Welcome to your place for tech questions! ( Log In or Join today ) Get answers from experts today. (it's 100% free) Virus removal forum

3 Pages V   1 2 3 >  
Reply to this topicStart new topic
> Google Redirect Infection, Removal Instructions
LDTate
post Jun 20 2010, 05:21 PM
Post #1


Forum God
Group Icon

Group: Root Admin
Posts: 56,304
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276
MVP


Google Redirects




DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



You might want to print these instructions out.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

    If you use Firefox browser

    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step


Next:

Download TDSSKiller and save it to your Desktop.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • Extract the file and run it.
  • Reboot your machine and see if the infection is gone



Reboot and the infection should be removed.

If you still need help Start a new topic:
Also please post the contents of that log TDSSKiller and GooredFix log.

Start a in Spyware / Malware / Virus Removal Forum
Go to the top of the page
 
+Quote Post
LDTate
post Sep 13 2010, 03:49 PM
Post #2


Forum God
Group Icon

Group: Root Admin
Posts: 56,304
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276
MVP


Position "bump"
Go to the top of the page
 
+Quote Post
robregions1974
post Sep 30 2010, 10:45 AM
Post #3


New Member
*

Group: New Member
Posts: 1
Joined: 30-September 10
Member No.: 94,598
Operating System: xp professional



Wow, I got the redirect virus yesterday and COULD NOT GET IT REMOVED until found this post and now I'm virus free. I used a program called Hitman Pro to scan my computer, it found the rootkit virus but could not remove it. I typed in the statement that it gave me into google and found this post, followed the instructions and now it appears the virus is gone. I executed the 3 programs, rebooted then ran Hitman pro again and there was no note that any virus was identified, I've been opening new windows and new tabs like a madman and no redirects, so I think I'm clean THANK YOU SO MUCH FOR YOUR HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!! thumbup.gif thumbup.gif
Go to the top of the page
 
+Quote Post
LDTate
post Sep 30 2010, 03:13 PM
Post #4


Forum God
Group Icon

Group: Root Admin
Posts: 56,304
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276
MVP


QUOTE (robregions1974 @ Sep 30 2010, 11:45 AM) *
Wow, I got the redirect virus yesterday and COULD NOT GET IT REMOVED until found this post and now I'm virus free. I used a program called Hitman Pro to scan my computer, it found the rootkit virus but could not remove it. I typed in the statement that it gave me into google and found this post, followed the instructions and now it appears the virus is gone. I executed the 3 programs, rebooted then ran Hitman pro again and there was no note that any virus was identified, I've been opening new windows and new tabs like a madman and no redirects, so I think I'm clean THANK YOU SO MUCH FOR YOUR HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!! thumbup.gif thumbup.gif

You're more than welcome.
Glad we were able to help

Peace be with you wavey.gif
Go to the top of the page
 
+Quote Post
LDTate
post Oct 16 2010, 08:01 AM
Post #5


Forum God
Group Icon

Group: Root Admin
Posts: 56,304
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276
MVP


Updated
Go to the top of the page
 
+Quote Post
estone
post Oct 16 2010, 09:46 PM
Post #6


New Member
*

Group: New Member
Posts: 1
Joined: 16-October 10
Member No.: 94,769
Operating System: XP



QUOTE (robregions1974 @ Sep 30 2010, 12:45 PM) *
Wow, I got the redirect virus yesterday and COULD NOT GET IT REMOVED until found this post and now I'm virus free. I used a program called Hitman Pro to scan my computer, it found the rootkit virus but could not remove it. I typed in the statement that it gave me into google and found this post, followed the instructions and now it appears the virus is gone. I executed the 3 programs, rebooted then ran Hitman pro again and there was no note that any virus was identified, I've been opening new windows and new tabs like a madman and no redirects, so I think I'm clean THANK YOU SO MUCH FOR YOUR HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!! thumbup.gif thumbup.gif


