1. Welcome to Tacoma World!

    You are currently viewing as a guest! To get full-access, you need to register for a FREE account.

    As a registered member, you’ll be able to:
    • Participate in all Tacoma discussion topics
    • Communicate privately with other Tacoma owners from around the world
    • Post your own photos in our Members Gallery
    • Access all special features of the site

Google Redirect virus

Discussion in 'Technology' started by macgyver, Mar 21, 2012.

  1. Mar 22, 2012 at 6:25 AM
    #41
    Squisha

    Squisha Well-Known Member

    Joined:
    Sep 14, 2011
    Member:
    #63484
    Messages:
    65
    Gender:
    Female
    Westminster, CO
    Vehicle:
    99 Taco Reg Cab 4x4
    What browser are you using?

    There's a bit of malware getting inadvertantly installed now with other programs (I got hit with one called mybrowserbar), and it's a script thing.

    I got rid of it with Hijackthis, I think. I might have used Hijackthis in combination with SuperAntiSpyware.

    I use Noscript with Firefox now--it blocks everything except what I want to allow. It takes a bit to establish what's ok, but it keeps your browser from diverting away and lets you know when something is going on.
     
  2. Mar 22, 2012 at 6:29 AM
    #42
    clarkie152

    clarkie152 Well-Known Member

    Joined:
    Dec 25, 2009
    Member:
    #28146
    Messages:
    553
    Gender:
    Male
    MA
    Vehicle:
    2016 4Runner Trail
    LED light swap, TRD wheels, KO2s, C4Fab lo-pro
    Seems like its your host file that is redirecting.... try Norton Power Eraser
     
  3. Mar 22, 2012 at 6:31 AM
    #43
    leveltwo

    leveltwo Well-Known Member

    Joined:
    Apr 19, 2011
    Member:
    #55215
    Messages:
    570
    Gender:
    Male
    we had this on one of our computers at work, they had to send it off somewhere to have it fixed...
     
  4. Mar 22, 2012 at 6:37 AM
    #44
    Devux

    Devux Well-Known Member

    Joined:
    Oct 16, 2011
    Member:
    #65267
    Messages:
    68
    Gender:
    Male
    First Name:
    Devin
    Las Vegas, NV
    Vehicle:
    2014 TRD Sport 4x4
    Leveling kit & wheels
    Just re-install the OS, something that is infected that badly isn't worth messing with. My suggestion is to make an image of your PC right after you get the OS installed, drivers installed and OS patched. That way if you ever have to do it again, it is that much less work next time. Look into http://clonezilla.org/ it is a free alternative to Norton Ghost and the like.
     
  5. Mar 22, 2012 at 6:38 AM
    #45
    KenpachiZaraki

    KenpachiZaraki Its Wicked Flow BITCHES!!

    Joined:
    May 24, 2009
    Member:
    #17581
    Messages:
    4,159
    Gender:
    Male
    First Name:
    Alex •﹏•
    Lubbock
    Vehicle:
    05 TRD. 325/275/365 SBD
    ALL POSER- Afe Pro Dry S drop in filter, 3" AP leaf pack, Eibach w/5100's up front, 5100's rear, Fog Light Mod, ABS off mod, Dash Light MOD, Doug Thorley Long Tube Headers, Wicked Flow Bitches MAX Muffler, 4" floods, 20", 43" light bars, 265/75/16 Hankook Dynapro ATm, oil catch can, rear diff breather relocate, Custome Sliders, SOS concepts Front bumper, Demon Eye Mod, backlit TRD emblem on bumper, Morimoto D2S projectors,
    Good info, my moms computer only lets us surf the web on my sisters profile, but it was working before . I believe it has this redirect virus, its freaking annoying.
     
  6. Mar 22, 2012 at 6:41 AM
    #46
    mgrande

    mgrande iKill

    Joined:
    Apr 11, 2009
    Member:
    #15830
    Messages:
    5,363
    Gender:
    Male
    Raleigh
    Vehicle:
    2011 TRD off road
    Kings, AP 3" leaf pack, timbrens front and rear, TC UCA's, pro comp 7189's, baja ATZ's, CBI sliders and rear, relentless front, dynomax catback
    microsoft security essentials
     
  7. Mar 22, 2012 at 1:56 PM
    #47
    MurphMan

    MurphMan Senility Rocks!

