1. Welcome to Tacoma World!

    You are currently viewing as a guest! To get full-access, you need to register for a FREE account.

    As a registered member, you’ll be able to:
    • Participate in all Tacoma discussion topics
    • Communicate privately with other Tacoma owners from around the world
    • Post your own photos in our Members Gallery
    • Access all special features of the site

Google Redirect virus

Discussion in 'Technology' started by macgyver, Mar 21, 2012.

  1. Mar 21, 2012 at 2:16 PM
    #21
    macgyver

    macgyver [OP] Well-Known Member

    Joined:
    Aug 14, 2009
    Member:
    #21173
    Messages:
    3,577
    Gender:
    Male
    First Name:
    Brad
    Canton, GA
    Vehicle:
    '13 Tundra double cab SR5 4x4

    Haha True, I've been holding onto this thing for a while. I got it for free from my Ex g/f's brother about 5 years ago. He didn't use it anymore. I wiped it clean and re-installed windows, and added 1G ram when I got it from him. Literally removed almost everything I possibly could from it after reinstalling windows. The only programs installed on it are office xp, my antivirus software, Adaware, Spybot, Itunes, Utorrent (which i haven't used in a long time), and Firefox for web browsing. It has been great for what I use it for which is only Internet, Music, Pictures, and excel spreadsheets for my business.
     
  2. Mar 21, 2012 at 2:18 PM
    #22
    arrrghhh

    arrrghhh Well-Known Member

    Joined:
    Jan 19, 2009
    Member:
    #12748
    Messages:
    2,062
    Gender:
    Male
    Denver, CO
    Vehicle:
    09 TRD Off-Road
    Custom Front Bumper, Smittybilt XRC-8, 3" OME lift, 33" Falken A/T tires
    Should be easy to restore then.

    Especially if it's used for a business, I wouldn't even mess with removing it. If TDSSKiller didn't get it, you're probably not going to get rid of it. I assume you followed the remaining directions on the link I posted however...
     
  3. Mar 21, 2012 at 2:20 PM
    #23
    macgyver

    macgyver [OP] Well-Known Member

    Joined:
    Aug 14, 2009
    Member:
    #21173
    Messages:
    3,577
    Gender:
    Male
    First Name:
    Brad
    Canton, GA
    Vehicle:
    '13 Tundra double cab SR5 4x4
    Hmmm... I didn't try re-naming the program. I'll try that when I get home from work.

    I did run the Norton TDSSfix program. It didn't work.
     
  4. Mar 21, 2012 at 2:22 PM
    #24
    arrrghhh

    arrrghhh Well-Known Member

    Joined:
    Jan 19, 2009
    Member:
    #12748
    Messages:
    2,062
    Gender:
    Male
    Denver, CO
    Vehicle:
    09 TRD Off-Road
    Custom Front Bumper, Smittybilt XRC-8, 3" OME lift, 33" Falken A/T tires
    TDSSKiller is Kapersky. That's the one that fixed it for me. I don't remember renaming the file, but I do see that in the directions.

    Follow that post carefully.
     
  5. Mar 21, 2012 at 2:23 PM
    #25
    macgyver

    macgyver [OP] Well-Known Member

    Joined:
    Aug 14, 2009
    Member:
    #21173
    Messages:
    3,577
    Gender:
    Male
    First Name:
    Brad
    Canton, GA
    Vehicle:
    '13 Tundra double cab SR5 4x4
    Yep, that's the one I have.
     
  6. Mar 21, 2012 at 2:29 PM
    #26
    AeroCooper

    AeroCooper Half the strength of ten (microscopic men)

    Joined:
    Apr 16, 2010
    Member:
    #35400
    Messages:
    2,581
    Gender:
    Male
    NH
    Vehicle:
    2018 Barcelona Access Cab Off Road
    Remote start, tailgate inserts, nifty key fob case, Husky X-Act floor liners, AVS vent shades, bed mat, MX4 Tonneau cover, Tyger step rails
    Turn off System Restore before you run any spyware/antivirus or it will come right back when you reboot. Just remember to turn it back on when you are sure the machine is clean.
     
