I Have the Google Redirect virus

November 3, 2010 at 12:21:04
Specs: Windows XP, 512 mg
I have scaned with Malwarebytes and Trojen Remover and neither has found anything. I also tried the search of the device manager for the file TDDServer and it not there either...Please help.

See More: I Have the Google Redirect virus

Report •


#1
November 3, 2010 at 12:23:19
download and run these in this order
1- rkill.exe
2- tdss killer
3- malwarebytes, run a full scan after you do the other 2 first.

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •

#2
November 4, 2010 at 10:52:22
The Rkill and the TDSS Killer did NOT find anything. I am running the Malwarebytes right now, but since nothing was changed, I don't expect anything in that program either.

Any other ideas?

Thanks


Report •

#3
November 4, 2010 at 10:55:19
I don't expect anything in that program either.


Have patience, let the scan finish

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •

Related Solutions

#4
November 4, 2010 at 12:05:42
Malwarebytes finished and found nothing. What now?

Report •

#5
November 4, 2010 at 12:26:00
Combofix will be your best bet:
http://www.bleepingcomputer.com/com...
Follow the instructions carefully and only download it from that website.

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •

#6
November 4, 2010 at 13:16:13
My laptop has the redirect so I tried to download the combofix on my desktop, but my virus program deletes it saying there is a trojen. What now?

Report •

#7
November 4, 2010 at 13:26:50
My laptop has the redirect virus, so I downloaded ComboFix on my desktop but my virus program deletes it saying its a trojen!

What do you think?

Thanks


Report •

#8
November 4, 2010 at 16:20:19
what is your antivirus program?

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •

#9
November 4, 2010 at 16:45:29
The Laptop with the redirect virus is using AVG free version and the desktop has McAfee.

Thanks for all your input, I hope there is a way to get rid of the redirect!


Report •

#10
November 4, 2010 at 17:45:35
turn off the antivirus when installing combofix. I would also add that AVG is not the best by any means, why not unload it and try Avast Free, much better protection and real-time protection.

McAfee is pretty bad too...but it's up to you.

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •

#11
November 5, 2010 at 09:13:25
I had Panda Cloud when I got this redirect...so I did a search and read AVG was supposed to be better. I had not heard of Avast. McAfee came with my new desktop so I am going to use till it expires. I have always used Symantyc Norton Anti Virus before.

I have downloaded Combo Fix on the laptop. If I turn off the AVG do I still leave the internet connection on? I am using a wireless connection.


Report •

#12
November 5, 2010 at 11:09:21
read the tutorial on the webpage

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •

#13
November 5, 2010 at 13:09:31
Here is the log from ComboFix

ComboFix 10-11-04.08 - Jim 11/05/2010 15:36:44.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.151 [GMT -4:00]
Running from: c:\documents and settings\Jim\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jim\Application Data\inst.exe

.
((((((((((((((((((((((((( Files Created from 2010-10-05 to 2010-11-05 )))))))))))))))))))))))))))))))
.

2010-11-05 18:48 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-11-05 18:48 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-11-05 18:48 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-11-05 18:48 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-11-05 18:48 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-11-05 18:48 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-11-05 18:48 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-11-05 18:46 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-11-05 18:46 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-11-05 18:45 . 2010-11-05 18:45 -------- d-----w- c:\program files\Alwil Software
2010-11-05 18:45 . 2010-11-05 18:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-11-05 01:33 . 2010-11-05 01:33 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\Help
2010-11-03 19:55 . 2010-11-03 19:55 -------- d-----w- c:\documents and settings\Jim\Application Data\AVG10
2010-11-03 19:46 . 2010-11-03 19:46 20 ----a-w- c:\windows\system32\drivers\PCTGNTDI.SYS
2010-11-03 19:45 . 2010-11-03 19:45 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2010-11-03 19:40 . 2010-11-05 19:09 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
2010-11-03 19:39 . 2010-11-03 19:39 -------- d-----w- c:\program files\AVG
2010-11-03 19:28 . 2010-11-03 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2010-11-03 17:49 . 2010-11-03 17:53 -------- d-----w- c:\documents and settings\All Users\Application Data\SafeReturner
2010-11-03 16:59 . 2006-06-19 17:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2010-11-03 16:59 . 2006-05-25 19:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2010-11-03 16:59 . 2005-08-26 05:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2010-11-03 16:59 . 2003-02-03 00:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2010-11-03 16:59 . 2002-03-06 05:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2010-11-03 16:59 . 2010-11-03 17:00 -------- d-----w- c:\program files\Trojan Remover
2010-11-03 16:59 . 2010-11-03 16:59 -------- d-----w- c:\documents and settings\Jim\Application Data\Simply Super Software
2010-11-03 16:59 . 2010-11-03 16:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
2010-11-03 01:20 . 2010-10-18 13:41 6146896 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{A342FB53-496D-44D1-9E6D-7F1ED259C77F}\mpengine.dll
2010-11-01 23:56 . 2010-11-02 10:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2010-11-01 23:54 . 2010-11-01 23:54 -------- d-----w- c:\program files\Common Files\iS3
2010-11-01 23:54 . 2010-11-02 13:19 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-11-01 21:05 . 2010-11-03 17:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-11-01 21:02 . 2010-11-03 16:13 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-10-28 16:53 . 2010-10-28 16:53 -------- d-----w- c:\windows\system32\XPSViewer
2010-10-28 16:53 . 2010-10-28 16:53 -------- d-----w- c:\program files\MSBuild
2010-10-28 16:53 . 2010-10-28 16:53 -------- d-----w- c:\program files\Reference Assemblies
2010-10-28 16:52 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-10-28 16:51 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-10-28 16:51 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-10-28 16:51 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-10-28 16:51 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-10-28 16:51 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-10-28 16:51 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-10-28 16:51 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-10-28 16:51 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-10-28 16:51 . 2010-10-28 16:52 -------- d-----w- C:\e235b21ea52ad5f9238683
2010-10-28 13:56 . 2010-09-18 06:53 954368 ------w- c:\windows\system32\dllcache\mfc40.dll
2010-10-28 13:56 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-28 13:56 . 2010-09-18 06:53 974848 ------w- c:\windows\system32\dllcache\mfc42.dll
2010-10-28 13:55 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2010-10-26 23:59 . 2010-10-26 23:59 -------- d-----w- c:\windows\system32\drivers\umdf
2010-10-25 18:23 . 2010-10-25 18:23 -------- d-----w- c:\documents and settings\Jim\Application Data\Malwarebytes
2010-10-25 18:23 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-25 18:23 . 2010-10-25 18:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-10-25 18:23 . 2010-10-25 18:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-25 18:23 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-23 20:45 . 2010-10-23 20:45 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 15:41 . 2009-10-06 16:23 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-18 13:41 . 2006-08-11 13:44 6146896 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2010-09-18 16:23 . 2005-08-16 10:18 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2005-08-16 10:18 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2005-08-16 10:18 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2005-08-16 10:18 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-15 08:50 . 2010-05-06 14:50 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-15 06:29 . 2009-10-09 20:27 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-10 05:58 . 2005-08-16 10:18 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2005-08-16 10:18 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2005-08-16 10:18 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2005-08-16 10:18 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2005-08-16 10:18 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2005-08-16 10:18 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2005-08-16 10:18 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2006-01-23 18:32 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-28 00:28 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2005-08-16 10:18 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2005-08-16 10:18 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2005-08-16 10:18 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-01 18:47 . 2009-04-01 18:47 4816122 ----a-w- c:\program files\avi-pro-regnow.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-03-10 28160]
"DVDTray"="c:\program files\HP DVD\Umbrella\DVDTray.exe" [2003-07-23 69632]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2010-08-02 1167808]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-23 98304]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk - c:\program files\CreataCard\Gold\FMRemind.exe [2006-2-9 189952]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-1-23 24576]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-2-7 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-2-7 438272]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-3-21 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 22:08 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11/5/2010 2:48 PM 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/5/2010 2:48 PM 17744]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 hpusbwdm;HP DVD Movie Writer dc3000;c:\windows\system32\drivers\hpusbwdm.sys [1/13/2008 6:46 PM 1080064]
S3 RegKernelHelp;RegKernelHelp;\??\c:\program files\Safe Returner\RegKernelHelp.sys --> c:\program files\Safe Returner\RegKernelHelp.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-11-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://myyahoo.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Add animation to IncrediMail Style Box
Trusted Zone: musicmatch.com\online
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-05 15:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1092)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2010-11-05 15:52:31
ComboFix-quarantined-files.txt 2010-11-05 19:52

Pre-Run: 23,979,286,528 bytes free
Post-Run: 24,645,791,744 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 975F92E014934E6F5373FB8890E5A687


Report •

#14
November 5, 2010 at 13:21:50
Is yur PC running better?

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •

#15
November 5, 2010 at 13:54:11
I am not getting the redirect that I was, but I am having trouble with serches. Such as I did a search on insurance and clicked on farmers offical site, but it wouldn't open. I tried some others and they open ok. Did I loose any files I need to reinstall?

Report •

#16
November 5, 2010 at 14:05:08
It appears as though now I am being redirected by Yahoo. Could that be possible?

Report •

#17
November 5, 2010 at 16:35:48
which browser are you using?

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •

#18
November 5, 2010 at 17:08:42
I am using Internet Explorer 8. After I posted I tried many searches and some worked and some didn't. I checked some of the ones that didn't on my desktop and they worked there. Soooo I am wondering whats up?

Thanks again for all your help!


