BullGuard
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution  
Forum Quick Jump
 
New Topic Post reply to : PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution Printable version of : PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
35 posts in this thread.
Viewing Page :
 1  2 
[ << Previous Thread | Next Thread >> ]

virusbuster08
New Member


Date Joined Nov 2008
Total Posts : 3
 
   Posted 11/13/2008 5:40 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
So I had the same issue and used this forum among many others to try and solve the problem and it turned out to be easier than any of the steps provided for in any forum.

Follow this step by step and your computer will be back to normal.

1. Download malwarebyte (latest version with all the updates) on a good computer.
2. Put it on a flash drive
3. Transfer it to the infected computer
4. Rename the file to setup.exe
5. Run the setup.exe file
6. Rename the directory it's installing to as Malware and rename the folder as Malware too in the installation setup screen
7. When it gets to the final step of the installation it will seem like it froze....it hasn't but it will take anywhere from 15mins to an hour to get through that step so just let it do its thing.
8. Go into the Malware folder in through Program Files
9. Rename the mamb.exe or what not file to mab.exe and run it.
10. Do a full computer scan
11. It should bring up 10-20 viruses most of which are the source of this problem the TDSS trojan virus.
12. Check all and remove/fix/delete them.
13. Restart your computer and you should be back to normal.

I would also update your virus protection, clean house in your computer and get rid of all unused software and run a disk defragment.
Back to Top
 

Ecstasy
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11/13/2008 8:28 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
So the main point is to make it run as a different name other than Malwarebytes?

Is it because the virus can detect Malwarebytes and stops it from launching?


That's the problem I'm having. I'll try this when I get home.
Back to Top
 

virusbuster08
New Member


Date Joined Nov 2008
Total Posts : 3
 
   Posted 11/13/2008 8:42 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Yea. It seems like the virus only has the programs listed by name. So rename everything i listed above...the install file, the folders and the exe file and it should run.

Malwarebyte is the only thing that will remove it.
Back to Top
 

Ecstasy
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11/14/2008 12:09 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Thank you very much.

I'll try this once I get home.

It's strange going home from school and actually doing homework rather than procrastinating with your computer, huh? lol

Seems like I get more work done without my computer interrupting me.
Back to Top
 

marybethg2312
New Member


Date Joined Nov 2008
Total Posts : 3
 
   Posted 11/14/2008 2:23 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Worked like a charm..Thank you for posting!!!
Back to Top
 

solana
New Member


Date Joined Nov 2008
Total Posts : 24
 
   Posted 11/14/2008 1:18 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Virusbuster -

This is simply the best idea I've read (and I've spent probably 12 hours working on this problem over the past few days). I'll let you know how it goes.
Back to Top
 

Ecstasy
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11/14/2008 3:38 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
solana, could you also post in here how it went?

I've yet to come home and try this method out.


If it works for you, it'll most likely work for me, considering how we have almost identical problems.
Back to Top
 

morgan1
New Member


Date Joined Nov 2008
Total Posts : 2
 
   Posted 11/14/2008 5:03 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
hey i have the exact same problem and i tried your method
the installation worked but when i renamed the file to mab.exe and opened it, it still wouldnt open...
am i doing something wrong or?...
Back to Top
 

morgan1
New Member


Date Joined Nov 2008
Total Posts : 2
 
   Posted 11/14/2008 5:06 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
scratch that.. it just opened :)
 
 
Back to Top
 

usmc1868
New Member


Date Joined Nov 2008
Total Posts : 1
 
   Posted 11/14/2008 8:43 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Morgan has the TDSS Trojon been completly removed with the posted formula from your computer??  I myself was infected lastnight, is this a new virus?  I have not tried anything yet, did not want to make any hasty decisions to only end up completly crapping out the entire laptop.  Any info would surely be appreciated by anyone who can help me erradicate this from my computer.  Do the people out there have anything better to do with there time other than being a bunch of menaces on society!!!!!!!!!!!!!!
Back to Top
 

Ecstasy
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11/15/2008 2:43 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
virusbuster, I did everything that you wrote out.

When I finished installing Malwarebytes, it asked if I want to Update/Launch. Do I leave those checked?

I left them checked, and Malwarebytes still didn't launch.

And also, I renamed mbam.exe to mab.exe, but it still didn't launch, but it's in Processes (task manager).





Links to screenshots:
http://i35.tinypic.com/r0r311.jpg
http://i33.tinypic.com/68ey6x.jpg
http://i38.tinypic.com/nleb20.jpg

It still wouldn't launch. Any help?
Back to Top
 

solana
New Member


Date Joined Nov 2008
Total Posts : 24
 
   Posted 11/15/2008 3:45 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Ecstasy -

Exact same outcome here. And I was hopeful! I'm letting it run in hopes that it will eventually open up and do its thing (the installation took a solid 10 minutes before it was done)

I'm really ready to wipe my harddrive and be done with this. I backed up all the family photos last night. This weekend - one way or another - I'm going to be rid of this thing.

