Equipped To Survive Equipped To Survive® Presents
The Survival Forum
Where do you want to go on ETS?

Page 1 of 2 1 2 >
Topic Options
#202304 - 05/23/10 01:26 AM There is a new google redirect virus out- HELP!!!
ironraven Offline
Cranky Geek
Carpal Tunnel

Registered: 09/08/05
Posts: 4642
Loc: Vermont
OK, I admit it. I let my guard down on one of my XP boxes. Don't know, I keep the updates up to date, OS and AV (run AVG). But now, I get a redirect when I'm searching for stuff.

First time goes ok. I can view any of the results just fine.

Second and subsequent attempts to look at any results get redirect. There is a variety of sights, most of them look like advertising, but they sure aren't my desired results; about half the time, the redirect fails. There is also an icon of a blue, hand written number "2" on the redirect page.

AVG finds nothing.
Malwarebytes finds nothing.
ZoneAlarm hasn't yelled at me in a few weeks.
I can't find anything new and interesting in my registry.
I can account for every non-cache file created or modified in the past week.

It is consistant with all Google searches in Firefox, IE7 (can't go to 8, in case I have to work from home), and Opera10. In Opera, I got it to do the same thing with a yahoo search, but was unable to recreate that with the other browsers.

Anyone seen anything that fits this profile?

Bah. I need to do some research, and it's my desktop that is unwell. Doing real work on a netbook is possible but not fun frown
_________________________
-IronRaven

When a man dare not speak without malice for fear of giving insult, that is when truth starts to die. Truth is the truest freedom.

Top
#202306 - 05/23/10 01:57 AM Re: There is a new google redirect virus out- HELP!!! [Re: ironraven]
Art_in_FL Offline
Pooh-Bah

Registered: 09/01/07
Posts: 2432
Not specific to this situation but it is usually good practice to dump your browser cache, cookies, flash cookies and any other junk files first thing. If you don't have a cleaner program get one. CCleaner usually does a good job and its free. Get the trash out and you get rid of a lot of problems if the situation isn't caused by anything too malevolent.

If that doesn't help you will need to undertake sterner steps.

Top
#202307 - 05/23/10 01:59 AM Re: There is a new google redirect virus out- HELP!!! [Re: Art_in_FL]
GarlyDog Offline
τΏτ
Old Hand

Registered: 04/05/07
Posts: 776
Loc: The People's Republic of IL
Do a system restore back to a date before you had the problem.

http://support.microsoft.com/kb/306084
_________________________
Gary








Top
#202310 - 05/23/10 03:40 AM Re: There is a new google redirect virus out- HELP!!! [Re: ironraven]
Teslinhiker Offline
Veteran

Registered: 12/14/09
Posts: 1418
Loc: Nothern Ontario
Has the hosts file been modified and do you see any redirects of common website names to IP address?

c:\windows\system32\drivers\etc\hosts

This is just a text file and can be opened with notepad.
_________________________
Earth and sky, woods and fields, lakes and rivers, the mountain and the sea, are excellent schoolmasters, and teach some of us more than we can ever learn from books.

John Lubbock

Top
#202312 - 05/23/10 05:06 AM Re: There is a new google redirect virus out- HELP!!! [Re: Teslinhiker]
ironraven Offline
Cranky Geek
Carpal Tunnel

Registered: 09/08/05
Posts: 4642
Loc: Vermont
Checked that- going home to 127 0 0 1.

Thanks guys- been doing IT for too long, and I'm running out of ideas. Unfortunately, my system backups have not been as frequent as they should be, but all the key stuff is stored in a external hdd that hasn't even been powered since this started. frown

Thought I'd gotten it, but not only is it redirecting still, I've got scvhost going nuts.

I'm going to bed. Probably missing the obvious at this point.
_________________________
-IronRaven

When a man dare not speak without malice for fear of giving insult, that is when truth starts to die. Truth is the truest freedom.

