't find anything, Super AntiSpyware said it found a trojan. I'm not really noticing any more random popups/redirecting, but google.com redirects to google.nl still and I can't seem to fix it. D:
     
  8. kritius

    kritius TS Guru Posts: 2,084

    1. Close any open browsers.

    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    3. Open notepad and copy/paste the text in the quotebox below into it:

    Save this as CFScript.txt, in the same location as ComboFix.exe


    [​IMG]

    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
     
  9. Liam414

    Liam414 TS Rookie Topic Starter

    ComboFix log:
     
  10. kritius

    kritius TS Guru Posts: 2,084

    1. Close any open browsers.

    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    3. Open notepad and copy/paste the text in the quotebox below into it:

    Save this as CFScript.txt, in the same location as ComboFix.exe


    [​IMG]

    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
     
  11. Liam414

    Liam414 TS Rookie Topic Starter

    ComboFix log:
     
  12. kritius

    kritius TS Guru Posts: 2,084

    Mercifies, please stop posting.

    1. Close any open browsers.

    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    3. Open notepad and copy/paste the text in the quotebox below into it:

    Save this as CFScript.txt, in the same location as ComboFix.exe


    [​IMG]

    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
     
  13. Liam414

    Liam414 TS Rookie Topic Starter

    ComboFix log:
     
  14. kritius

    kritius TS Guru Posts: 2,084

  15. Liam414

    Liam414 TS Rookie Topic Starter

    Forgive my ignorance, but why do I want to remove AVG completely?
     
  16. kritius

    kritius TS Guru Posts: 2,084

    Take your pick which to remove

    AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    2 antivirus products is never ever good, anyone who tells you differently is wrong
     
  17. Liam414

    Liam414 TS Rookie Topic Starter

    Ok, that makes perfect sense. I removed AVG from my system with the avgremover tool.
     
  18. kritius

    kritius TS Guru Posts: 2,084

    Please download DDS by sUBs from HERE or HERE and save it to your Desktop.

    Vista users. Right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    • Double click on dds to run it.
    • When done, DDS.txt will open.
    • You will receive another prompt after a while. Click Yes at the prompt. It will take another few minutes to scan.
    • When done, Attach.txt will open.
    • Please zip and attach the contents of DDS.txt and Attach.txt in your next reply.
     
  19. Liam414

    Liam414 TS Rookie Topic Starter

    DDS + Attach are attached. ;o
     
  20. kritius

    kritius TS Guru Posts: 2,084

    Sorry for the delay, how are things running?
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...