How to remove the Google Redirect Virus on my gf's pc? Nothing seems to work!

Hi Guys,
So I was trying to save my girlfriend's pc from this Google Redirect Virus (the one where you are redirected to some random commercial site when you click on a link in google), but I am having real trouble. Of course I want to solve this and be her hero, so could someone please give me some advice?
I've tried everything. The TDSS-killer, the changing of the host file, I've downloaded several anti-malware or spyware programmes, but nothing helps. I can recommend everybody with this problem to download the NoScript Add-On, so that at least you don't really go to the commercial website, but are redirected (after being redirected) back to google.
This is what I know:
- When I tried to solve something in MSConfig, I noticed that there where two weird programmes that started when I turned on her pc: the first is (the virus!) SetWallpaper.cmd. I can't seem to find this anywhere else on her pc and I do not know if it is connected, but I need to destroy it somehow. The second is some process called: 'fyhgylwg', and it's task is to 'rundll32 C:\User\GF'sName\Roaming\winsta8.dll, Clxeigube'. The reason this caught my attention is because the task isn't sent by Microsoft, but by 'Unkown' and I found it's name really weird.
- No anti-virus programme seems to solve the problem
- I haven't tried Combo-Fix yet, because I do not know the name of the file that is causing the problem
Please help me and my girlfriend out! What can we do?
Boris

Perform the suggestion mentioned in the following articles:
* [https://support.mozilla.com/en-US/kb/Template:clearCookiesCache Clear Cookies & Cache]
* [[How to clear the cache#w_clear-the-cache|Clear the Network Cache]]
* [[Searches are redirected to another site]]
* [[Is my Firefox problem a result of malware]]
Check and tell if its working.

Similar Messages

  • How do I get rid of the Google Redirect virus on ipad2?

    Everytime I type in a search topic or click a website link I get redirected to a completely different website. Is this a virus? How di I get rid of it?

    It's not a virus - there are no known viruses for the iPad.
    First thing I'd suggest is shut down Safari - double-tap the home button to bring up multi-tasking, press on an app icon (doesn't have to be Safari) until they wiggle and red circles appear in top left corner, then press the red corner to shut the app.
    Next step is a hard restart - http://support.apple.com/kb/ht1430 . Often takes care of problems.

  • My iPods internal speaker isn't working, the sound works with headphones but now without. I've turned it on and off several times and pulled the headphone out and put them back in but nothing seems to work, please help?!

    My sound usually works but just yesterday it totally just stopped. The sound is turned on full, the headphones are out, and I've tried turning it off then back on but it didn't help at all. It's an iPod touch 2nd generation, 8G.

    Try the following to rule out a software probleM
    - Reset. Nothing will be lost.
    Reset iPod touch:  Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    - Restore from backup
    - Restore to factory defaults/new iPodIf you still have the problem you likely have a problem with the headphone jack in the iPod.  They can be replaced.  I would make an appointment at the Genius Bar of an Apple store to identify/determine the cause.

  • Google Redirect Virus Fix - How to Locate Internet Temp Folder?

    Hi - I am hoping to remove the google redirect virus and, following instruction from an eHow article, I need to delete both my computer and internet temp folders, and then establish new, empty folders for temps.
    I assume that "internet temp folder" means there is an actual folder for my firefox temp files? If so, is this found within the browser settings? Or, is it something that resides on the computer?
    Sorry for my ignorance ... this virus is sending me into entirely new levels of the learning curve...

    Perform the suggestion mentioned in the following articles:
    * [https://support.mozilla.com/en-US/kb/Template:clearCookiesCache Clear Cookies & Cache]
    * [[How to clear the cache#w_clear-the-cache|Clear the Network Cache]]
    * [[Searches are redirected to another site]]
    * [[Is my Firefox problem a result of malware]]
    Check and tell if its working.

  • Google Redirect Virus Removal

    So essentially, it seems that somehow my PC has picked up a version of the Google redirect virus. It is only affecting Firefox, and it seems to be a bit stealthier than previous versions. Essentially, 70% of the time I try and click on a search result (only the first one clicked per search), it will redirect me to a php script on a different server. It seems the script analyzes what I searched and attempts to redirect me to a phishing site that has related information about my search e.g. realgamerz.net and other shady URLs. I assumed it was a registry issue, but despite using all of the below virus/malware scanners nothing has been found. Is it possible one of my plugins has been compromised and that it has something to do with the Firefox software/Firefox plugins? Your advice is much appreciated.
    1) Kaspersky Anti-Virus 2011 Professional
    2) HijackThis
    3) SuperAntiSpyware
    4) Spybot S&D
    If there are other recommended malware scanners you think I should try I would be happy to do so.

    I also disabled printer helper and it totally worked! Thank you.

  • I have a Google redirect virus which redirects every hit I click on in every search engine, in every browser, to a completely unrelated website. No anti-virus software I've tried can get rid of it. Help.

