Ok so some how I got this google redirect virus (when clicking a link in google I get sent to a site other than the one I want.)
I've tried running spyware doctor, super anti-spyware, spybot, hitman pro, combofix, and nothing has worked? anyone know how to get rid of this very annoying virus/malware?
Ok so it seems everything is working now with IE, but I use Firefox, and the issue is still happening under firefox.
+ Reply to Thread
Results 1 to 13 of 13
-
What We Do In Life, Echoes In Eternity....
-
Check your user folders and see if another account has been created there,if that's the case reboot to safe mode and delete the bogus account and remove the startup entry in the registry.
I think,therefore i am a hamster. -
have you tried malwarebytes?
run it from safe mode.Donadagohvi (Cherokee for "Until we meet again") -
The last couple of times one of my agency's PCs have gotten this, it's been piggybacked along with the Vundo virus, which is a bitch to get rid of. Not sure really which steps in the combination finally cleared them both up, but I used a combination of:
1. Booting to a BartPE/WindowsLive Boot CD/DVD rescue disc that has a whole bunch of utilities.
2. Ran through: EZPCFix (many tools), Spybot S&D, Avira+Avast AVs. Put a bunch of utilities onto C:\Documents & Settings\Administrator\Desktop.
3. Then boot to Safe Mode Administrator logon
4. Ran through: RKill, ComboFix, Rootkit Repeal, CCleaner, Malwarebytes MBAM, Spybot S&D, Hijack This, a few others. Made sure Spybot had chance to run in Boot mode.
5. Got rid of ALL temp directories, and checked all major sys folders for items with newest dates, renaming extension of suspect files if necessary (to .bad, or something).
6. If everything doesn't run fast and smoothly, and allow for tools like Spybot to stay resident, then go back to beginning and repeat, trying a few others as well.
If all you have is the redirect, this is overkill, but you may find out that you have more than you think...
Scott -
..What cornucopia said...Look for Vundo. Rename Malwarebytes to DenverDawg123 (or whatever), move it to a new, randomly named directory and bury it under two layers of sub-directories. Many of these virii recognize names and prevent the .exe from running. You can also try running it from your thumb drive. I just had one that would shut down MB soon as it loaded, then would delete the MB executable file so that it had to be downloaded fresh again. Only problem was that it also hijacked the browser so that you could only go to certain websites, so you couldn't download it again. Then it set the Hosts file to read only so you couldn't edit it. I finally nailed it but would take too long to explain here.
-
Well last night whikle trying different fixes, my pc just started to reboot itself. Could get to safe mode at all. So had to reinstall from an acronis true image I had saved. So good news is google redirct is gone, bad news is I had to do some program updating, but not to bad. All is good again. Only lost a few e-mails and few unimportant files.
thanks for the repliesWhat We Do In Life, Echoes In Eternity.... -
Aren't you glad you backed up?!!!
Donadagohvi (Cherokee for "Until we meet again") -
Always. Keep it all in a fire proof safe as well......Can't be to safe!!
What We Do In Life, Echoes In Eternity.... -
Afoke_Frieser is a virus.
I think,therefore i am a hamster. -
Similar Threads
-
How do I remove/repair AVI video file virus?
By paulywalnuts in forum Newbie / General discussionsReplies: 6Last Post: 7th Feb 2011, 20:40 -
Highlight parameter breaks redirect
By thecoalman in forum FeedbackReplies: 0Last Post: 21st Jun 2010, 12:18 -
Question about virus so terrible that Ghost restore did not kill the virus
By jimdagys in forum ComputerReplies: 24Last Post: 27th Apr 2010, 10:58 -
Google Is putting out it's own web browser. Google Chrome
By freebird73717 in forum ComputerReplies: 35Last Post: 24th Sep 2008, 00:38 -
TDK DVDR840G wont read anything after tryin to remove possible virus
By kemet in forum DVD & Blu-ray RecordersReplies: 9Last Post: 1st Feb 2008, 10:09