Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93098 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Google Redirect Infection


  • This topic is locked This topic is locked
39 replies to this topic

#1 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 20 June 2010 - 05:21 PM

Google Redirects

Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



You might want to print these instructions out.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Download TDSSKiller and save it to your Desktop.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • Extract the file and run it.
  • Reboot your machine and see if the infection is gone


Reboot and the infection should be removed.

If you still need help Start a new topic:
Also please post the contents of that log TDSSKiller and GooredFix log.

Start a Posted Image in Spyware / Malware / Virus Removal Forum

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

    Advertisements

Register to Remove


#2 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 13 September 2010 - 03:49 PM

Position "bump"

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#3 robregions1974

robregions1974

    New Member

  • New Member
  • Pip
  • 1 posts

Posted 30 September 2010 - 10:45 AM

Wow, I got the redirect virus yesterday and COULD NOT GET IT REMOVED until found this post and now I'm virus free. I used a program called Hitman Pro to scan my computer, it found the rootkit virus but could not remove it. I typed in the statement that it gave me into google and found this post, followed the instructions and now it appears the virus is gone. I executed the 3 programs, rebooted then ran Hitman pro again and there was no note that any virus was identified, I've been opening new windows and new tabs like a madman and no redirects, so I think I'm clean THANK YOU SO MUCH FOR YOUR HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!! :thumbup: :thumbup:

#4 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 30 September 2010 - 03:13 PM

Wow, I got the redirect virus yesterday and COULD NOT GET IT REMOVED until found this post and now I'm virus free. I used a program called Hitman Pro to scan my computer, it found the rootkit virus but could not remove it. I typed in the statement that it gave me into google and found this post, followed the instructions and now it appears the virus is gone. I executed the 3 programs, rebooted then ran Hitman pro again and there was no note that any virus was identified, I've been opening new windows and new tabs like a madman and no redirects, so I think I'm clean THANK YOU SO MUCH FOR YOUR HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!! :thumbup: :thumbup:

You're more than welcome.
Glad we were able to help

Peace be with you :wavey:

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#5 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 16 October 2010 - 08:01 AM

Updated

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#6 estone

estone

    New Member

  • New Member
  • Pip
  • 1 posts

Posted 16 October 2010 - 09:46 PM

Wow, I got the redirect virus yesterday and COULD NOT GET IT REMOVED until found this post and now I'm virus free. I used a program called Hitman Pro to scan my computer, it found the rootkit virus but could not remove it. I typed in the statement that it gave me into google and found this post, followed the instructions and now it appears the virus is gone. I executed the 3 programs, rebooted then ran Hitman pro again and there was no note that any virus was identified, I've been opening new windows and new tabs like a madman and no redirects, so I think I'm clean THANK YOU SO MUCH FOR YOUR HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!! :thumbup: :thumbup:


Exact same experience here as of Oct 16. Ran Hitman Pro 3.5.7 after fix and it no longer picked up "TDL3 (alias Alureon)" issue. Many thanks gentlemen for providing a very helpful solution to this highly annoying redirect problem!!

#7 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 17 October 2010 - 05:20 AM

Thanks for posting back and letting us know :thumbup: Peace be with you :wavey:

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#8 virusesluvme

virusesluvme

    New Member

  • New Member
  • Pip
  • 1 posts

Posted 07 December 2010 - 09:27 PM

LDTate - you da man! HitmanPro couldn't fix this problem - until I stumbled onto this fix. TDSS found the rootkit (on the second try) and sent TDL3 to bye-bye land! Thanks for being one of the good guys!

#9 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 08 December 2010 - 08:37 AM

You're more than welcome. Glad we were able to help Peace be with you :wavey:

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#10 werdnaJT

werdnaJT

    New Member

  • New Member
  • Pip
  • 2 posts

Posted 10 December 2010 - 02:36 PM

I have had the same problem, ran hitman, and it only said that a possible variation was detected. I ran step 1 on this post, then tried to open the link for step two. All it shows is a blank page, and the same for step #3? Not quite sure where to go from here...

    Advertisements

Register to Remove


#11 inzanity

inzanity

    ♠♠lost♠♠

  • Malware Team
  • 2,340 posts

Posted 12 December 2010 - 05:30 AM

Hi werdnaJT,

The links should take you directly to download those tools. The infection may be preventing you from doing so.

I would suggest reading here: Getting Started: How To Get Help

then create a new topic here: Virus, Spyware & Malware Removal

One of our Malware fighters would help you in removing this infection. Thank you. :)

Proud graduate of WTT Classroom


The help we provide here is free, however, if you wish to donate, you can do so here: http://www.whatthetech.com/donate/

ASAP and UNITE member

________________________________________________


!


#12 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 12 December 2010 - 05:55 AM

I have had the same problem, ran hitman, and it only said that a possible variation was detected. I ran step 1 on this post, then tried to open the link for step two. All it shows is a blank page, and the same for step #3? Not quite sure where to go from here...

Sounds like a browser issue.
Right Click on the link and select "Open In New Windows"

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#13 werdnaJT

werdnaJT

    New Member

  • New Member
  • Pip
  • 2 posts

Posted 13 December 2010 - 02:48 PM

Thanks alot for your help, the problem is gone. I can't start to tell you how helpful people like you are, i really appreciate it. Thanks!

#14 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 13 December 2010 - 03:40 PM

You're more than welcome. Glad we were able to help Peace be with you :wavey:

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#15 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 21 December 2010 - 07:41 PM

Updated

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

Related Topics



1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users