Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi everyone - I'm in a bit of a bind here and I was wondering if you could help.
I've seen many guides and pleas for help about this infection across the internet but none explain how to get rid of it in detail. I'm willing to cooperate to fix this.OK, so here goes...
The symptoms of this infection include:
Common search engine redirects (Google, Yahoo, etc.)
Redirection of legit. sites (McAfee, Windows Update, etc.) including some computer help sites [these sites redir. to 127.0.0.1]*
Unexpected freezes/system crashes*I have already looked through the Hosts file, already checked proxy settings, already checked firewall settings, etc. etc.
I'm worried mainly about a keylogger obtaining personal info., but it would also be nice if my computer worked correctly again.
I'll post a HijackThis log if "an expert requests it", but be aware that I can't install Spybot S&D (requires internet connection/redirects...), can't update McAfee (ditto/redirects...), and Malwarebytes simply will not start [process is in task manager - will not bring up window]
Any help will be much appreciated; thank you in advance.

First try this:
Click on Start, click Run, and then type devmgmt.msc and click OK
On the View menu click on Show hidden devices
Browse to Non-Plug and Play Drivers and click the + sign to the left, you should see something like TDSSserv.sys in that list.
Highlight that driver and right click on it and select DISABLE - NOT uninstall.
Now RESTART your computer.If that did not work go start > run type cmd and press enter or ok.
type ipconfig /flushdns (The space between g and / is needed)Then press Enter, type Exit, press Enter again, Try to connect to the internet.
If that did not work try Safe Mode with Networking. Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select Safe Mode with Networking, then press "Enter".
Choose your usual account.
Please download Malwarebytes' Anti-Malware from one of these sites:
Rename the setup file, mbam-setup.exe, before you download it. To do that once the "enter name of file to save to" box appears as the download begins in the filename box rename mbam-setup.exe to tool.exe> click save.
1. Double Click tool.exe to install the application.
2. Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
3. If an update is found, it will download and install the latest version.
4. Once the program has loaded, select "Perform Quick Scan", then click Scan. The scan may take some time to finish,so please be patient.
5. When the scan is complete, click OK, then Show Results to view the results.
6. Make sure that everything found is checked, and click Remove Selected.
7. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
8. The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
9. Copy&Paste the entire report in your next reply.
Please download and install the latest version of HijackThis v2.0.2:
Download the "HijackThis" Installer from this link:
Hijack This
1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
If Malwarebytes installed but will not run navigate to this folder:
C:\Programs Files\Malwarebytes' AntiMalware
Rename all the .exe files in the MAlwarebytes' Anti-Malware folder and try to run it again.
For Hijack This if it will not run rename the Hijack This.exe file to somethingelse.exe and try installing it again.

Hello again - I am glad to say that your first suggested step has fixed all the problems. I cannot thank you enough and can assure you that I will be running updated versions of all my anti-virus/anti-spyware programs as well as a firewall. I am currently running 2 scans, and updating EVERYTHING. Thank you so much. I will definitely bookmark this site and tell all my friends. Would you still like me to post the Malwarebytes' and HijackThis logs?

![]() |
Google Redirect Virus !!!
|
winupgro.exe removal
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |