Why does NOBODY have a fix for GOOGLE REDIR?!

May 18, 2011 at 18:03:46
Specs: Windows 7
Have worked in IT for 12 years, running repair business for 8. I have never come across a more ridiculous infection than this redirect BS. Every time I see it, it takes something different to fix.

Today I have spent 3 hours trying to fix one to no avail.

I have tried:

Sophos Anti-rootkit

NOTHING WILL FIND IT. The best one I've had success with in the past is tdsskiller, but it WILL NOT RUN regardless of what I rename it. renaming it explorer.exe will generate me an error if I try to run it, but otherwise it just immediately kills itself.

Seriously ? How can an infection as common as this b---tard have no routine fix? Does ANYONE have some suggestions because I'm at my wits end.

May 18, 2011 at 18:18:16
Have you tried renaming TDSSKiller with a .com or .scr extension before you run it?

Follow with RKill

Try running the Vipre Rescue program. It runs from the command prompt, and will scan for, and remove most malware, including rootkits. It normally runs when other programs won't.

Vipre Rescue download:

If the file does not download, copy/paste the following >without the quotes or brakets< into the address bar of your browser

May 18, 2011 at 18:29:36
Have renamed both tdsskiller and rkill to random file names with extensions *.scr, *.pif, *.com, *.bat.

RKill will "run" but nothing happens.

Add "Hitman Pro" to the list of "didn't work".

downloading vipre now.

May 18, 2011 at 19:43:25
A log named MBRCheck_date_time.txt (i.e. MBRCheck_05.18.11_10.22.51.txt) should have been created on the Desktop, or in the same folder from which you ran the program.

Can you provide the MBRCheck log in your reply?

May 18, 2011 at 19:43:39
Vipre did not work either.

May 18, 2011 at 19:48:45
I should also note the hosts file is clean

May 18, 2011 at 20:08:33

Kaspersky's AVP tool has detected "MEM:Rootkit.Win32.Sst.a" but cannot remove or disinfect.

May 18, 2011 at 20:54:46

Kaspersky's AVP tool also detected TDSS.e and said it would cure upon reboot. Reboot came and went, redirect is STILL THERE.

I'm at a complete freakin loss.

May 18, 2011 at 21:00:55
*Update 3*

Have also run RootRepeal and Gooredfix to no avail.

So to consolidate, here's everything I've run and still have the redirect:

Hitman Pro
Kaspersky AVP
Sophos Anti-rootkit

12 different tools and not one has caught/fixed this effing thing. I swear I always get the oddballs.

May 18, 2011 at 21:08:44
You are on the right track. Keep cool...let's confirm and re-confirm.

Please download aswMBR;
Save to your Desktop.

Double click the aswMBR.exe icon to run it
Click the Scan button to start the scan

Upon completion of the scan, click the Save Log button
>>Save the log to your Desktop. and post it in your reply.<<

Also download GMER’s mbr.exe: http://www2.gmer.net/mbr/mbr.exe
Save it on your C drive (so the file is recognized as C:\mbr.exe).

Go to Start > Run, and type cmd in the blank area
Press: OK
At the command prompt (black screen) type or copy/paste the following commands, one at a time, and press Enter after each:


mbr.exe -t

Then, type exit and press Enter to close the command window.

The report created in the command window is saved to C:\mbr.log.

>>Please locate the mbr.log, and post it in your reply.<<

Got to get some Zzzzzs...early rise tomorow. If at all possible, let things be, and don't run any other programs for now. Will be back with you tomorrow.

May 18, 2011 at 22:08:33
Well after running aswmbr the computer decided not to boot anymore.

Ran a "repair" on the OS and everything is working now, redirect gone. Running full scan with malwarebytes just to be sure.

Was really hoping to avoid all this as they had some specialized software that will need to be re-setup, but it is what it is. What a nightmare.

May 19, 2011 at 05:51:57
Some of these viruses are designed to infect the Master Boot Record (MBR), and by doing so, the virus is able to continuously re-infect the PC after each removal.

Actually, it is better to start clean.

Vipre Rescue runs from the command prompt. You may want to give it a whirl.

Let us know how it goes.

May 19, 2011 at 08:18:35
I stated in post #4 that vipre did not work.

I know that these things hide in the MBR. What amazes me is I never have one give me as much trouble/be as undetectable as this google redirect.

May 19, 2011 at 20:52:54
Glad you finally got rid of it. I know the frustration. Part of my job is dealing with these for various users from time to time.

I'm going to keep this thread for reference later...the tools mentioned may come in handy.

Just out of curiosity, what version of Windows was this ...AND....did you ever slave the drive on another PC and run scans from there?


> PLEASE HELP OTHERS - Report back what did/didn't work for those referencing this thread.<

May 19, 2011 at 21:02:41
This was Windows XP, and no I never slaved the drive on another PC. Will try that in the future though.

Report •

'Have worked in IT for 12 years, running repair business for 8
I've been repairing PC's for 10 yrs now and do not find the problem you had hard at all, I usually have it cleaned out after about 4 different scans.

The redirects are all different animals so that's why using 4 good scanners will find it without having to mess with the registry or having to reformat.

Many of the cleaners you used are old hat already.

Some HELP in posting on Computing.net plus free progs and instructions Cheers

Report •

July 2, 2011 at 02:42:49

Could you please tell me what four scans you used that resulted in the elimination of the redirect virus? Do you run all four scans simultaneously, or one at a time?

I really don't want to have to reformat my entire computer (as many have recommended) to get rid of this virus.

Thanks for your help!

Report •