Top
#202314 - 05/23/10 05:59 AM Re: There is a new google redirect virus out- HELP!!! [Re: ironraven]
Xterior Offline
Member

Registered: 06/25/05
Posts: 148
I had good results with combofix, where malware bytes was not able to fix some customer pc's

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Top
#202317 - 05/23/10 09:55 AM Re: There is a new google redirect virus out- HELP!!! [Re: ironraven]
EMPnotImplyNuclear Offline
Enthusiast

Registered: 09/10/08
Posts: 382
Try Spybot Search & Destroy

Better yet, boot from ultimate boot cd for windows and then run spybot/avg .... from the boot cd

You also might be interested in autopatcher, makes it easier to manage the updates

Top
#202325 - 05/23/10 04:35 PM Re: There is a new google redirect virus out- HELP!!! [Re: EMPnotImplyNuclear]
GarlyDog Offline
τΏτ
Old Hand

Registered: 04/05/07
Posts: 776
Loc: The People's Republic of IL
IR, System Restore is a Windows function. It should be automatically turned on and working. Go to Windows Help and type in 'system restore wizard' This restore will not over-write your personal data, only system settings. I have had good luck knocking out viruses this way as a first step.
_________________________
Gary








Top
#202345 - 05/23/10 10:25 PM Re: There is a new google redirect virus out- HELP!!! [Re: GarlyDog]
ironraven Offline
Cranky Geek
Carpal Tunnel

Registered: 09/08/05
Posts: 4642
Loc: Vermont
Thanks Garly.

I"ve had like 6 hours of sleep in the past two days, and was up until dawn on Saturday with someone else's computer problems. Amazing what doesn't process right when you need to defrag your head.
_________________________
-IronRaven

When a man dare not speak without malice for fear of giving insult, that is when truth starts to die. Truth is the truest freedom.

Top
#202421 - 05/25/10 12:37 AM Re: There is a new google redirect virus out- HELP!!! [Re: ironraven]
ironraven Offline
Cranky Geek
Carpal Tunnel

Registered: 09/08/05
Posts: 4642
Loc: Vermont
OK, I'm to the point I'm thinking I got a rootkit or something else deep, deep down. What every it is survived window restore points back to February.

I guess I'm on my netbook until this weekend. Hadn't planned on spending a day rebuilding a PC. Waste of a good day off.
_________________________
-IronRaven

When a man dare not speak without malice for fear of giving insult, that is when truth starts to die. Truth is the truest freedom.

Top
Page 1 of 2 1 2 >



Moderator:  Alan_Romania, Blast, chaosmagnet, cliff 
May
Su M Tu W Th F Sa
1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31
Who's Online
0 registered (), 294 Guests and 31 Spiders online.
Key: Admin, Global Mod, Mod
Newest Members
Explorer9, GallenR, Jeebo, NicholasMarshall, Yadav
5368 Registered Users
Newest Posts
Bird Flu (H5N1) found in cattle -- are Humans next
by dougwalkabout
05/10/24 01:28 AM
My Doug Ritter Folder Attacked Me!
by dougwalkabout
05/04/24 02:30 AM
People Are Not Paying Attention
by Bingley
04/28/24 03:24 AM
Corny Jokes
by wildman800
04/24/24 10:40 AM
USCG rescue fishermen frm deserted island
by brandtb
04/17/24 11:35 PM
Silver
by brandtb
04/16/24 10:32 PM
EDC Reduction
by Jeanette_Isabelle
04/16/24 03:13 PM
Newest Images
Tiny knife / wrench
Handmade knives
2"x2" Glass Signal Mirror, Retroreflective Mesh
Trade School Tool Kit
My Pocket Kit
Glossary
Test

WARNING & DISCLAIMER: SELECT AND USE OUTDOORS AND SURVIVAL EQUIPMENT, SUPPLIES AND TECHNIQUES AT YOUR OWN RISK. Information posted on this forum is not reviewed for accuracy and may not be reliable, use at your own risk. Please review the full WARNING & DISCLAIMER about information on this site.