Login Register






[Revolution]The Google redirect virus and how to remove it [TUT] filter_list
Author
Message
[Revolution]The Google redirect virus and how to remove it [TUT] #1
I have recently seen quite a lot of people worrying about Google Redirect Virus. I have made a small effort to help you know about it and various solutions to get rid of it.

What is Google Redirect Virus ?

Google redirect virus, also known as WEB Redirect virus or Yahoo search redirect virus is a most spreading malware virus these days that effects all main Internet search browsers. Simply trying to use a different one will not resolve the problem because it is a deep root issue. When you have this problem then it is because your computer has recently become hijacked by a common trojan that a lot of people are getting.

The virus, Go.google.com mostly redirects the google search results to spam websites that contain adsense or other online advertising companies ads. This google redirect virus also blocks user from downloading programs or any file from the Internet. When the user clicks on download links go.google.com displays the following fake errors:

1).Internet explorer cannot open web page
2).filename.exe is not a valid win 32 application
3).Setup files are corrupted. Please obtain new copy of program

Go.google.com virus is web browser hijacker tool which commonly infects Mozilla Firefox and Microsoft Internet explorer and redirects the user to the following web-sites:

clearask.com
web-analytics.google.com
brittaniasearch.com
go.google.com

The virus, Go.google.com disables the running firewalls and anti-virus softwares and breaks your security, it records and send the web urls visited on the infected computer to the hacker.

Most common signs of this virus go.google.com browser hijacker:
  • It corrupt Registry files and "Blue Screen of Death"
  • It changes the desktop background
  • IE and Firefox slows down after getting infected by go.google.com virus
  • Also infects e-mail attachments, messenger and other freeware programs

The TDL3 Root Kit is the main problem, and it's something that many anti-virus programs are having a tough time addressing. TDL3 is a sub variation of the TDSS rootkit , which is also called Alureon. The main reason that it deceives and sneaks by anti virus detection software is because it hides itself alongside of a driver. The driver does not appear as a threat and so it is allowed to simply pass by.

The driver is a print processor, and because it is granted administrative rights by your system, does not throw up a red flag and goes by completely undetected. Because Windows trusts this process, it does not even catch it before it's too late. Even worse, the virus begins going to work on your computer and effects a lower level of your system drive, which then confuses any possible communication with your hard drive. It cleverly tricks your anti virus software, by presenting it with knowledge that the hard drive is fine, or in its original condition. In other words, the Alureon virus has found a way to camouflage itself.

If you think that your virus protection software will be able to detect these newer problems - think again. The TDL3 Root Kit gives them complete, covert coverage, and so the vicious cycle continues.

How can you get rid of Google Redirect Virus?

You will need to remove the root of the problem, TDSS. In order to do so, follow these steps..

1. Go to START

2. Right Click on MY COMPUTER

3. Choose PROPERTIES

4. Click the HARDWARE tab

5. Now choose DEVICE MANAGER button

6. Click the VIEW tab

7. Select SHOW HIDDEN DEVICES

8. If you need to, click to expand all of the devices

9. Search for TDSSserv.sys

10. Right click on it and choose to "disable" (DO NOT UNINSTALL!)

11. Download and do a scan with an effective Anti-Spyware software program. If you don't have one, Spyzooka is outstanding.

Another Method To Fix Go.google.com redirect problem:

There is Malware Removal tool called Combofix which can fix this go.google.com virus if the above methods are not working for you. Beware that its a DOS based tool and do not interrupt the tool while it is running as it may cause problems with registry entries. Be sure that you are not running any softwares while running scan using Combofix.

Important Note: Don't use Combofix if you are not techie.

[Download Combofix Malware Removal Tool]

Another Solution to fix the issue:

Follow the instruction below in removing the Google Redirect Virus.

The first thing you need to do is download tdsskiller from the following link and save it to your desktop.
Click to Download TDSSKiller

If for some reason you are unable to download the file then TDSS may be blocking it. What you can do is to download TDSSKiller from a clean computer then transfer it to any external drive or USB flash drive.

