I think I have a google redirect virus

Avast was detecting some malware on my computer and I removed it with Malwarebytes, but when I restarted, I still had a google redirect virus. I’m not sure on what I should do now. How do I get rid of it? Does it have a major effect on your computer (e.g. steal information, delete or infect files)? Any help would be very appreciated. Thanks. :slight_smile:

Hi…

Download DDS and save it to your Desktop from here:
http://download.bleepingcomputer.com/sUBs/dds.scr

Double click dds.scr to run the tool.

* When done, DDS will open two (2) logs:
     1. DDS.txt
     2. Attach.txt

Save both reports to your desktop. Attach DDS.txt & Attach.txt back to topic.

Okay, here you go. :slight_smile:

Ok,before we continue removal run this tool.

Download aswMBR to your desktop.

[*] Double click the aswMBR icon to run it.
[*] Vista and Windows 7 users right click the icon and choose “Run as administrator”.
[*] Click the Scan button to start scan.
[*] When it finishes, press the Save log button, save the logfile to your desktop and post its contents in your next reply.

Here. :slight_smile:

Ok,let’s go :slight_smile:

Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this Instruction.

Start >> Run

"%userprofile%\desktop\combofix.exe" /killall

Enter

This will Run ComboFix.
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.
If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.

When the tool is finished, it will produce a log report for you. (typical location: C:[b]ComboFix.txt[/b] )
Attach log reports ( ComboFix.txt) back to topic.

Okay, here it is. :slight_smile:

http://www.geekstogo.com/forum/topic/267407-how-to-fix-google-redirects/ Just suggestion. :slight_smile:

@flodefence

Re-run Combofix. When the tool is finished attach here fresh log.

Tell me do you have a problem now?

Yeah, I tried running TDSSKiller, but it didn’t pick anything up. :S

If you run TDSSKiller then paste here log to see it. :wink:

You may locate log on root C:
C:\TDSSKiller_version_DD.MM.GG_HH.MM.SS.txt

Please,re run ComboFix tool. I have something to check in CF log…

Okay, here’s the combo-fix and TDSSKiller logs. :slight_smile:

[*]In notepad click on File and then on Save as
[*]In the Save as window select any convenient folder to save in
[*]At the bottom of the Save as window make sure code ANSI is selected
[*]At the very bottom of the Save as window click on Save

Then attach log here … >> or just paste TDSSKiller log here :smiley:

Open notepad and copy/paste the text present inside the code box below:

DeQuarantine::
C:\Qoobox\Quarantine\C\program files\Hotspot Shield\HssIE\HsSIe.dll.vir
Quit::

Save this as CFScript.txt.

http://img213.imageshack.us/img213/1218/cfscript1.gif

Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )

And tell me do you have a problem now?

Okay, here they are. :slight_smile:

I don’t seem to have a problem anymore, but I couldn’t access the internet for a while. It happened twice right after doing the Combofix scan. The first time, I fixed up the proxy settings and it worked, the second time, I needed to restart my computer to fix it.

Ok,it is necessary to you uninstall Combofix.

Start >> Run

Combofix /Uninstall

Enter. Then do the following

Open Notepad and Copy/Paste everything from the Code box into Notepad:


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="\"C:\\Program Files\\Alwil Software\\Avast5\\avastUI.exe\" /nogui"
* Go to[b] File > Save As[/b]
* Save File name as [b]nogui.reg[/b]
* Change Save as Type to [b]All Files[/b] and save the file to your [b]Desktop[/b]
* double-click [b]nogui.reg[/b] on your Desktop
* When it asks if you want to merge the info to the registry, hit YES/OK
  Reboot computer

Okay, done that. :slight_smile: Just asking, why do I have to uninstall Combofix? What kind of problems does it have on my PC?

Actually, I’m having a small problem, something pops up and say “Not all data was successfully written into the registry. Some keys are open by the system or other processes.” What should I do?

Download this zip/rar file

http://www.speedyshare.com/files/28378919/avast6_nogui.zip

extract to your Desktop. Double-click on nogui.reg and reboot windows.

Just asking, why do I have to uninstall Combofix? What kind of problems does it have on my PC?
read manual. ;) http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Combofix is quite tricky and very powerful tool.
For each independent run this tool without the supervision of a trained helper it can lead to crash your systems.

And when we uninstall ComboFix we finish with cleaning.

Registry still not working. :frowning:

Restart/Reboot Windows.

If pop up still showing…download to Desktop & Run it…
http://www.speedyshare.com/files/28379313/show.zip

On desktop it will create new notepad with name on it “showRun”

Paste here log

By pop-up you mean the redirecting on google?