Question:
How do I get rid of a Search Engine Ad Virus?
David K
2010-06-29 01:30:17 UTC
Every time I click on a link from a search engine such as Yahoo or Google, instead of taking me to the link I clicked on, the browser instead takes me to random advertising sites and prevents me from hitting the back button.

I have run multiple scans with Symantec but it still fails to resolve the problem. Has anyone encountered this type of virus before and knows what I could possibly do to remove it?
Six answers:
Sly_Old_Mole
2010-06-29 02:10:10 UTC
https://answersrip.com/question/index?qid=20100624080054AA3RoXF
2010-06-29 01:50:19 UTC
Virus your computer is highly infected.



First

click on Start > Run. Type in the following into the open box.



devmgmt.msc



then Click on OK. This will run Device Manager. In Device Manager,

click on View > Show Hidden Devices.



expand all the devices by clicking on the "Plus" sign. Now try to find

TDSSserv.sys or clbdriver.sys or oUltraf or seneka.sys,

right click on whatever one you found and select Disable.

Please make sure that you do not select the Un-Install option

otherwise infection will be back once you reboot your computer.



if none of them are there do not worry,

it could be something simpler but follow what comes next.



Delete everything in the windows temp folder,

C > Windows > Temp



Delete all cookies,

Delete all temporary internet files(not to be confused with windows temp files)

these are best deleted via your internet browsers.

it will save you messing about in the the hidden system files



reset internet explorer,

tools > internet options > Advanced tab > reset .



Delete everything in the prefetch folder.

C > Windows > Prefetch



Delete the hosts file,

C > Windows > System32 > drivers > etc > HOSTS

A clean hosts file will be written by windows when you reboot later.

Note: if you were using a custom Hosts file

you will need to replace any of those entries yourself.





Delete the flash cookies found in the macromedia, #Shared Objects folder.

c > users > "your name" > App Data > Roaming > macromedia > Flash player > #Shared Objects

delete everything you find in the #Shared Objects folder



App Data is a hidden folder so you will have to enable view hidden folders.



Run a full scan with this

Sophos Anti-Rootkit : http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html

and remove everything it finds.



Sophos Anti-Rootkit DOWNLOAD : https://secure.sophos.com/support/cleaners/sar_15_sfx.exe



Then run a full scan with this and remove what it finds.

Super anti spyware Pro : http://www.superantispyware.com/



Super anti spyware Pro DOWNLOAD : http://downloads.superantispyware.com/downloads/SUPERAntiSpywarePro.exe

this has a tool built in that can reset the URL prefix's

USE IT.



reset your router to default.



your redirect virus should now be gone.









.
Man of Mystery
2010-06-29 01:35:16 UTC
Yeah, there is a lot of bad stuff on your computer, and you need to remove as much as possible.

If you need to, you should print this page:



Try to do the following:

-Now, the first thing to do is try a system restore to an earlier time before the bad stuff started appearing (if you don't know how to do it, go to Start > Run > type in 'rstrui.exe' > restore my computer to an earlier time). Highly unlikely it will work, but have a go anyway.

-If that fails, and you think you can just delete it, download and run Killbox.

-After that, go to 'TrendMicro Housecall'. If you can, run it, and let it run until it is finished.

-After that, download Malwarebytes Anti-malware. Install, update and run a full scan. When finished, restart your computer, and log back in. Check to see if the virus has vanished. If so, great; if not, well, there are still a few more things to do.

-This time, restart your computer, and rapidly press F8 on your keyboard until a black screen with a lot of choices appear. Look for an option that says 'Safemode'. Select it, and then go into the Admin account. Once you're in, run Malwarebytes again. When it is done, restart your computer once again and then go into your account. Hopefully it will be gone.

-Lastly, if you don't have an antivirus on your computer, I recommend you get Avast! or AVG antivirus. Both of them are quite good, and they don't cost anything. Download, install, run, update and scan.



If at any time, you are unable to complete one of these steps, move onto the next one. If you cannot access any anti-virus website, ask a friend to download and install them onto a USB stick/flash drive for you.



Worst case scenario, copy and paste all your important files (as in, the 'documents and settings' folder) onto an external hard drive or a USB stick/flash drive. Then put your Windows installation disc into the computer, and go into the Boot Menu (it will say what key to press on startup) and repair your computer. If the problem persists, format the computer. If you don't know how to do that, give it to your local computer repair shop or a knowledgable friend and tell them you want your computer formatted and backed-up.



Websites:

http://housecall.trendmicro.com/

http://www.malwarebytes.org/mbam.php

http://www.avast.com/eng/download-avast-home.html

http://www.zonealarm.com/security/en-us/zonealarm-pc-security-free-firewall.htm

http://killbox.net/
2016-06-04 07:42:36 UTC
what you have is not a virus, those are just ordinary pop-up ads that promote a site that you are trying to search on. I suggest you download a pop-up blocker instead. Try yahoo toolbar, it has its own pop-up blocker
?
2010-06-29 09:13:01 UTC
Step by step Search Engine redirect virus removal guide http://deletemalware.blogspot.com/2010/02/remove-google-redirect-virus.html

I hope this helps. Good luck!
2010-06-29 10:26:29 UTC
its a browser hijacker virus known as google redirect virus, heres a solution for it

http://darfuns.com/remove-google-search-result-redirect-virus/


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...