Google Redirect Virus
Google Redirect Virus Description
The Many Origins of the Google Redirect Virus
Although Google Redirect Virus is often known by the ‘virus’ title, a more appropriate classification would be rootkit or Trojan. Google Redirect Virus is caused by various types of the infamous TDSS Rootkit, which is known by a variety of other names, including Alureon, Tidserv, Backdoor.Tidserv, Trojan:WinNT/Alureon.D, TrojanSpy:Win32/Chadem.A and many other variations.
As you might expect from the many possible aliases, Google Redirect Virus infections can contain many different kinds of secondary symptoms. However, the primary Google Redirect Virus attack is always the same. After you click on a link in a Google search result, Google Redirect Virus will redirect you to a completely unrelated website. These websites are designed to generate revenue for the criminals behind the Google Redirect Virus enterprise. Some websites may use the artificial traffic to boost affiliate payments, while others may attempt to trick you into purchasing fake security software such as Windows Necessary Firewall or Fast Windows Antivirus 2011.
Google Redirect Virus hijacks Google search results and redirects to several websites. Among them are coolsearchserver.com, webplains.net, Bodisparking.com, Zwankysearch.com, find-fast-answers.com, njksearc.net, qooqlle.com, Blendersearch.com, Thewebtimes.com, Marveloussearchsystem.com, search-netsite.com, toseeka.com, AboutBlank, La.vuwl.com, 10-directory.com, 63.209.69.107, 67.29.139.153, 7search.com, adorika.com, adf.ly, alive-finder.com, alltheservices.com, articlemule.org, asklots.com, ave99.com, b00kmarks.com, background-sleuth.net, bargainmatch.com, beoo.com, bestdiscountinsurance.com, bestsearchpage.com, bestclicksnow.com, bestmarkstore.com, bestwebchoices.com, bestwebsearch.com, bidsystem.com, secure.bidvertiser.com, blinkx.com, britewallet.com, budgetmatch.net, buzzclick.com, celebrity-gossip.net, cheapstuff.com, citysearch.com, clicksor.com (Clicksor), clkads.com, feed.clickbizz.com, comparedby.us, comparestores.net, couponmountain.com, digitaltrends.com, easilyfindlocal.com, everythinghere.com, evoplus.com, expandsearchanswers.com (expand search answers), fastfinder.com, feedsmixer.org (starFeedsMixer), find-quick-results.com, FilesCup.com (FilesCup), findexmark.com, find-answers-fast.com, finditreport.com, findology.com, finderquery.com, findstuff.com, flurrysearch.com, forless.com, gimmeanswers.org, glimpse.com, google-redirect.com, googlesearchserver.net, get-search-results.com, goingonearth.com, goodsearch.com, gomeo.co.uk, gossipcenter.com, gquestionnaire.com, greatsearchserver.com, greenluo.com, grooveswish.com, guide2faucets.com, happili.com, HelloLocal.com, hyperpromote.com, informationgetter.com, inruo.com, jerseyscatalog.com, juggle.com, k100searches.com, YouPorn, kitchenrenopages.com, kingtopsearch.net, kiseek.com, lawyerinsight.org, letsbuystuff.com, liutilities.com, livejasmin.com (creative.livejasmin.com popups), local-search-pages.com, localpages.com, localsearchbug.com, lowpriceshopper.com, manufacturersdirectory.com, merchantsnearby.com, monstermarketplace.com, mooter.com, multifind24.com, mybestclick.net, mycustomsearch.cn, mydealchoices.com, mydealmatch.com, mylocalhero.com, neatsales.com, neatsearchserver.com (neat search server ZeroAccess rootkit), netsearchfinder.com, netshoppers.com, nexplore.com, privacycheck.ru, Pulse360.com, qooqle.com, questyes.com, quick-search-results.com, quick-suggest.com, redirectsite.net, results5.google.com, safecompare.com, saveandcoupon.com, Storeordersonline.com, savecompare.com, savingwithads.com, scour.com, scoursearch.net, search-redirector.com, searchforall.info, searching4all.com, search-results.com (int.search-results.com), searchbacon.com, searchdiscovered.com, Search.babylon.com, searchqu.com, searchqualitysites.com, searchnext.com, searchspice.com, shopcompare.net, shopcompareus.com, shopfinded.com, shopica.com, shopica.com/search, shopzilla.com, socialsurvey2011.info, Social Search Redirect, somesearchsystem.com, startnow.com, startsearcher.com, supersearchserver.com, TabDiscover.com, tazinga.com (tazinga!), theifinder.com, TheTop10.com, tubedownloader.com, theyellowpages.com, theyellowpagez.com, topdaodrugs.com, tubedownloader.com, Therelatedsearch.com, unblock-us.com, us-srch-system.com, valueapproved.com, vshare.toolbarhome.com (vShare), vehiclefind24.com, Worldslife.com, weeklycontestwinner.org, weeklyusa-winner.com, webshoppinghelper.com, webresults6.org, Wickedsearchsystem.com, whatcarefreefeelslike.com, yellowmoxie.com, yellowise.com, ylwbook.addresses.com, youfindmore.com. Zinkwink.com
In all cases, you should minimize any contact that you have with the websites that Google Redirect Virus redirects you towards, since these websites can be a source of fraud and other infections that use browser exploits to install themselves.