Exact same experience here as of Oct 16. Ran Hitman Pro 3.5.7 after fix and it no longer picked up "TDL3 (alias Alureon)" issue. Many thanks gentlemen for providing a very helpful solution to this highly annoying redirect problem!!
Go to the top of the page
 
+Quote Post
LDTate
post Oct 17 2010, 05:20 AM
Post #7


Forum God
Group Icon

Group: Root Admin
Posts: 56,304
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276
MVP


Thanks for posting back and letting us know thumbup.gif

Peace be with you wavey.gif
Go to the top of the page
 
+Quote Post
virusesluvme
post Dec 7 2010, 09:27 PM
Post #8


New Member
*

Group: New Member
Posts: 1
Joined: 7-December 10
Member No.: 95,259
Operating System: WinXP



LDTate - you da man!

HitmanPro couldn't fix this problem - until I stumbled onto this fix. TDSS found the rootkit (on the second try) and sent TDL3 to bye-bye land!

Thanks for being one of the good guys!

Go to the top of the page
 
+Quote Post
LDTate
post Dec 8 2010, 08:37 AM
Post #9


Forum God
Group Icon

Group: Root Admin
Posts: 56,304
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276
MVP


You're more than welcome.
Glad we were able to help

Peace be with you wavey.gif
Go to the top of the page
 
+Quote Post
werdnaJT
post Dec 10 2010, 02:36 PM
Post #10


New Member
*

Group: New Member
Posts: 2
Joined: 10-December 10
Member No.: 95,286
Operating System: Windows XP



I have had the same problem, ran hitman, and it only said that a possible variation was detected. I ran step 1 on this post, then tried to open the link for step two. All it shows is a blank page, and the same for step #3? Not quite sure where to go from here...
Go to the top of the page
 
+Quote Post
inzanity
post Dec 12 2010, 05:30 AM
Post #11


♠♠lost♠♠
Group Icon

Group: Malware Team
Posts: 2,330
Joined: 24-February 09
From: Philippines
Member No.: 84,376
Operating System: XP Home SP3, Win 7 32 bit,
Ubuntu



Hi werdnaJT,

The links should take you directly to download those tools. The infection may be preventing you from doing so.

I would suggest reading here: Getting Started: How To Get Help

then create a new topic here: Virus, Spyware & Malware Removal

One of our Malware fighters would help you in removing this infection. Thank you. smile.gif
Go to the top of the page
 
+Quote Post
LDTate
post Dec 12 2010, 05:55 AM
Post #12


Forum God
Group Icon

Group: Root Admin
Posts: 56,304
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276
MVP


QUOTE (werdnaJT @ Dec 10 2010, 02:36 PM) *
I have had the same problem, ran hitman, and it only said that a possible variation was detected. I ran step 1 on this post, then tried to open the link for step two. All it shows is a blank page, and the same for step #3? Not quite sure where to go from here...
Sounds like a browser issue.
Right Click on the link and select "Open In New Windows"
Go to the top of the page
 
+Quote Post
werdnaJT
post Dec 13 2010, 02:48 PM
Post #13


New Member
*

Group: New Member
Posts: 2
Joined: 10-December 10
Member No.: 95,286
Operating System: Windows XP



Thanks alot for your help, the problem is gone. I can't start to tell you how helpful people like you are, i really appreciate it. Thanks!
Go to the top of the page
 
+Quote Post
LDTate
post Dec 13 2010, 03:40 PM
Post #14


Forum God
Group Icon

Group: Root Admin
Posts: 56,304
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276
MVP


You're more than welcome.
Glad we were able to help

Peace be with you wavey.gif
Go to the top of the page
 
+Quote Post
LDTate
post Dec 21 2010, 07:41 PM
Post #15


Forum God
Group Icon

Group: Root Admin
Posts: 56,304
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276
MVP


Updated
Go to the top of the page
 
+Quote Post

3 Pages V   1 2 3 >
Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 21st May 2013 - 12:31 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy