• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Redirect Virus

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

jaredavidporter

Member
Joined
Oct 3, 2005
Location
Mesquite, Texas
Well I never thought I would be asking for help on virus related issues..

Browser: Firefox Mozilla 9.0.1
Laptop: Asus G73JH-BST7
OS: Windows 7 Home Premium 64x



So a couple of months ago I got this nasty virus on my laptop; No clue how it got on here, possibly because I let my mother use it for the day. It started off as one of those fake antivirus programs. I went through the appropriate steps to get rid of it but I have been unable to get rid of this redirect virus.

I've been searching around and most people say the redirects only occur when using google. That's not the case for me, they occur on any website. What's strange about it is that once I click back and try clicking on different links I will get redirected to a different area on that website. For example: I click a link on reddit, get redirected to some adspam-website, click back to reddit, once I try to click a link within reddit again (any link not just the one I was redirected from) I get redirected to reddit's help page. This happens on several other websites too such as my school's website.

I've used just about every antivirus/malware program trying to get rid of it and still nothing. I've thought about reformatting my hdd but that's a last resort.
 
Is there a proxy set for the browser or for the entire system? Is your hosts file modified? What have you scanned your system with?
 
If you haven't already, boot into safe mode and run Norton's Powr Eraser (free), select scan and restart to check for rootkits. When it reboots go back into safe mode (never scan in normal if you can avoid it). NPE will run at the next startup even in safe mode. Let it do its thing and if it finds stuff, obviously have it remove those items (be sure to check what it finds, I have seen it flag network app shortcuts as a risk even though they were not). It will reboot, again go back into safe mode and it will scan to verify the removal worked. Then run combofix and malwarebytes. If it's not being found by any of these, you have been infected with one of the only viruses I have not been able to remove (professionally) in quite some time. I had to wipe/restore the machine, but that was before I started implimenting Norton Power Eraser into my removal routine. It's a compact app and scans quickly, so it's worth adding to the toolkit. It's also detecting things combofix is completely missing!
 
Back