The Rootkit and Trojan Attacks That Google Redirect Virus May Also Use Against Your Computer
Its primary function is bad enough, but Google Redirect Virus can also use other attacks against your PC, many of which are even more serious. Some of the major possibilities that have been linked to infection by Google Redirect Virus-spawning rootkits include:
- The appearance of unwanted and potentially dangerous advertisements. In addition to redirecting you to dangerous sites and slowing down your PC, these advertisements may use drive-by download scripts via Flash or Java to install harmful programs.
- The creation of a backdoor hole in your security. These holes can include a disabled firewall, exceptions added to your firewall or network ports being opened to allow traffic to pass through them uncontested. Backdoor attacks are strongly associated with remote attacks by criminals and endanger your computer’s security and privacy.
- Some variants of Google Redirect Virus will take their Trojan duties a little more seriously than other variants and may install other threats to your PC, including rogue security programs, keyloggers, ransomware and other harmful applications.
All versions of Google Redirect Virus use rootkit tactics to hide themselves, so that you will not detect any separate Google Redirect Virus files or memory processes. Since rootkits are extremely difficult to remove, you should only use the most reliable anti-virus software that you can access, to get rid of Google Redirect Virus. Anything less than the best may easily fail to remove Google Redirect Virus, even if Google Redirect Virus appears to have been removed in a scan.
Aliases
Trj/Genetic.gen [Panda]Generic29.AKVZ [AVG]W32/Kryptik.KO!tr [Fortinet]Win32.Malware [Ikarus]a variant of Win32/Kryptik.AKCO [ESET-NOD32]Trojan/Win32.Milicenso [AhnLab-V3]Trojan:Win32/Vundo [Microsoft]Win32.Troj.Undef.(kcloud) [Kingsoft]Trojan/Generic.aziif [Jiangmin]Gen:Variant.Symmi.1594 (B) [Emsisoft]
More aliases (48)
Google Redirect Virus Automatic Detection Tool (Recommended)
Is your PC infected with Google Redirect Virus? To safely & quickly detect Google Redirect Virus, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect Google Redirect Virus
What happens if Google Redirect Virus does not let you open SpyHunter or blocks the Internet?
Visual & GUI Characteristics
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read
the tutorials on how to find malware,
kill unwanted processes,
remove malicious DLLs and
delete other harmful files. Always be
sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name Detection Count 1 %LOCALAPPDATA%\AIM Toolbar\[RANDOM CHARACTERS].dll 703 2 %LOCALAPPDATA%\Macrovision\[RANDOM CHARACTERS].dll 703 3 %LOCALAPPDATA%\Inbox Toolbar\[RANDOM CHARACTERS].dll 696 4 %LOCALAPPDATA%\AlwaysNeat\Adobe\[RANDOM CHARACTERS].dll 696 5 %LOCALAPPDATA%\Intel\[RANDOM CHARACTERS].dll 689 6 %LOCALAPPDATA%\AIM\Adobe\[RANDOM CHARACTERS].dll 689 7 %LOCALAPPDATA%\Snapfish\[RANDOM CHARACTERS].dll 679 8 %LOCALAPPDATA%\Roxio\[RANDOM CHARACTERS].dll 679 9 %LOCALAPPDATA%\SSPrint\[RANDOM CHARACTERS].dll 672 10 %LOCALAPPDATA%\VirtualDJ\[RANDOM CHARACTERS].dll N/A 11 dmgsh.exe N/A 12 TDSSserv.sys N/A 13 Xwo.exe N/A 14 Xwk.exe N/A 15 Xzagua.exe N/A 16 C:\Windows\System32\wdmaud.sys N/A 17 C:\WINDOWS\Xzagua.exe N/A 18 C:\WINDOWS\_VOID\ N/A 19 C:\WINDOWS\_VOID\_VOIDd.sys N/A 20 C:\WINDOWS\system32\UAC.dll N/A 21 C:\WINDOWS\system32\uacinit.dll N/A 22 C:\WINDOWS\system32\UAC.db N/A 23 C:\WINDOWS\system32\UAC.dat N/A 24 C:\WINDOWS\system32\uactmp.db N/A 25 C:\WINDOWS\system32\_VOID.dll N/A 26 C:\WINDOWS\system32\_VOID.dat N/A 27 C:\WINDOWS\SYSTEM32\4DW4R3c.dll N/A 28 C:\WINDOWS\SYSTEM32\4DW4R3sv.dat N/A 29 C:\WINDOWS\SYSTEM32\4DW4R3.dll N/A 30 C:\WINDOWS\system32\drivers\_VOID.sys N/A 31 C:\WINDOWS\system32\drivers\UAC.sys N/A 32 C:\WINDOWS\SYSTEM32\DRIVERS\4DW4R3.sys N/A 33 C:\WINDOWS\SYSTEM32\DRIVERS\4DW4R3.sys N/A 34 C:\WINDOWS\Temp\_VOIDtmp N/A 35 C:\WINDOWS\Temp\UAC.tmp N/A 36 %Temp%\UAC.tmp N/A 37 %Temp%\_VOID.tmp N/A 38 C:\Documents and Settings\All Users\Application Data\_VOIDmainqt.dll N/A
More files
Registry Modifications
Tutorial: To edit and delete registry entries manually, read the tutorial on
how to remove malicious registry entries.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\4DW4R3HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sysHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys
Posted: May 18, 2009 | By SpywareRemove
Share:
Threat Level: 8/10
Rate this article:
Detection Count: 100,668


More

(13 votes, average: 3.77 out of 5)
This post is great. I realy like it!
This website won’t show up correctly on my i phone – you may want to try and fix that
Satyanarayana would you please elaborate a little in reference to your comment 12/30/12? I am having difficulty navigating to find the Internet protocol version (TCPIP) v4, and have the redirect virus really bad on my main computer. Please…any info would be so appeciated. Thanks Sheila
Are you serious? kid, you can not deetle the Windows Host file. No one listens to this retard. The only way to get rid of the redirect virus is by going on to your internet connection properties, click on Internet protocol version (TCPIP) v4, then click on properties . at the bottom of the box make sure you click on Obtain DNS server address automatically and make sure you uncheck use the following DNS address .Do not listen to idiots who will fuck up your machine or want to charge you
Why can’t google remove the redirect. Doesn’t it hurt them that because of this pest, people will avoid using google search!
I would love to have help getting rid of Babalon
lol smart!
It didnt work for me. I was just going on the minecraft page and the "redirect" thing stopped me. redirect always brigns me to a scuba diving gear thing. about five weeks ago there was this scan thing that told me i had 16 viruses. i could not go on the internet because of it. i could remove all the viruses but i didnt cuz it costed money.now i wish i did, but at that point i thought that the scan was fake and it was a viruse but i guess not.
This redirect virus has caused my business to suffer. Now thanks to the spyhunter, I could remove it from two of my office PCs. My workers and I thank you spywareremove for your efforts in fixing this issue.
I can not access to the Regedit in order to change tha paramether. Are there any other way to access to it. Thank you.
Thank you for some other excellent article. Where else may just anybody get that type of info in such a perfect approach of writing? I’ve a presentation subsequent week, and I’m on the search for such info.
The easiest way to remove Win 7 Anti-Virus 2011 malware is to buy a Mac!
nice blog
The google redirect virus is killing me… anyone know any good alternatives to remove this darn virus?
I savor, lead to I found exactly what I was having a look for. You’ve ended my four day long hunt! God Bless you man. Have a nice day. Bye
This is really fascinating, You’re an overly professional blogger. I’ve joined your feed and look forward to in search of more of your excellent post. Also, I have shared your site in my social networks
It is really a nice and helpful piece of information. I’m satisfied that you shared this helpful information with us. Please stay us informed like this. Thanks for sharing.
Thank you a bunch for sharing this with all folks you really know what you’re speaking about! Bookmarked. Kindly additionally discuss with my site =). We can have a hyperlink exchange agreement among us
most of my web surfing now redirects me to sites that i do not want. what do i do? i have tried running spybot but nothing helps. going to try your malware scan to see if that does the trick.
I have tried everthing.I have pc tools doctor and other online tools and nothing can touch this SOB. Google and Bing are the same. Please Help.
I can no longer use Google. I keep getting redirected to other sites, including porn. I have to block Google from my computer. Ugh…
does Google condone redirect ? Does Google make money allowing “redirect” ?