    ''Locked due to age. If you still have a problem, please [https://support.mozilla.org/en-US/questions/new start a new thread]''
    Basically the Google redirect virus is caused by a trojan with rootkit capability, and so whenever I click on a link on Google, it redirects me to a completely unrelated site. I think I got it on there because of downloading pirated software (patches, cracks, keygens) to avoid paying: so stealing software didn't pay off :(
    I know you guys aren't specialised in internet security, but can you help?

    There seems to be more than one, possibly several malware objects that can cause Google search redirects in both Firefox and Explorer... some result in multiple infected files and are self- regenerating. I tried rootkit, gooredfix, tdskiller and every other tool I could download... several times I was certain it was gone but it always came back! If you want to kill this thing for good, combofix is the only thing that removes ALL of the infected elements. Combofix takes a long time to run (circa 30 min?) and requires some user input and also messes with your system settings a little but it is VERY thorough and it does work and best of all, it's free.

  • Google redirect virus

    I've been hit with the google redirect virus! Right now, it's just MySpace that's affected, but I've read in other PC forums that it can affect one's ability to surf all websites. I ran iAntivirus and it can't find anything. I'm not in the States, and my software purchasing is limited to what I can download off the internet (otherwise, I must buy Chinese language versions of everything, and my Chinese is nowhere near good enough to take that leap.) Any suggestions or others who have run into this? It seems to happen no matter what web browser I use.

    Hi
    Welcome to Apple Discussions
    This is not a virus issue, just poor or twisted site coding.
    Sometimes adding DNS server codes to the Network panel eliminates these types of problems.
    Usually, those types of messages are remedied by adding DNS server codes to your Network settings (Firefox has its own way of connecting to your IP).
    To add the codes, go to System Preferences>Network. Click on your internet connection - either Ethernet or Airport, then "advanced". In the DNS panel enter on separate lines the following OpenDNS codes: 208.67.222.222 and 208.67.220.220. Select "OK", then "apply".
    In the Network panel, if Ethernet or Airport (whichever you use) is not at the top of the list, click on the "gear icon" at the left bottom. Select "set service order". When the help box opens drag your connection type to the top of the list. Select "apply" when complete.
    Restart Safari.

  • I am not able to set up my ipad2 - tried the regular help but nothing seems to working. itune simply wont detect the ipad

    i am not able to set up my ipad2 - tried the regular apple help - did all those routines - but nothing seems to working. itune simply wont detect the ipad

    http://support.apple.com/kb/TS1538

  • How do I remove google redirect virus??? I can't get onto any sites that will offer help - as they're all "redirected!!"

    I've got a GOOGLE REDIRECT VIRUS, and am not able to enter any websites that will give removal information - as I'm being REDIRECTED! I need to know the name of the file to remove...and where/how!!! Any/ALL internet inquiries for assistance are....being redirected/hijacked. HELP.
    == This happened ==
    Every time Firefox opened
    == yesterday.

    This malware is actually in your add-ons. Go to Tools in your browser and click Add-ons and see if there are any add-ons that you didn't install. Mine was called '''XUL Cache''' that added itself. I uninstalled it and the problem was gone but the addon can have different names.

  • How to remove  Google Redirect Virus

    How to remove  Google Redirect Virus

    ABA123 wrote:
    Google Redirect Virus
    Your question presupposes a conclusion that will only mislead you and others into pursuing solutions that are likely to exacerbate whatever problem exists.
    Please describe the problem you are experiencing, and the equipment being affected by the problem. Your question was posted in the Power Mac Discussions area while your equipment profile indicates a Mac Pro, and a version of iOS inapplicable to either of them. All that information conflicts with itself, so please resolve those discrepancies.
    Thanks!

  • I live in thailand. my firefox homepage comes up with a google mark and is in thai language. how do i remove the google link and get english language?

    I live in thailand. I just downloaded firefox 3.6.12. I have uninstalled google chrome. My firefox homepage comes up with a google mark and is in thai language. How do i remove the google link and get english language?

    You can set the Interface Language via the Search settings link on the http://www.google.com/ncr site. That should work for the Google Firefox page as well.<br />
    That setting is stored in a Google PREF cookie that you need to keep (allow).

  • Removing the incredimail mystart virus ? or is it google chrome for me

    Can asolution be found for removing the incredimail mystart virus or do I have to move to google chrome

    A new tab opens by default as a blank tab (about:blank).
    If that isn't the case then an extension has changed that behavior.
    * https://support.mozilla.com/kb/Troubleshooting+extensions+and+themes
    Do or did you have the Google Toolbar installed?
    * http://www.google.com/support/toolbar/bin/answer.py?answer=115561 Web-browsing tools : Google new tab page and most visited websites

  • S35dvd: How to remove the HDD?

