ForumsSupport ForumRedirected

4 1525
Evilfishy111
offline
Evilfishy111
1,386 posts
Shepherd

Though this topic isnt related to anything on armor, I could only ask here, because when I go on google now, and I click on a link, I keep getting redirected to random sites, such as seek, kidspot crap, and other sites so on so forth. Then after a few times of going back and clicking on the link again, it would take to that place, so If i search on google, and click on a link, it would just redirect me to some other crap site I dont even want to go to. Anyone have any idea?

  • 4 Replies
nichodemus
offline
nichodemus
14,991 posts
Grand Duke

It's almost certainly a virus, might be the TDL3, a variant of the TDSS rootkit (also known as Alureon). It's exploiting a vulnerability in Java in order to write a small script into the Firefox folder which constantly redirects your search results to infected servers which may be constantly loading more and more crap onto your drives. Two ways to get around this, one is for Firefox users.

1. Navigate to: C:\\Program Files\\Mozilla Firefox\\extensions\\, look for a folder that is a string of letters, created around the time you began having the problem. Something like ''{BCB94CDD-5542-403F-9FB3-07D3DB1E9951}''
2. Open the folder, and then open the folder called ''chrome'', then ''content'', and look for a file inside called overlay.xul (variants may have different names).
3. Verify that it is the virus: does it have code similar to this: click to see code
4. If you have found the culprit, delete the file (or encrypt with Axcrypt which is reversible).
5. Replace it with a blank text file with the same name and extension.
6. Repeat the process â" you may have multiple copies in multiple folders.
7. Test: Go back to Google, try your search results again.

Second way is to just use an anti-virus software. Try to use your own installed software, before trying the free ones below.

Ad-Aware Free
Spybot S & D
Hitman Pro

Evilfishy111
offline
Evilfishy111
1,386 posts
Shepherd

Thanks Nicho, but when I got to step two, I opened the folder which had the numbers, but there were no folders in there, all there was was three files, two PNG images, one called icon and another preview, and a RDF file called 'install', by the way, your link at step 4 didnt work. Apparently my anti virus software says the virus is a high risk Trojan.zeroaccess. Any idea Nicho?

nichodemus
offline
nichodemus
14,991 posts
Grand Duke

Delete the virus.

Evilfishy111
offline
Evilfishy111
1,386 posts
Shepherd

Thanks for the help Nicho. Really appreciate it. I removed of it and now its gone, thanks again.

Showing 1-4 of 4