This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] google redirect, etc

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

did your system reboot?

Are you still getting the redirects after the reboot?

Please try running the GMER file again:

this time uncheck the box beside "files"

I will give you the link and the instructions for GMER again…make sure all security programs are disabled and all other programs closed before running it:

Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
System did reboot for that scan. It was/is still re-directing search engine. Tried to run GMER again this time I got the Windows blue screen of death after it ran for about an hour. Any other ideas? Thanks!!
Hi,

run this program first:

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.


then try GMER in safe mode.

make sure these items are unchecked:
  • files
  • Sections
  • IAT/EAT
  • Drives/Partition other than Systemdrive (typically C:\)
  • Show All (don't miss this one)

make sure all other programs are closed and all security programs are disabled.
GMER ran. I saved the file. I tried to turn my anti virus back on. The computer froze. Tried to reboot. Now I cannot get Windows to start. Normally or in Safe Mode. Blue screen of death has returned for normal start up. Safe mode start just lists all of the files and does nothing. :pullhair: Any other suggestions?
Hi,

Try the following:

try each step - if it doesn't work - move on to the next step

1. Last Known Good Configuration:

Reboot the computer > tap F8 repeatedly as if entering safe mode > arrow up to Last Known Good Configuration > Enter



2. Erunt Backup

  • Restart your computer
  • Before Windows loads, you will be prompted to choose which Operating System to start
  • Use the up and down arrow key to select Microsoft Windows Recovery Console
  • You must enter which Windows installation to log onto. Type 1 and press enter.
  • At the C:\Windows prompt, type the following bolded text, and press Enter:

    cd erdnt\subs


  • At the next prompt, type the following bolded text, and press Enter:

    batch erdnt.con

  • The erunt backups will begin copying.
  • At the next prompt, type the following bolded text, and press Enter:

    exit

  • Windows will now begin loading.


3.Advise what the stop error is

  • When you boot your machine, press F8 to list the startup options, exactly as you would if you were trying to enter Safe Mode
  • Select "Disable Automatic Restart on System Failure", as shown here:
    [external image: Posted Image]
  • When your system BSODs, write down the STOP error code, as well as any written out error message back here. The STOP error will always appear, but the message may not. You are looking for this:
    [external image: Posted Image]
what happened when you tried to invoke the erunt backup?



Please do the following:



Hopefully you have access to a computer that can burn CD's

We will need to make a BOOT CD

Print these instruction out so that you know what you are doing.

Two programs to download

First

Please downloadISOBurner and save it to your desktop. This program will allow you to burn OTLPE.ISO to make a bootable CD.
  •  
  • Double click the ISOBurner set up icon to install the program, from there on in it is fairly automatic.
  • There are Instructions for the iso burner here if you need them.

Second


  • Download OTLPE.iso save it to your desktop. Now burn OTLPE.iso to a CD using ISO Burner. {NOTE: This file is 292Mb in size so it may take some time to download.)
  • When downloaded double click OTLPE.iso > this will then open ISOBurner to burn the file to CD

  • Reboot the infected system using the boot CD you just created.
    Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • you will find an icon on the desktop called OTLPE > Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to SafeList
  • Press Run Scan to start the scan.
  • When finished, the file will be saved  in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the C:\OTL.txt file in your reply.
The erunt backup did what it was supposed to and when the computer tried to boot it gave the blue screen with the same message. I am done messing with this for a little while. Luckily I have backed up my files so I can put them on another computer. Thanks for your help.
tripleE2008, CatByte is unavailable for a few days. I am unclear on your last response. Are you going to attempt a repair install or what is your plan at this point?
I am just going to wipe the box clean and start over. What are your anti virus/anti-malware suggestions? This is my home computer so I can't ban the guilty user from using it. ;) I was using AVG Free.
Personally I like Avast or Avira for AV. For anti spyware, I run MalwareBytes' once a week.
I've been hearing good things about Microsoft Security Essentials but I haven't used it myself.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI