Google virus, NOT redirect virus. PLEASE HELP!

Could you go to virustotal and within the browse box at the top locate the mbr.dat file on your desktop and upload that please

http://www.virustotal.com/

Could you then post the result

http://www.virustotal.com/file-scan/report.html?id=4afd954989067ffc6ffc2f3ba21ada07b2f66f2fb04b76d7678094baf47726fd-1310590951

heres the page

Do you use a router ? And do any other computers using it suffer from redirects as well ?

Download MBRCheck.exe to your Desktop. Run the application.

If no infection is found, it will produce a report on the desktop. Post that report in your next reply.

If an infection is found, you will be presented with the following dialog:

[QUOTE]Enter ‘Y’ and hit ENTER for more options, or ‘N’ to exit:
[/quote]
Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.

Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.
[/quote]
I think you misunderstand, my problem is not redirect, its that when ever I search stuff on google, avast says theres a virus on everything from images.
Yes I do use a router and no none of my computers have a redirect problem.

Is it still doing that - sorry I have redirects on the brain at the moment

Right now its not, but its really weird, sometimes it will show up and others it will be working fine.

Well there is no malware on the system - so I would think that some of the images you are trying to view have been poisoned… Especially as it is erratic

Could you let me know next time it happens and give the link to the page (broken please )

Have you checked your hosts file?
Usually in c:\windows\system32\drivers\etc
Are there any google-like records?

How does the mentioned google site resolve to you?
Ie. open cmd, and run command
nslookup XXX
where XXX is the site making you the problems.

Host file is empty according to OTS

this is such irritating, I am 1000% sure this is not a virus, but an error.
I’ve had viruses before and usually there would be symptoms like my PC acting up but so far there is no sign of a virus

http://img59.imageshack.us/img59/9214/hmmbr.png

its like one day i’ll search something and everything will be fine, and the next I’d search something and avast keeps telling me malicious malware was found.
edit: I’ve realized this will stop at any time… because it just did.
edit2: okay, Ive realized that this doesnt just stop, it seems to be that when ever I search something new that I havent searched before the warning shows up, and if I refresh the page, it doesnt show up anymore, and if I scroll down and new images load the warning shows up again

http://www.google.com/search?hl=en&q=hmm&gs_sm=e&gs_upl=9530l9763l0l9932l3l2l0l0l0l0l130l218l1.1l2&bav=on.2,or.r_gc.r_pw.&biw=1920&bih=979&um=1&ie=UTF-8&tbm=isch&source=og&sa=N&tab=wi

heres the search link

Works for me, but I expected that. This is not widespread, we would see it.

What is the output of the nslookup command I asked few messages back?

At this point im just about to remove avast because it is only annoying me with “Threat has been detected” sounds and not warning my about real viruses

Do it and you may have further problems.Can’t you wait for Essexboy?He will figure out what’s going on.

I really enjoy these double monologs.

I’m trying to ‘fix’ your problem but you simply don’t reply to any of my questions. What do you expect then? ???

sorry kubecj, I missed your question, heres whats in C:\Windows\System32\drivers\etc

hosts
lmhosts.sam
networks
protocol
services

How does the mentioned google site resolve to you?
Ie. open cmd (command-line), and run command
nslookup t0.gstatic.com

or

nslookup t2.gstatic.com

Post here the results. For me it returns something like this
Name: t0.gstatic.com
Addresses: 74.125.79.147
74.125.79.99
74.125.79.104

but it will differ because Google has geoip-based replies.

Yes mine shows up the same with a Non-Authoritive answer thing.

Really? The same IP addresses? The addresess I posted were from Europe. I’m getting different IPs for USA based server.

the IPs I got is
74.125.226.116
74.125.226.112
74.125.226.113
74.125.226.114
etc.

OMG. These are computers, they don’t work with etc. ::slight_smile:

One of the ips in the 74.125.226.x range was wrongly blocked. The badguys do this as a decoy, they put good addresses amongst the bad to slow us down or embarass us when we block something like google.

I removed it, will be in the next update. We’ll see if it’ll be fixed or not.