Google redirect virus

i believe i have this virus but cant get rid of it

it is also affecting other search engines, and i no longer have access to Windows Task Manager (win 7)

i am using nis 2012 - i think. i cant see how to find out. it would help if norton hadnt hidden this information.

i have tried the following:

scan with nis - clear

scan with norton NPE - clear

scan with malwarebytes antimalware - clear

ran norton removal tool for TDSS - which i gather is another name for this trojan

 

MBAM did initially find some malwares including win32.dll - i clicked ok to fix them, and then windows wouldnt boot and i had to go back to a restore point. i'm surprised it was so stupid as to remove this file.

 

please can anyone suggest anything to get rid of this thing?

 

thanks

 

Hello Dshanley

 

Welcome to the Community

 

According to a Google search, this virus can be indicative of a rootkit. I would recommend a visit to one of the free removal sites where they will work with you on a 1 to 1 basis and help you to clean up your computer. Please sign up with one of them and put the name of the virus in the topic header.

 

 

Please go to one of these free Forums for help in removing your bad malware or rootkits.


http://www.bleepingcomputer.com

http://www.geekstogo.com/forum/

http://www.cybertechhelp.com/forums/

http://forums.whatthetech.com/

(Thanks to Delph for providing the list of sites)

 

 

Please come back and let us know how you made out. Thanks.

I appear to be suffering froma Google redirect trojan of some kind.  When I click on a searched link I get a redirct to an ad or porn site.  Not evry time, but frequently (~75%).  Please help.

[Instructions are for the thread starters system only, Not another users system]

 

 

Please Read  http://community.norton.com/t5/Malware-Discussion/Malware-Discussion-Board-Guidelines/td-p/961409

 

This is to make sure the user has seen the Guidelines before starting.  

 

Even other Malware Removal forums state like

 

"you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a Malware Removal Team member, nor should you continue to ask for help elsewhere. Doing so can result in system changes which may not show it the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.
From this point on the Malware Removal Team should be the only members that you take advice from, until they have verified your log as clean."

 

 

Users have to realise these tools used can cause problems anyway, and if instructions are not followed, bigger problems can occur from deleting something that shouldn't be, the program has caused the system to freeze, the program jammed during the restart etc etc.  and so we use instructions to allow the tools to be in the correct location (so we also know) settings given so that items won't be automatically deleted, other programs disabled so things can be done without detection or conflict.

 

When the user follow instructions and things still go a little haywire, and it does happen, it is up to us to sort the extra problem out.

 

Confirm in Reply you have read and understand the Guidelines etc.

 

Quads

I have read and understand

Read Slowly and all of it.

 

Please download http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/   You need to download the 64 bit version.

 

Save it on to your desktop

 

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) On to your Desktop. Please attach back in a Reply your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

 

Quads

Here you go. 

Looks Similar to Tracur

 

Download the fixlist.txt that is attached to this message / post  Have fixlist.txt on the Desktop with FRST.exe (so same location).  The script tells FRST what to do.

DO NOT DRAG AND DROP to download the script,  it won't work for FRST (Right click on the attachment link (not the normal left click) and from the menu choose  Save As or Save Link as.)

 

 

  • Start FRST that is on the desktop  
  • When the tool opens click Yes to disclaimer. (if it still does)
  • Press the Fix button just once and wait.
  • The tool will make a log on the Desktop (Fixlog.txt) please post it to your reply (attach).

 

Quads

Done.

With Tracur, The files been moved and the registry keys deleted, the Redirects should now stop.

 

Quads

Sorry - still happening.  I just tied a google search and got redirected to

 

[Removed Link]

 

That redirect lasted for just a second, then it settled into

 

[Removed Link]

 


Edited by Quads

Go here and click on the fix it button - http://support.microsoft.com/kb/923737  (Should be able to be run or saved from Chrome also)

Then

 

With IE 
click on safety
click on Delete Browsing History
make sure all boxes are checked
click on Delete
click on Tools
click Internet Options
On the Advanced tab, click Reset (Restore Advanced Settings)
put a check mark next to Delete Personal Settings
click Reset
when complete click Close

 

  

Restart the Computer  Now see if IE stops redirecting.

 

Quads

I am receiving an error when trying to run teh MSI.  "The Temp folder is on a drive that is full or inaccessible.  Free up space on the drive or verify that you have write permission on the Temp folder."

 

It does not specify which Temp folder.  I have 92GB free on the C: drive. 

Try this bit instead to reset

 

With IE 
click on safety
click on Delete Browsing History
make sure all boxes are checked
click on Delete
click on Tools
click Internet Options
On the Advanced tab, click Reset (Restore Advanced Settings)
put a check mark next to Delete Personal Settings
click Reset
when complete click Close

 

  

Restart the Computer  Now see if IE stops redirecting.

 

Quads

Sorry - running IE9.  I found most of those settings are under Internet Options, but nothing labeled "safety".  I deleted all browsing history from the "general" tab.  I followed teh instructions as witten for resetting advanced options and restoring IE to default settings (after checking "Delete Personal Settings")

That seems to have done it.   I hit search links about 20 times without getting a redirect.

 

Thank you.

Any redirect using IE now??

 

Quads

Posted at the same time.  Is Chrome Redirecting??   I have just moved the Tracur looking files and there must have been a setting / piece for it in the Browsers.

 

Quads

I never really use Chrome so I didn;t notice if it was redirecting before.  When I oaunched it I gor an error that my profile could not be read.  The home page was set to "elta search" when it launched, which struk me as odd.  But I browsed to Google and tried about a dozen links without error.

Delta Search is a PUP.

 

Quads