I'll post back if it runs.
Back to Top
 

Ecstasy
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11/15/2008 6:17 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Well, solana, hopefully, it works out for you.

It turns out that when I went into safe mode, I didn't notice I had Administrator as an account. I logged onto that, did what virusbuster posted, and Malwarebytes launched.

The scan took almost 2 hours, and it only found 3 main viruses/trojans, all of them were related to TDSS.

I'm thinking of doing a scan in my regular mode (not safe mode) right now. I'm running Opera, since my Firefox didn't seem to work with the virus being on my computer. So far, everything's working like the way it should be.


Edit: Spybot is not launching. Hmm, strange.
Back to Top
 

Ecstasy
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11/15/2008 6:31 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Edit: I'm running a scan right now on Malwarebytes in regular mode (not safe mode), and here's what happening so far:



Link: http://i36.tinypic.com/fxxoar.jpg


There's still the virus because when I re-installed Firefox, it still had the go.google link for every search result. Hopefully, these 10 objects infected are the ones that virusbuster was talking about.


Maybe it'll work for you, solana:

1.) Go in safe mode on your computer (keep pressing F8 before the main Windows screen pops up)
2.) If you see an Administrator account, log onto that
3.) Follow virusbuster's rules step-by-step
4.) Run Malwarebytes (now with the exe name of -> mab.exe)
5.) Wait for it to finish scanning; quarantine and then delete the infected objects
6.) Log back onto your regular mode (not safe), and you should be able to launch Malwarebytes normally now
7.) Do a full/quick scan once again, and you'll see that there are still more viruses/trojans to be deleted

I'll post up what happens after a couple of scans (see if go.google is gone).
Back to Top
 

Ecstasy
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11/15/2008 7:05 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
And sorry for triple post, but my Firefox is now working as opposed to before when it wouldn't even launch (probably because of the virus).

I'll let you know how it goes after a couple of scans.

Edit: Here's the results of a quick scan on Malwarebytes:

Back to Top
 

solana
New Member


Date Joined Nov 2008
Total Posts : 24
 
   Posted 11/15/2008 3:25 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Ecstasy -

Running Malwarebytes in safe mode under the administrator WORKED! Yahoo!

I'm going to try running it in normal mode now -

Thank you both for this help!
Back to Top
 

solana
New Member


Date Joined Nov 2008
Total Posts : 24
 
   Posted 11/15/2008 6:02 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Free at last - free at last!

To summarize:

1. Download malwarebytes on a clean computer and put on a flash drive.
2. Rename it to setup.exe
3. Drag it onto your infected computer
4. Install it - change the names of both directories to another name - I used "Malwar" - be patient - it gets hung up for a full 10 minutes.
5. After installation - rename the mbam.exe file to mab.exe
6. Reboot into safe mode using F8
7. Log on as administrator
8. Run mab.exe from its directory and wait 2-3 hours for it to finish - remove the infected files - about 4
9. Reboot
10. Run mab.exe from your normal mode
11. Allow it to run 2-3 hours until it finishes - remove about 9 infected files - and it requires a reboot to get rid of some of them.
12. Log back in again - and get your life back.

Touch, VirusBuster and Ecstasy -

Much appreciated!
Back to Top
 

solana
New Member


Date Joined Nov 2008
Total Posts : 24
 
   Posted 11/15/2008 6:06 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
And now - can someone give me a really good recommendation for a program that will prevent this from ever happening again? I'm running Avast - and clearly, its not up to snuff.
Back to Top
 

Ecstasy
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11/16/2008 2:43 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
I'm glad it worked out for you, solana.

I went into my C:drive and I saw a new folder named Avenger, and inside were the TDSS dll files. I instantly deleted the folder because it was totally suspicious what with the TDSS name and such. I suggest you do the same. Maybe it's a waste product of the TDSS trojans you got rid of. Still, my computer is working perfectly now, before TDSS attacked it.

And I suggest keeping Malwarebytes for your computer. It's probably the best anti-malware/spyware program now. I also have Spybot on my computer. I've never used Avast, so I can't say much, but my uncle gave me a copy of his ESET NOD32 Business Edition (anti-virus/spyware) and it uses very little resources.

