Just got google redirection virus 63.209.69.107 - Pls help

Just got this virus 2 hrs ago on google, but also on other search engines. Norton security suite did not stop it. Been running full scan now for 2 hrs, has not found it.  Googled virus, saw advice to download norton power eraser, but checked this forum first and saw Quads' warning not to run if you really don't know what you're doing.  Google searches going to sites like: beesq.net, howtofolk.com, search many.com. Example of google search for "weather" took me to: http://63.209.69.107/search/web/weatehr/a22/46938-10090/v5.

 

Have windows xp home, sp3. Please help. Thanks a lot. 

Additional info:  SONAR detected suspicious activity on full scan, the program is bkrtgifz.dll

Can someone pls help?  thanks

 

Can you give the location  bkrtgifz.dll is detected from by Norton??

 

Quads

Thanks for responding Quads. Norton file insight doesn't indicate where it is located, origin is not available.

In the History it will tell you where the file was located.

 

Quads

History didn't show it, but I searched for it and found it. Created 9/22/12. Here it is:

 

c:\documents&settings\Judy\localsettings\ApplicationData\Help\Google

ANY other user other than the thread starter is not to use any instructions, scripts or proceedures,  The work though in cleaning a system is individual and only for that system due to a number of factors.

 

Unfortunately, with the amount of threads means the waiting time is longer, Norton continually Blocking files won't hurt your system but is is just annoying, Please wait and be patient.   I am  trying to keep up, spending hours here to script and clean machines on a first come/first served basis. If you or someone adds to your thread It will be pushed back in line due to the new update.  I use the boards in reverse to what is seen

 

Please do not run any tools unless instructed to do so. 

  • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability. Do as the instructions ask nothing extra or run things twice
  • If I ask a Question just answer it, don't run anything unless it states.
  • Major steps used:

1. Find

2. Break

3. Destroy

4. Cleanup  (including system as a whole)

 

Please read every post completely before doing anything. 

  • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.

 

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forum, (sometimes :smileylol:)

  • Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.


XP, so I need a first log, I think it is Tracur, but usually comes with more than that.

 

Disable Norton for say 30 minutes

 

 

Download OTL http://www.bleepingcomputer.com/download/otl/

 

Start OTL,  

Click the Scan All Users checkbox.

Change file age to 60 days

 

Press the 

 

 

An OTL.txt  and extras.txt will be created.

 

Quads

Thank you. Ok, I'm ready.

Where is the logs, see last message above.

 

Quads

Here's the 2 reports.

Download Roguekiller and start the program, then click the Search Button.

 

http://www.sur-la-toile.com/RogueKiller/

 

It will create a log in the same location as the program.

 

Quads

Here's the report.

OK, Now have Roguekiller,  Delete (or Repair) by hitting the delete button this time.

 

Quads

OK, it deleted the first 4 files and replaced the rest. 

What's next?

 

I really appreciate your help.

 

Quads, I just tested out google with no redirects. Thank you very much, I'd send you a check if I knew where.

Hahaha, OK you keep the infected system.

 

Quads

Quads, my bad.  Thought Roguekiller took care of everything as there were no further instructions posted and there's been no google redirects since yesterday.  What's next?  Thanks.   

Quads, Can you let me know if there's any more to do with my issue. Appreciate it, thanks.

I am not doing anything more, good luck 

 

Quads

Quads,  I don't know how I offended you.  I  followed your directions yesterday, correctly I believe.  You didn't say there would be more instructions to come and you didn't post anything back for a half hour, so I thought everything was ok and edited my post thanking you for all your help.  Can we continue and do what still has to be done.  thank you.