Results 1 to 8 of 8
  1. #1
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,520
    BG Level
    6
    FFXI Server
    Carbuncle

    Google links redirection virus help

    I seem to have got a virus/malware/whatever.

    It will at random points, redirect links from Google to it's own sites, usually random search engines that forward me to other sites.

    Multiple AV programs don't locate it. I removed some shit it put in my hosts.ini, had me surfing by proxy which I also removed, and I have not been able to find any of the supposed associated files / registry entries that i've been able to google up.

    The sites it most often sends me to are get-answers-fast.com bifsearch.net and expandsearch, which then forward me god only knows where. Anyone have experience with this?

  2. #2
    This isnt going so well guys.
    Join Date
    May 2005
    Posts
    3,654
    BG Level
    7
    FFXI Server
    Bahamut

    This should remove it, it sounds like a tdss virus. http://support.kaspersky.com/viruses...?qid=208280684

  3. #3
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,520
    BG Level
    6
    FFXI Server
    Carbuncle

    Tried that too It found nothing. Combofix is supposed to have some success, I ran that, and so far no redirects, but it's difficult to tell if only because the redirects happen at random times, might not get any for hours, or even half a day, then bam :3

  4. #4
    Annihilation Banwave
    sprout sprout sprout
    2031 No.1 Draft Pick
    Pittsburgh Penguins

    Sweaty Dick Punching Enthusiast

    Join Date
    Aug 2006
    Posts
    19,830
    BG Level
    9
    FFXI Server
    Bismarck

    I actually have it as well. Kaspersky, Hijack This, Combofix, Malwarebytes all were unsuccessful. I ended up just reformating the hard drive(I was planning on doing this next weekend before I got the virus anyways lol.)

  5. #5
    Shallow and Pedantic
    Join Date
    Jun 2007
    Posts
    4,996
    BG Level
    7

    Quote Originally Posted by Brill View Post
    I actually have it as well. Kaspersky, Hijack This, Combofix, Malwarebytes all were unsuccessful. I ended up just reformating the hard drive(I was planning on doing this next weekend before I got the virus anyways lol.)
    Had the same issue, ended up reformatting. Took it to my Best Buy I work @, all of the Tech's basically just gave up and said reformat or bust.

  6. #6
    Chram
    Join Date
    Jul 2005
    Posts
    2,581
    BG Level
    7
    FFXIV Character
    Deejay Zombie
    FFXIV Server
    Excalibur

    have you tried this?

    http://siri.geekstogo.com/SmitfraudFix.php

    smitfraudfix, it's fixed many problems i've had other programs haven't been able to successfully.