So overall, I have:

ESET NOD32 Business Edition
Spybot
Malwarebytes

I suggest you update all 3 programs daily or at least every 2 days. They're constantly getting updates that'll help to guard/defend your computer from new viruses and attacks. This Google redirect virus seems to be the newest, most malicious one out there right now. I don't think I've ever gotten this bad of a virus so much that it disabled my computer, and slowed it down too.

I've heard AVG is also good, though the free version is not up to par to the other heavyweights such as NOD32 and Avast. Still, all these aforementioned programs beat out the likes of McAfee and Norton. Those are low-grade programs that uninformed people actually think are good.
Back to Top
 

virusbuster08
New Member


Date Joined Nov 2008
Total Posts : 3
 
   Posted 11/20/2008 12:16 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Hi sorry I haven't been on since the day I posted it. Completely forgot.

As for the safe mode, I did it through safe mode but forgot to post that here.

The only thing is that I did not have any avenger folder, that could just be the name/program/downlod that your trojan infected your comp under.

Glad this helped somewhat.
Back to Top
 

chillicane
New Member


Date Joined Nov 2008
Total Posts : 1
 
   Posted 11/23/2008 9:16 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Thanks everyone for this post/forum, ive spent the last 7 hours removing this virus. Its one of the craftiest viruses ive ever seen.

Also while i was writing this sentance a saw a command prompt window open and close in front of my eyes so maybe its not over yet....

ALSO i will be getting NOD 32 antivirus after this, iv thought i was too smart to get stung, but now im here and i guess im not!.
nod 32 comes highly recommended from various people in the tech industry ive spoken too.

Post Edited (chillicane) : 23-11-2008 06:21:11 GMT

Back to Top
 

MeadowMuffin
New Member




Date Joined Nov 2004
Total Posts : 19
 
   Posted 11/23/2008 9:26 PM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Remember folks. Any time you're running any Anti-Spyware programs & they come up with anything close to being serious be sure to Re-run them until they come up clean.
Edit: This was a interesting log to follow including the log that sent me to this one:
http://www.bullguard.com/forum/5/I-got-hit-hard-Dont-know-if-th_68112_2.html


                          FIGHT THE POWER
      "To be nobody but myself-in a world which is doing its best, night and day, to make you everybody else-means to fight the hardest battle which any human being can fight, and never stop fighting".
                              
                                         e.e. cummings (1894-1962)

Back to Top
 

Debora
New Member


Date Joined Dec 2008
Total Posts : 1
 
   Posted 12/1/2008 2:46 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Thank you so much. I finally got the software to launch. I could not launch my husband computer in safe-mode so I went to the command prompt and cd to Malware.
The program is currentl y running and has found 26 infected objects.
Back to Top
 

testorck
New Member


Date Joined Dec 2008
Total Posts : 1
 
   Posted 12/8/2008 8:25 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
I was having the same problem, but it still isn't fixed. In Safe mode, I changed the Malwarebytes folders/program names which allowed me to execute the malware scan. A bunch of crap came up and i hit the fix button. I rebooted, again in safe mode and scanned again. Now only 2 items keep coming up regarding "userinit.exe". I deleted those, but they came up again upon another reboot in safe mode.

Now, when I start up normally, all I see is my background and my cursor with no Taskbar or desktop icons . I am able to hit Ctrl+Alt+Del to bring up the task manager but I am unable to do anything else. Any Ideas on how to fix this at this problem?
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 12975
 
   Posted 12/8/2008 8:35 AM (GMT +3)    Quote: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus SolutionAlert an admin about: PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
Hello testorck smile
 
 
Reboot to safe mode with network.
 
 
Then ->
 
Please download Combofix:
 
And save to the desktop.

Close all other browser windows.
 
Please connect all your external hard drive/flash drive before running Combofix
 
 
 
Important-> Temporarily disable your anti-virus, real-time protection before performing a scan. They can interfere with combofix or remove some of its embedded files which may cause "unpredictable results". 
 
Double-click on the combofix icon found on your desktop.
 
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.  

 When finished, it will produce a logfile located at C:\combofix.txt.

Post the contents of that log in your next reply


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 
New Topic Post reply to : PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution Printable version of : PROBLEM SOLVED - Google Redirect/Antivurs blocked TDSS Virus Solution
35 posts in this thread.
Viewing Page :
 1  2 
 
Forum Information
Currently it is Thursday, October 02, 2014 1:23 PM (GMT +3)
There are a total of 60,630 posts in 13,328 threads.
In the last 3 days there were 2 new threads and 2 reply posts. View Active Threads
Who's Online
This forum has 36455 registered members. Please welcome our newest member, empatbelass.
3 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Kitchen Shops Wakefield (0)10/2/2014 2:39:02 AM (empatbelass)
Bullguard antivirus offline (2)10/2/2014 2:07:56 AM (Sabuz Ahmed)