Author Topic: I think I have a google redirect virus  (Read 8693 times)

0 Members and 1 Guest are viewing this topic.

flodefence

  • Guest
I think I have a google redirect virus
« on: May 09, 2011, 03:18:52 PM »
Avast was detecting some malware on my computer and I removed it with Malwarebytes, but when I restarted, I still had a google redirect virus. I'm not sure on what I should do now. How do I get rid of it? Does it have a major effect on your computer (e.g. steal information, delete or infect files)? Any help would be very appreciated. Thanks. :)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: I think I have a google redirect virus
« Reply #1 on: May 09, 2011, 03:34:22 PM »
Hi...

Download DDS and save it to your Desktop from here:
http://download.bleepingcomputer.com/sUBs/dds.scr

Double click dds.scr to run the tool.

    * When done, DDS will open two (2) logs:
         1. DDS.txt
         2. Attach.txt

Save both reports to your desktop. Attach DDS.txt & Attach.txt back to topic.



flodefence

  • Guest
Re: I think I have a google redirect virus
« Reply #2 on: May 09, 2011, 03:40:15 PM »
Okay, here you go. :)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: I think I have a google redirect virus
« Reply #3 on: May 09, 2011, 03:44:14 PM »
Ok,before we continue removal run this tool.

Download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.
  • Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the Save log button, save the logfile to your desktop and post its contents in your next reply.

flodefence

  • Guest
Re: I think I have a google redirect virus
« Reply #4 on: May 09, 2011, 03:47:49 PM »
Here. :)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: I think I have a google redirect virus
« Reply #5 on: May 09, 2011, 03:53:11 PM »
Ok,let's go :)


> Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this Instruction.


Start >> Run

Code: [Select]
"%userprofile%\desktop\combofix.exe" /killall
Enter


> This will Run ComboFix.
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.

flodefence

  • Guest
Re: I think I have a google redirect virus
« Reply #6 on: May 09, 2011, 04:09:46 PM »
Okay, here it is. :)

yongsua

  • Guest

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: I think I have a google redirect virus
« Reply #8 on: May 09, 2011, 05:04:11 PM »
@flodefence

Re-run Combofix. When the tool is finished attach here fresh log.

Tell me do you have a problem now?

flodefence

  • Guest
Re: I think I have a google redirect virus
« Reply #9 on: May 09, 2011, 05:10:23 PM »
Yeah, I tried running TDSSKiller, but it didn't pick anything up. :S

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: I think I have a google redirect virus
« Reply #10 on: May 09, 2011, 05:12:29 PM »
If you run TDSSKiller then paste here log to see it.  ;)

You may locate log on root C:
C:\TDSSKiller_version_DD.MM.GG_HH.MM.SS.txt

Please,re run ComboFix tool. I have something to check in CF log...

flodefence

  • Guest
Re: I think I have a google redirect virus
« Reply #11 on: May 09, 2011, 05:22:59 PM »
Okay, here's the combo-fix and TDSSKiller logs. :)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: I think I have a google redirect virus
« Reply #12 on: May 09, 2011, 05:34:19 PM »


  • In notepad click on File and then on Save as
  • In the Save as window select any convenient folder to save in
  • At the bottom of the Save as window make sure code ANSI is selected
  • At the very bottom of the Save as window click on Save
Then attach log here ... >>  or just paste TDSSKiller log here  :D

.......................

Open notepad and copy/paste the text present inside the code box below:

Code: [Select]
DeQuarantine::
C:\Qoobox\Quarantine\C\program files\Hotspot Shield\HssIE\HsSIe.dll.vir
Quit::


Save this as CFScript.txt.



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )




And tell me do you have a problem now?

flodefence

  • Guest
Re: I think I have a google redirect virus
« Reply #13 on: May 09, 2011, 06:00:41 PM »
Okay, here they are. :)

I don't seem to have a problem anymore, but I couldn't access the internet for a while. It happened twice right after doing the Combofix scan. The first time, I fixed up the proxy settings and it worked, the second time, I needed to restart my computer to fix it.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: I think I have a google redirect virus
« Reply #14 on: May 09, 2011, 07:20:45 PM »
Ok,it is necessary to you uninstall Combofix.

Start >> Run

Combofix /Uninstall

Enter. Then do the following

Open Notepad and Copy/Paste everything from the Code box into Notepad:

Code: [Select]
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="\"C:\\Program Files\\Alwil Software\\Avast5\\avastUI.exe\" /nogui"



    * Go to File > Save As
    * Save File name as nogui.reg
    * Change Save as Type to All Files and save the file to your Desktop
    * double-click nogui.reg on your Desktop
    * When it asks if you want to merge the info to the registry, hit YES/OK
      Reboot computer