Report •

#19
November 5, 2010 at 17:19:52
sorry, maybe someone else has some ideas

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •

#20
November 5, 2010 at 21:33:32
When you ran Rkill previously, did you reboot after it finished, or after it finished, did you download and run TDSS Killer?.

Helpful tips before getting started: http://www.computing.net/howtos/sho...


Report •

#21
November 6, 2010 at 11:38:11
Okay, first try turning off Javascript in Internet Explorer 8 by going to "Tools", then selecting "Internet Options", then going to the "Security" tab, and clicking on "Custom Level...", from there scroll down and highlight the "Scripting" option, and click "Disable". Now, re-download Rkill from here: http://download.bleepingcomputer.co... , and after it finishes running, please DO NOT reboot, as this will cause the malware to restart (Rkill is a malicious process ender, which won't remove the infection, but will stop it from running temporarily), then re-download and also follow the instructions here to run TDSSKiller: http://support.kaspersky.com/viruse... after that finishes running, please reboot and then let me know if that solved your problem, and if not, I'll see what else we can do.

Also @Tinkus, please post your ComboFix Log, and or problem in a new thread in the Security/Virus forum for a member to look over and help you with.

Helpful tips before getting started: http://www.computing.net/howtos/sho...</


Report •

#22
November 7, 2010 at 11:27:21
Neither RKill or TDSSKill found anything & I am still having probles with some links. Any other ideas?

Thanks


Report •

#23
November 7, 2010 at 11:28:51
Oh yes..should I turn scripting back on?

Report •

#24
November 7, 2010 at 13:34:38
I would leave it off for right now, as it will cause the redirecting to stop temporarily. Since TDSS Killer did not find anything, nor did ComboFix really fix the issue. I'd like to try and change your DNS settings and see if that works:

Before following these steps, please go to Start > Run and type "Cmd.exe" without the quotes, you'll then see a black box pop up, which is the command prompt. Please type in "Ipconfig /flushdns" without the quotes, and remember to have a space between the "g" and the "/" as shown.

To change your DNS servers follow these steps:

Step 1) Right click on your Wireless Connection in XP.

Step 2) Click on Open Network Connections.

Step 3) Right click on your Wireless Connection (I.E. Wireless Connection 2) and go to Properties.

Step 4) Scroll down to Internet Protocol (TCP/IP) and click the Properties box,

Step 5) At the bottom check the radio button that says "Use the following DNS Server addresses".

Step 6) For Preferred DNS Server type in "208 67 222 222",
and for Alternate DNS Server type in "208 67 220 220".

Step 7) Reboot.

The servers you will be using are those of OpenDNS which you can find more about here: http://en.wikipedia.org/wiki/OpenDNS

Also besides being redirected, are you experiencing any Audio-ad type pop-up's (Such as hearing Ad's but not seeing any), along with a "clicking" noise of the tabs in IE 8?..


Helpful tips before getting started: http://www.computing.net/howtos/sho...</


Report •

#25
November 7, 2010 at 17:34:19
I want to give you an update before I try your instructions....I seem to only have problems with yahoo search. I searched the same query with yahoo & Google....With Yahoo 8 of ten finds I clicked on would not come up. Google opened all the items I clicked on with their search......Please advise me.

Report •

#26
November 7, 2010 at 17:42:33
Are you using a Yahoo toolbar, or a Yahoo homepage?.

Helpful tips before getting started: http://www.computing.net/howtos/sho...


Report •

#27
November 7, 2010 at 17:48:06
Homepage

Report •

#28
November 7, 2010 at 18:16:04
When you say the results don't come up in Yahoo, do you mean when you click on the links that they won't physically open, or you're redirected again?. Also, if Google works, then I suggest changing to that, as long as you're not still being redirected.

Helpful tips before getting started: http://www.computing.net/howtos/sho...


Report •

#29
November 8, 2010 at 16:28:59
With a Yahoo search, when I click on the links they don't always open...a page comes up with a continue button and when I click on that it says it can't display the page......I tried with Google and every link worked without a redirect. Thats GREAT!...but I am wondering what happen to my Yahoo search??? I have used it from my home page for a very long time and not had this problem before. Had hopes you knew what had happened when I had used the RKill, TddsKill & the Combo fix???

Thanks


Report •

#30
November 8, 2010 at 17:13:32
Sorry it took me so long to respond!. I would try resetting your Host file, as that might fix the problem, but I'm not totally certain. You can do this by downloading Hostxpert from the following link and following the provided instructions: http://forums.majorgeeks.com/showth...

Helpful tips before getting started: http://www.computing.net/howtos/sho...</


Report •

#31
November 11, 2010 at 17:02:42
I will try your request and get back to you as soo as I can...I am in the middle of a family crisis at the moment.

Thanks


Report •

#32
November 13, 2010 at 07:27:30
Yahoo.............seems like it worked......can't thank you enough. You guys are the best!

Report •


Ask Question