  7. Mar 21, 2012 at 2:33 PM
    #27
    TrdSurgie

    TrdSurgie revised

    Joined:
    Feb 19, 2012
    Member:
    #73132
    Messages:
    4,181
    Gender:
    Male
    Oahu

    I bet the other computer(s) are STD machines. :D
     
  8. Mar 21, 2012 at 2:36 PM
    #28
    neontrail

    neontrail ✈ ✈ ✈ ✈ ✈ ✈ ✈

    Joined:
    Apr 9, 2008
    Member:
    #5844
    Messages:
    10,109
    Gender:
    Male
    Idaho
    Vehicle:
    2004 NISSAN XTERRA XE/SE
    De-badged, Tint 20%, Blue 48 LED dome-light, .......
    OP i have your same exact problem, for about 3-4 weeks now. The worst BS virus i ever had! I still have it, can't get rid of it. Tried EVERYTHING, short of wiping everything clean.

    :(
     
  9. Mar 21, 2012 at 2:37 PM
    #29
    arrrghhh

    arrrghhh Well-Known Member

    Joined:
    Jan 19, 2009
    Member:
    #12748
    Messages:
    2,062
    Gender:
    Male
    Denver, CO
    Vehicle:
    09 TRD Off-Road
    Custom Front Bumper, Smittybilt XRC-8, 3" OME lift, 33" Falken A/T tires
    Then why not just wipe it?

    Honestly, it's not worth the effort to remove. 3-4 weeks!?!? It wouldn't take that long to wipe & restore EVERYTHING, I guarantee it!
     
  10. Mar 21, 2012 at 3:03 PM
    #30
    neontrail

    neontrail ✈ ✈ ✈ ✈ ✈ ✈ ✈

    Joined:
    Apr 9, 2008
    Member:
    #5844
    Messages:
    10,109
    Gender:
    Male
    Idaho
    Vehicle:
    2004 NISSAN XTERRA XE/SE
    De-badged, Tint 20%, Blue 48 LED dome-light, .......
    ^^^I just have SOOOO much shit.....I cant face the fact of starting over
     
  11. Mar 21, 2012 at 3:45 PM
    #31
    arrrghhh

    arrrghhh Well-Known Member

    Joined:
    Jan 19, 2009
    Member:
    #12748
    Messages:
    2,062
    Gender:
    Male
    Denver, CO
    Vehicle:
    09 TRD Off-Road
    Custom Front Bumper, Smittybilt XRC-8, 3" OME lift, 33" Falken A/T tires
    You would've been done with this 3-4 weeks ago if you had just wiped it. Everyone has a lot of shit - I have 2.5 terabytes of shit on my server. But the point is, if you can't get rid of it with a few scans and a little bit of research - it's usually not worth removing manually. Even if you remove it and don't notice it, what's leftover? Who knows, and now it has access to all your shit.

    There's a lot of tools out there, but obviously these bastages that write the virii/rootkits/etc are always trying to stay ahead of them. Hence why it's always a good idea to just wipe it if you get infected. My company has a policy to wipe without even caring on our branch PC's. There's something to be said for having that down to a science when you run Windoze..
     
  12. Mar 21, 2012 at 5:10 PM
    #32
    neontrail

    neontrail ✈ ✈ ✈ ✈ ✈ ✈ ✈

    Joined:
    Apr 9, 2008
    Member:
    #5844
    Messages:
    10,109
    Gender:
    Male
    Idaho
    Vehicle:
    2004 NISSAN XTERRA XE/SE
    De-badged, Tint 20%, Blue 48 LED dome-light, .......
    ^^^ u r right
     
  13. Mar 21, 2012 at 5:32 PM
    #33
    elmo7

    elmo7 Easily Replaceable Member

    Joined:
    Aug 11, 2011
    Member:
    #61553
    Messages:
    706
    Gender:
    Male
    SC
    Vehicle:
    07 DC TRD OR 4x4
    You'll be surprised how much you don't bother to reinstall after reformatting. It's like spring cleaning. Good for any computer every once in a while, IMO.
     