    Joined:
    Mar 21, 2008
    Member:
    #5413
    Messages:
    760
    Gender:
    Male
    First Name:
    Murph
    Maine
    Vehicle:
    '08 Tacoma TRD Sport
    * AFE Stage 2 XP CAI System * Westin Platinum Series Black Step Bars * TruXedo Lo Pro QT Soft Roll-Up Tonneau * Dee Zee Heavyweight Truck Bed Mat * WeatherTech Extreme-Duty Floor Liners * WeatherTech In-Channel Window Visors * Sony Xplod CDX-GT81UW Receiver * Sony Xplod 2-way speakers * Boss Audio BASS600 Amplified Subwoofer * Billet Grille Mod
  8. Mar 22, 2012 at 2:08 PM
    #48
    MountainEarth

    MountainEarth Well-Known Member

    Joined:
    Feb 1, 2010
    Member:
    #30519
    Messages:
    2,481
    Gender:
    Male
    First Name:
    Bryan
    CO
    Vehicle:
    2010 TRD OR Access
    Leer 100XR Shell, BedRug mat - comfy sleeping, GT Covers microfiber seat covers, BFG All Terrains 265/70r16, Dashmat, Antennax 13" shorty antenna, Weathertech liners, Ultra Gauge, Avid Light Bar, PIAA 520 ATPs, one old dog
    This ^^ big time. That might be why you're getting reinfected.

    Also
    http://www.bleepingcomputer.com/virus-removal/remove-tdss-tdl3-alureon-rootkit-using-tdsskiller. I know you said you tried it, but perhaps this page will give you a bit more info.

    Renaming TDSSkiller.exe might help too.

    Also check out the tools from Avira. I've had great success with them, especially the bootable rescue CD (Avira AntiVir Rescue System) whcih allows you to boot off the CD, bypassing Windows. It's free. They've got a nice anti-rootkit tool as well.

    But MAKE SURE you turn off system recovery first!
     
  9. Mar 22, 2012 at 3:52 PM
    #49
    neontrail

    neontrail ✈ ✈ ✈ ✈ ✈ ✈ ✈

    Joined:
    Apr 9, 2008
    Member:
    #5844
    Messages:
    10,109
    Gender:
    Male
    Idaho
    Vehicle:
    2004 NISSAN XTERRA XE/SE
    De-badged, Tint 20%, Blue 48 LED dome-light, .......
    such great info in this thread
     
  10. Mar 22, 2012 at 8:31 PM
    #50
    macgyver

    macgyver [OP] Well-Known Member

    Joined:
    Aug 14, 2009
    Member:
    #21173
    Messages:
    3,577
    Gender:
    Male
    First Name:
    Brad
    Canton, GA
    Vehicle:
    '13 Tundra double cab SR5 4x4
    It's redirecting to random websites, not really consistent.





    I'll try that. Thanks
     
  11. Mar 23, 2012 at 2:52 AM
    #51
    MurphMan

    MurphMan Senility Rocks!

    Joined:
    Mar 21, 2008
    Member:
    #5413
    Messages:
    760
    Gender:
    Male
    First Name:
    Murph
    Maine
    Vehicle:
    '08 Tacoma TRD Sport
    * AFE Stage 2 XP CAI System * Westin Platinum Series Black Step Bars * TruXedo Lo Pro QT Soft Roll-Up Tonneau * Dee Zee Heavyweight Truck Bed Mat * WeatherTech Extreme-Duty Floor Liners * WeatherTech In-Channel Window Visors * Sony Xplod CDX-GT81UW Receiver * Sony Xplod 2-way speakers * Boss Audio BASS600 Amplified Subwoofer * Billet Grille Mod
    Try posting over on bleepingcomputer.com. They'll walk you through a process to ID and extract the malware. Do exactly as they tell you and nothing more. They have good folks on that forum.
     
  12. Mar 23, 2012 at 5:17 AM
    #52
    98tacoma27

    98tacoma27 is going full "SANDWICH" Moderator

    Joined:
    Dec 18, 2008
    Member:
    #11714
    Messages:
    67,731
    Gender:
    Male
    First Name:
    Ben
    Not Beech Creek
    Vehicle:
    05 Tundra SR5 (+295k AND COUNTING), 2006 F350 King Ranch 6.0L
    Some stuff. Not a lot, just some.
    I see I'm not the only one suffering. I'm slowly working my way down the thread trying each suggestion. I got mine through something called Internet Security. It's one of those "You have a virus. Buy me and I'll get rid of it" virus's. Looks like this:

    [​IMG]

    I got rid of that and now have the Redirect BS. :frusty:
     
  13. Mar 23, 2012 at 5:51 AM
    #53
    tbturner47

    tbturner47 Well-Known Member

    Joined:
    Apr 17, 2010
    Member:
    #35484
    Messages:
    1,148
    Gender:
    Male
    Hickory, NC
    Vehicle:
    '16 Barcelona Red TRD Off Road


    This. I can send you a new HOST file, but check out bleepingcomputer.com they are pretty good. I've had to remove this virus several times for clients.
     
  14. Mar 23, 2012 at 6:07 AM
    #54
    MurphMan

    MurphMan Senility Rocks!

    Joined:
    Mar 21, 2008
    Member:
    #5413
    Messages:
    760
    Gender:
    Male
    First Name:
    Murph
    Maine
    Vehicle:
    '08 Tacoma TRD Sport
    * AFE Stage 2 XP CAI System * Westin Platinum Series Black Step Bars * TruXedo Lo Pro QT Soft Roll-Up Tonneau * Dee Zee Heavyweight Truck Bed Mat * WeatherTech Extreme-Duty Floor Liners * WeatherTech In-Channel Window Visors * Sony Xplod CDX-GT81UW Receiver * Sony Xplod 2-way speakers * Boss Audio BASS600 Amplified Subwoofer * Billet Grille Mod
    New host file may not work as I've seen these apps recreate them if they are replaced. I've also seen them locked down so you can't change them out. A process like RKILL is the only way to stop the app and then run the tools to kill the infection. This is why I always suggest people post in bleepingcomputer as they will ask for appropriate logs to determine the best course of action.
     
