Help with redirect virus

Talk about "WhatEVER !"..
Post Reply
Message
Author
RRHODY
Senior Member
Senior Member
Posts: 639
Joined: Tue Apr 27, 2004 3:38 pm
Location: Long Beach, CA

Help with redirect virus

#1 Post by RRHODY » Sat Feb 14, 2009 5:47 am

Need help. Even with Avira and AdAware my computer got an infection. I don’t know the name, but it redirects any search, Google, Yahoo, About.com, MSN. If a search is made and the results displayed, the entries look normal, but if you click on the title, a totally different site comes up, usually selling something. Google suggests going elsewhere for a solution, Yahoo doesn’t respond. Looking at anti virus and other applications, they seem to be directed at preventing infection – but what to do AFTER infection? Spy Bot, Avira and AdAware say the unit is “clean” but the infection is still there. There was a screen that came up saying their program could stop the intrusion if you paid $$$, it was called A360. I was suspicious, and did not accept the offer. Was that a legit offer?
This situation applies either with MS Internet Explorer or Mozilla Firefox using Windows XP Pro.
Obviously, I can’t do a search for an answer, so I’m hoping to get some directions from the list.

GomJabbar
Moderator
Moderator
Posts: 9765
Joined: Tue Jun 07, 2005 6:57 am

Re: Help with redirect virus

#2 Post by GomJabbar » Sat Feb 14, 2009 6:34 am

You need to download, install, and run Malwarebytes' Anti-Malware. Malwarebytes' Anti-Malware is a powerful virus removal tool. See the following for how to do this.

http://www.bleepingcomputer.com/malware ... ivirus-360

EDIT: Actually, it looks like you need to remove the Vundo Trojan (as well as possibly A360). See the following for removing the Vundo virus.

http://www.bleepingcomputer.com/malware ... virtumonde
DKB

aaa
ThinkPadder
ThinkPadder
Posts: 1062
Joined: Fri Jun 08, 2007 2:36 pm

Re: Help with redirect virus

#3 Post by aaa » Sat Feb 14, 2009 7:38 am

+1 on malwarebytes.

spuddog
Junior Member
Junior Member
Posts: 404
Joined: Thu Nov 09, 2006 3:36 am
Location: Harrisburg, IL

Re: Help with redirect virus

#4 Post by spuddog » Sat Feb 14, 2009 8:35 am

Sounds like your DNS settings have been hi-jacked. Open control panel go to Network connections-
right click on you network adapter- properties. in the list of properties- click on TCP/IP open properties.
under Obtain DNS most ISP's use Obtain Automaticaly. Set to auto and see what happens. Some ISP's
specify the DNS server, so you may have to call your ISP to find out what the setting should be.

By all means run MalwareBytes also.

Scott

RRHODY
Senior Member
Senior Member
Posts: 639
Joined: Tue Apr 27, 2004 3:38 pm
Location: Long Beach, CA

Re: Help with redirect virus

#5 Post by RRHODY » Sat Feb 14, 2009 10:13 am

The first link shows the exact screen shots of what my 'puter looked like. I will follow the instructions and report results.
THANKS !

RRHODY
Senior Member
Senior Member
Posts: 639
Joined: Tue Apr 27, 2004 3:38 pm
Location: Long Beach, CA

Re: Help with redirect virus

#6 Post by RRHODY » Sat Feb 14, 2009 5:38 pm

OK, got rid of A360 and the nag screens, but the search redirection still goes on. I'm going to try the next link.
I do appreciate the help.

GomJabbar
Moderator
Moderator
Posts: 9765
Joined: Tue Jun 07, 2005 6:57 am

Re: Help with redirect virus

#7 Post by GomJabbar » Sat Feb 14, 2009 5:57 pm

While I haven't read previously about the following software, I think I would give it a try. One thing it does is replace the "Hosts" file with a default one. The Hosts file can send you to a poisoned DNS.

http://www.softpedia.com/get/Tweak/Netw ... kFix.shtml

EDIT: Here is a newer version of the above: http://majorgeeks.com/download4372.html
DKB

aaa
ThinkPadder
ThinkPadder
Posts: 1062
Joined: Fri Jun 08, 2007 2:36 pm

Re: Help with redirect virus

#8 Post by aaa » Sat Feb 14, 2009 6:40 pm

There is also ComboFix. I had to rename the file to get it to run.

Marin85
Senior ThinkPadder
Senior ThinkPadder
Posts: 2975
Joined: Sat May 12, 2007 10:54 am
Location: Munich, Germany

Re: Help with redirect virus

#9 Post by Marin85 » Sat Feb 14, 2009 6:44 pm

@OP: you may also want to check out this thread in case you have to go the hard way...
IBM Lenovo Z61p | 15.4'' WUXGA | Intel Core 2 Duo T7400 2x 2.16GHz | 4 GB Kingston HyperX | Hitachi 7K500 500 GB + WD 1TB (USB) | ATI Mobility FireGL V5200 | ThinkPad Atheros a/b/g | Analog Devices AD1981HD | Win 7 x86 + ArchLinux 2009.08 x64 (number crunching)

RRHODY
Senior Member
Senior Member
Posts: 639
Joined: Tue Apr 27, 2004 3:38 pm
Location: Long Beach, CA

Re: Help with redirect virus

#10 Post by RRHODY » Sat Feb 14, 2009 7:03 pm

This is especially for Gomgraber

The first link you suggested worked fine.
The second link - virtumonde - neither program found any problems so didn't solve the problem.
I will continue other avenues in my quest for restoring searches.
Thanks.

spuddog
Junior Member
Junior Member
Posts: 404
Joined: Thu Nov 09, 2006 3:36 am
Location: Harrisburg, IL

Re: Help with redirect virus

#11 Post by spuddog » Sat Feb 14, 2009 11:23 pm

Check your DNS servers

Scott

RealBlackStuff
Admin
Admin
Posts: 17517
Joined: Mon Sep 18, 2006 5:17 am
Location: Mt. Cobb, PA USA
Contact:

Re: Help with redirect virus

#12 Post by RealBlackStuff » Sun Feb 15, 2009 9:30 am

You might have the CoolWebSearch virus.
This link gives you loads of info and how to get rid of it:
http://www.spywareinfoforum.com/lofiver ... 23424.html
Lovely day for a Guinness! (The Real Black Stuff)

Check out The Boardroom for Parts, Mods and Other Services.

NorrisCell
Senior Member
Senior Member
Posts: 882
Joined: Mon Apr 30, 2007 3:41 pm
Location: Las Vegas, NV

Re: Help with redirect virus

#13 Post by NorrisCell » Sat Feb 21, 2009 11:35 pm

I shudder at the name Vundo. Got it not too long ago. Similar symptoms. The Virtu removal found nothing, but Spybot said it was there. Never was able to kill it. Ended up redoing a different drive and safely transferring files. Not a huge deal because it needed to be transferred to the new drive anyway, but an unexpected headache none the less.
Cell phones are my specialty. Got questions? Ask away.

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “Off-Topic Stuff”

Who is online

Users browsing this forum: No registered users and 3 guests