  14. Mar 21, 2012 at 7:47 PM
    #34
    arrrghhh

    arrrghhh Well-Known Member

    Joined:
    Jan 19, 2009
    Member:
    #12748
    Messages:
    2,062
    Gender:
    Male
    Denver, CO
    Vehicle:
    09 TRD Off-Road
    Custom Front Bumper, Smittybilt XRC-8, 3" OME lift, 33" Falken A/T tires
    My Linux server is due, even. It's not infected, but damn... I need to add more HDD's, plus it's 32-bit. Always wanted to get it up to 64... 12.04 is coming soon too :cool:.
     
  15. Mar 21, 2012 at 10:32 PM
    #35
    LBtaco

    LBtaco Thread killer

    Joined:
    Jan 23, 2009
    Member:
    #12893
    Messages:
    1,237
    Gender:
    Male
    Long Beach , CA
    Vehicle:
    15 Nissan Leaf
    Jetsons mod
    not to hijack, but what linux are you running arrrghhh?

    Im trying to get a ubuntu machine running with modx so our website guy can play around with it. (hosted godaddy server using modx is our live one)
     
  16. Mar 21, 2012 at 10:39 PM
    #36
    JimBeam

    JimBeam BECAUSE INTERNETS!! Moderator

    Joined:
    Apr 14, 2008
    Member:
    #5966
    Messages:
    52,054
    Gender:
    Male
    First Name:
    JB
    Vehicle:
    2015 Tundra
    pretty much this

    a friend of mine had her computer infected and like arrrghhh said...it's a nasty little bastard

    On my friends computer, it had infected a crucial windows boot file, deleted it and replaced it with it's own file that mimicked the boot file and still allowed windows to boot

    when one of the spyware programs finally deleted it...the bootfile was LONG gone and we ended up having to wipe it anyways
     
  17. Mar 21, 2012 at 11:23 PM
    #37
    neontrail

    neontrail ✈ ✈ ✈ ✈ ✈ ✈ ✈

    Joined:
    Apr 9, 2008
    Member:
    #5844
    Messages:
    10,109
    Gender:
    Male
    Idaho
    Vehicle:
    2004 NISSAN XTERRA XE/SE
    De-badged, Tint 20%, Blue 48 LED dome-light, .......
  18. Mar 22, 2012 at 12:01 AM
    #38
    LTech221

    LTech221 Lurker

    Joined:
    Jan 11, 2010
    Member:
    #29156
    Messages:
    29
    Gender:
    Male
    First Name:
    Mark
    So Cal
    Vehicle:
    2017 Subaru Outback
    Traded the taco :(
    I've seen this quite a few times and have tried a ton of tools. Usually one thing or another gets it, but lately i've been using hitmanpro 3.5 http://www.surfright.nl/en/downloads to get rid of this particular nasty. Just active the free 30 day trial and see if it gets rid of it, other than starting fresh which is usually recommended.
     
  19. Mar 22, 2012 at 6:18 AM
    #39
    macgyver

    macgyver [OP] Well-Known Member

    Joined:
    Aug 14, 2009
    Member:
    #21173
    Messages:
    3,577
    Gender:
    Male
    First Name:
    Brad
    Canton, GA
    Vehicle:
    '13 Tundra double cab SR5 4x4
    So last night I tried re-naming TDSS-killer and running it. It didn't work.

    I think I found my windows disk. I found two different windows disks, I'll have to see which is which... and I found an office 2007 disk I didn't know I had (was running office 2003 on that computer). I'm gonna hold off until this weekend though, A buddy of mine who works for geek squad is going to come over this weekend and try a few different tools he uses at work.

    If it doesn't work, I think I'm going to just buy a new laptop and go ahead and wipe this computer and re-install the OS. I started moving all of my documents, pictures, and music out to my network storage (external hard drive hooked up to my router) last night.
     
  20. Mar 22, 2012 at 6:20 AM
    #40
    macgyver

    macgyver [OP] Well-Known Member

    Joined:
    Aug 14, 2009
    Member:
    #21173
    Messages:
    3,577
    Gender:
    Male
    First Name:
    Brad
    Canton, GA
    Vehicle:
    '13 Tundra double cab SR5 4x4
    Keep googling stuff. I've found that the first few google searches worked fine, then it came back after 3 or 4 searches.
     

Products Discussed in

To Top