  15. Mar 23, 2012 at 6:23 AM
    #55
    arrrghhh

    arrrghhh Well-Known Member

    Joined:
    Jan 19, 2009
    Member:
    #12748
    Messages:
    2,062
    Gender:
    Male
    Denver, CO
    Vehicle:
    09 TRD Off-Road
    Custom Front Bumper, Smittybilt XRC-8, 3" OME lift, 33" Falken A/T tires
    Indeed. bleepingcomputer is a great forum, they are very helpful - but like others said, do exactly as they say - no more, no less. Some of the stuff they have you do could be pretty dangerous if you don't follow their directions carefully.
     
  16. Mar 23, 2012 at 6:27 AM
    #56
    tootsgeek

    tootsgeek Member

    Joined:
    Jan 9, 2012
    Member:
    #70278
    Messages:
    14
    Gender:
    Male
    Wisconsin
    Vehicle:
    2006 TRD Sport
    Cigarette lighter to AC adapter DIY Washable Cabin Air Filter Illuminated 4X4 switch LED dome light
    Sorry if someone has already suggested this but you could boot into safe mode and then use system restore to go back to a restore point before you were infected. Good luck
     
  17. Mar 23, 2012 at 6:39 AM
    #57
    98tacoma27

    98tacoma27 is going full "SANDWICH" Moderator

    Joined:
    Dec 18, 2008
    Member:
    #11714
    Messages:
    67,731
    Gender:
    Male
    First Name:
    Ben
    Not Beech Creek
    Vehicle:
    05 Tundra SR5 (+295k AND COUNTING), 2006 F350 King Ranch 6.0L
    Some stuff. Not a lot, just some.
    That doesn't work.

    <-- tried it
     
  18. Mar 23, 2012 at 7:03 AM
    #58
    CRU

    CRU Well-Known Member

    Joined:
    Feb 10, 2011
    Member:
    #50946
    Messages:
    597
    Gender:
    Male
    Seminole Cnty, FL
    Vehicle:
    07 SSM TuRD Sport DCLB
    20" Enkei WT4 wrapped in Bridgestone Dueler A/T Revo 3 265/50, Steel braided brake lines, Pioneer AVH-X5500BHS deck w/JBL GTO cones, OEM Smoked headlights, OEM LED tails, Clazzio seat covers, aFe Pro-Dry S air filter, Fumoto oil valve, Grillcraft MX grille w/Land Cruiser "TOYOTA" emblem, Redline QuickLIFT hood struts, Leather TRD shift knob, 13" shorty antenna
    If it continues to reappear after it looks like it's gone, there is something hidden in your registry. I've run into a virus like this before. Took me almost a week to get rid of it. Malwarebytes got rid of a portion, but I still had to delete a few entries from the registry to prevent a return. I found the entries by using the name of a site it redirected me to and googling "redirect virus <site name>". Good luck.
     
  19. Mar 23, 2012 at 7:04 AM
    #59
    98tacoma27

    98tacoma27 is going full "SANDWICH" Moderator

    Joined:
    Dec 18, 2008
    Member:
    #11714
    Messages:
    67,731
    Gender:
    Male
    First Name:
    Ben
    Not Beech Creek
    Vehicle:
    05 Tundra SR5 (+295k AND COUNTING), 2006 F350 King Ranch 6.0L
    Some stuff. Not a lot, just some.
    Part of my issue is it doesn't redirect to the same site. It's always different.
     
  20. Mar 23, 2012 at 7:28 AM
    #60
    CRU

    CRU Well-Known Member

    Joined:
    Feb 10, 2011
    Member:
    #50946
    Messages:
    597
    Gender:
    Male
    Seminole Cnty, FL
    Vehicle:
    07 SSM TuRD Sport DCLB
    20" Enkei WT4 wrapped in Bridgestone Dueler A/T Revo 3 265/50, Steel braided brake lines, Pioneer AVH-X5500BHS deck w/JBL GTO cones, OEM Smoked headlights, OEM LED tails, Clazzio seat covers, aFe Pro-Dry S air filter, Fumoto oil valve, Grillcraft MX grille w/Land Cruiser "TOYOTA" emblem, Redline QuickLIFT hood struts, Leather TRD shift knob, 13" shorty antenna
    I just picked one. I guess it was a lucky pick. Didn't say it was gonna be easy. :D

    Try googling "google redirect virus registry entries". You might get lucky.

    PS BACK UP YOUR REGISTRY BEFORE FUCKING WITH IT!!!!
     

Products Discussed in

To Top