Not that simple as running a regular program. The creator of the google redirect virus is smart enough to know what TDSSKiller can do. But don’t worry we’re wiser than him. First, rename TDSSKiller by right-clicking the TDSSKiller.exe icon from your desktop and select RENAME.
Now you can edit the name with any name you want but do not forget that it should end with the .com extension. For example, asdfgh.com or 14344.com. Now that it is wearing a mask, you can proceed with the running of the program.
Click the Start scan button to scan your computer for TDSS infection. It will then display a result screen to find out any infection was on your computer.
If the infection is on your computer, you can get rid of google redirect virus by clicking the Continue button. The TDSSKiller will now work on attempting to clear your computer from the infection. If you do not get the message Cure, then just choose the default action Skip and press Continue. Do not attempt to change it to Delete or Quarantine as it may also delete the infected files that are needed for Windows to operate properly.
Once finished, it will give you a report stating whether the cleaning operation is successful. Reboot is required to finish the cleaning process, so click on the Reboot now button and let it finish the removal of the TDSS infection.

Removing Google Redirect Virus using with FixTDSS.exe

In some cases the TDSSKiller fails to do the job even after renaming the program. If you are unable to remove the virus using TDSSKiller, you can use FixTDSS by Symantec. Follow the steps below to remove google redirect virus using FixTDSS.
Download the FixTDSS.exe tool from Symantec
Run FixTDSS.exe then then click the Proceed button to begin the process and allow the tool to complete the cleaning
Restart your computer
After reboot, The tool will provide you the scan and cleaning results.
Check if the Google redirect virus is gone.
All set! Now your computer will be Google redirect virus free.

Fix Hacked Browser:

Download and Run UnHack Me tool that will fixx any browser hijacking, hacking and redriect issues.
The main difference between UnHackMe and other antirootkit software is the detection method.
UnHackMe tries to detect the hidden rookits by watching the computer from early study of the boot process till the normal Windows mode.

UnHackMe is a first bootwatch antirootkit.
Most modern antirookit programs try to detect the rookits when the rookit is already active. They use the very complex methods for detecting hooked system functions. But the rookit authors creates the new tricks and this war will not have the end.

Download UnHack Me tool

After running the tool,

Follow the instructions below:
1). Go to my computer and C:–>Windows–>System32–>Drivers–>etc folder.
2). In this folder, Look for a file named “Hosts”
3). Right click on this file and open it with the notepad
4). Now delete all the lines of IP addresses in the text document except for “127.0.0.1 localhost”.
5). Save the file and close it.

Doing this solves the problem and Now you should be able to surf Internet without any redirect problem. But remember! you still need to get rid of several infected files from your computer, remote registry entries and un-register the DLL files.

Open the registry (start –>run–>regedit). Take a backup of registry before making changes.

Click on edit –> find. Enter the first few letters of the infection name. In this case, I used TDSS and searched for any entries starting with those letters. Every time there is an entry starting with TDSS, it shows the entry and the value on the right side.
If there is just an entry, but no file location mentioned, then delete it directly. Continue searching for the next entry with TDSS
The next search took me to an entry which got details of file location on the right which says C:\Windows\System32\TDSSmain.dll.You need to utilize this information. Open folder C:\Windows\System32, find and delete TDSSmain.dll mentioned here.
Assume that you were not able to find the file TDSSmain.dll inside C:\Windows\System32.This shows the entry is super hidden. You need to remove the file using command prompt. Just use the command to remove it. del C:\Windows\System32\TDSSmain.dll
Repeat the same until all entries in registry starting with TDSS is removed. Make sure if those entries are pointing towards any file inside folder remove it either directly or by using command prompt.

I have seen various causes and solutions to fix it. I have listed down almost all the possible solutions and I wish this will be helpful to you in dealing with the virus.
Only PM me if its important if its not you will be blocked


Need good off shore paid hosting if you know a good place please PM me with the link


Reply

RE: [Revolution]The Google redirect virus and how to remove it [TUT] #2
Thanks for this! Im glad I can actually check for this now! I guess im clean! :epic:

Reply