    Can anyone tell me how to remove a hard drive from a s35dvd please? I can not find a service manual anywhere and I need to remove the drive to try to remove a load of viruses that i can't remove with windows running or even in safe mode.
    Thanks

    Hi
    Unfortunately this Toshiba unit it unknown to me and I dont have found any officials documents about the HDD replacing.
    But as far as I know there should be only 2 possibilities how to remove the HDD.
    1.) The HDD slot is placed at the bottom of the unit and you need to remove only the HDD cover.
    Or
    2.) The HDD is placed in the notebook. In this case you have to remover the keyboard and some covers to replace the HDD
    Well, I can give you only this info. I think if you want to know the detailed instruction you should contact the Toshiba service partner because he has a more detailed informations about such cases.

  • How can delete the serve.bannersdontwork virus from Safari on Mac?

    Hello @all,
    How can delete the serve.bannersdontwork virus from Safari on Mac?
    About every 8-20 clicks Safari opens a webside named serve.bannersdontwork.
    I can not remove this with my Avira antivirus programm.
    Can anybody help me?
    THX
    Hallo an alle,
    Ich habe mir einen Virus eingefangen, serve.bannersdontwork, auf Safari.
    Alle 8-20 clicks öffnet sich diese Seite "serve.bannersdontwork" und leitet mich auf andere weiter.
    Über mein Antivirusprogramm Avira konnte ich den Virus nicht beheben.
    Auch die erweiterung AdBlock hilf hier nicht weiter.
    Wer weiß, oder hat eine Ahnung, wie man diesen Virus wieder los wird?
    Danke schonmal im voraus!!

    From the Safari menu bar, select
    Safari ▹ Preferences ▹ Extensions
    Turn all extensions OFF and test. If the problem is resolved, turn extensions back ON and then disable them one or a few at a time until you find the culprit.
    If you wish, you may be able to salvage the errant extension by uninstalling and reinstalling it. Its settings will revert to their defaults. If the extension still causes a problem, remove it permanently or refer to its developer for support.

  • Please tell me exactly how to remove the AVG search function

    Please tell me exactly how to remove the AVG search function
    ''edited by a moderator for clarity''

    You don't need to repeat yourself dozens of time or use profanity to get help here.
    (1) Disable ALL nonessential or unrecognized extensions on this tab. Not sure what it does? If in doubt, disable:
    orange Firefox button (or Tools menu) > Add-ons > Extensions category
    Use of the links above a disabled extension to restart Firefox if any appear.
    (2) Reset your search providers to Google:
    https://addons.mozilla.org/en-US/firefox/addon/searchreset/
    (3) Check for a user.js file (do this before exiting Firefox, otherwise the settings in that file can undo your cleanup) as described in this article: [[How to fix preferences that won't save]].
    (4) If AVG search took over your new tab page (Ctrl+t), change that as follows:
    (A) In a new tab, type or paste '''about:config''' in the address bar and press Enter. Click the button promising to be careful.
    (B) In the filter box, type or paste '''newtab''' and pause while the list is filtered
    (C) Double-click the '''browser.newtab.url''' preference and enter the desired value for your preferred page:
    ''(i) Page thumbnails (default)'' => about:newtab
    ''(ii) Blank tab'' => about:blank
    ''(iii) Built-in Firefox home page'' => about:home
    ''(iv) Any other page'' => full URL to the page
    IMPORTANT: If you have AVG software in your Windows Control Panel, you may also need to remove it there.

Maybe you are looking for

  • Error in compiling Flex application: 64K byte limit

    Hi experts , While deploying the VC model , i m getting this error : Error in compiling Flex application: Error: A function in the code exceeds the 64K byte limit (actual size = '65557'). Since the problem occurs in the compiler-generated deferred in

  • Indexes missing

    Hi team ,   We have found one index missing in db02. The index is in Abap Dictionary but not in Database. How to find the who perform the deletion of index from data base OR who perforn the creation of index in only Abap Dictionary. Regards   Vishnu

  • CS3 Design Premium - Acrobat error on installation

    Hi, I have the CS3 Design Premium Suite. Up until about 2 weeks ago, I wasn't having any issues with it. I primarily use Photoshop/Dreamweaver/Flash, but was happy to have Acrobat and the Reader for functionality. Well, I reinstalled the entire suite

  • Advanced Security Manager on HPUX

    Hi,I tried using ASM 1.5 downloaded from olapunderground and installed it on Win98 machine.I need to move my Security from 1 server to another. Both the essbase servers are on HP UX boxes.Both are different versions of Essbase Source is Essbase 6.2 a

  • Listener down in em console?

    Hi in my home page of em console i have one listener Down. But when i go to the remote host and write: lsnrctl status (the listener is UP). All other target in this same host (database instance, ASM), show the status in the console as UP. thanks any