    http://siri.geekstogo.com/Bitmaps/Fix01b.png

    This tool removes Desktop Hijack malware: Advanced Antivirus, Advanced Virus Remover, AdwarePunisher, AdwareSheriff, AlphaCleaner, AntiSpyCheck, AntiSpyware Expert, Antispyware Soldier, AntiVermeans, AntiVermins, AntiVerminser, AntiVirGear, Antivirus 2009, Antivirus 2010, Antivirus 360, AntiVirus Lab 2009, Antivirus Master, Antivirus Sentry, Antivirus System Pro, Antivirus XP 2008, AntivirusGolden, AV Antispyware, AVGold, Awola, BraveSentry, Coreguard Antivirus, Extra Antivirus, HomeAntivirus 2009, IE Defender, IE-Security, Internet Antivirus, Malware Defender 2009, MalwareCrush, MalwareWipe, MalwareWiped, MalwaresWipeds, MalwareWipePro, MalwareWiper, Micro Antivirus 2009, MS AntiSpyware 2009, MS Antivirus, PC Protection Center 2008, Personal Defender 2009, PestCapture, PestTrap, Power Antivirus, Power-Antivirus-2009, PSGuard, quicknavigate.com, RegistryFox, Registry Cleaner, Renus 2008, Security iGuard, Smart Antivirus 2009, Smitfraud, SmitFraudFixTool, Spy Protector, SpyAxe, SpyCrush, SpyDown, SpyFalcon, SpyGuard, SpyHeal, SpyHeals, SpyLocked, SpyMarshal, SpySheriff, SpySoldier, Spyware Guard 2008, Spyware Protect 2009, Spyware Vanisher, Spyware Soft Stop, SpywareLocked, SpywareQuake, SpywareKnight, SpywareRemover, SpywareSheriff, SpywareStrike, Startsearches.net, System Antivirus 2008, System Guard 2009, TheSpyBot, TitanShield Antispyware, Total Protect 2009, Total Secure 2009, Trust Cleaner, Ultimate Antivirus 2008, UpdateSearches.com, UnVirex, Virtual Maid, Virus Heat, Virus Protect, Virus Protect Pro, VirusBlast, VirusBurst, VirusRay, Virus Remover 2008, Virus Shield, VirusResponse Lab 2009, VirusTrigger, Win32.puper, WinHound, WinPC Defender, WiniBlueSoft, Vista Antivirus 2008, WinDefender 2009, XLG Security Center, XP Deluxe Protector, XP Security Center, XPert Antivirus, XP Police Antivirus, Brain Codec, ChristmasPorn, DirectAccess, DirectVideo, EliteCodec, eMedia Codec, EZVideo, FreeVideo, Gold Codec, HQ Codec, iCodecPack, IECodec, iMediaCodec, Image ActiveX Object, Image Add-on, IntCodec, iVideoCodec, JPEG Encoder, Key Generator, LookForPorn, Media-Codec, MediaCodec, MMediaCodec, MovieCommander, MPCODEC, My Pass Generator, NetProject, Online Image Add-on, Online Video Add-on, PCODEC, Perfect Codec, PowerCodec, PornPass Manager, PornMag Pass, Pornovid, PrivateVideo, QualityCodec, Silver Codec, SearchPorn, SexVid, SiteEntry, SiteTicket, SoftCodec, strCodec, Super Codec, TrueCodec, VideoAccess, VideoBox, VidCodecs, Video Access ActiveX Object, Video ActiveX Object, Video Add-on, VideoCompressionCodec, VideoKeyCodec, VideosCodec, WinAntiSpyPro, WinMediaCodec, X Password Generator, X Password Manager, ZipCodec, WinCoDecPRO...

  7. #7
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,520
    BG Level
    6
    FFXI Server
    Carbuncle

    I has not tried it, so for Combofix seems to have worked, no redirection in a day or so now, keeping my fingers crossed. Glad to see i'm somehow not the only idiot who got this thing and found it so damn hard to remove.

  8. #8
    BG Content
    Join Date
    Jul 2007
    Posts
    22,334
    BG Level
    10
    FFXI Server
    Lakshmi
    Blog Entries
    1

    I'm doubtlessly way out of date about this, but did you open up your Hosts file and make sure it only had your local host in it?
    http://en.wikipedia.org/wiki/Hosts_%28file%29

    Iirc, people can put their server above your local host file and direct your traffic through them. Sort of a really basic way to do a redirection attack, but also one that I have to imagine almost every security program would protect against.

Similar Threads

  1. Google redirect virus
    By The_OG_Nelta in forum Tech
    Replies: 5
    Last Post: 2011-07-19, 10:41
  2. Virus Help
    By Deftscythe in forum Tech
    Replies: 2
    Last Post: 2011-06-14, 19:02
  3. Google redirect virus removal
    By FNH in forum Tech
    Replies: 6
    Last Post: 2011-02-11, 08:45
  4. Need some PC virus help please!
    By Nightbreed in forum Tech
    Replies: 23
    Last Post: 2011-01-23, 01:29
  5. Virus Help
    By Counterfeit in forum Tech
    Replies: 1
    Last Post: 2010-06-09, 16:58
  6. Virus Help
    By Counterfeit in forum Tech
    Replies: 3
    Last Post: 2009-08-09, 08:38
  7. Google Links get redirected
    By Akiyama in forum Tech
    Replies: 8
    Last Post: 2008-08-30, 22:14