Search
Virus Protection

PC Tools Spyware Doctor w/ Antivirus v6.0 FREE DOWNLOAD and VIRUS SCAN      Stopzilla Download - Get Rid of Spyware, Viruses, and Adware Today!

Google Redirect Virus: How to Remove – PC Magazine

Share this page

Social Sharing Sponsored by:

By: Neil J. Rubenking

PCMag's Editor-in-Chief Lance Ulanoff hit me with a strange question: "Every time I do a search and click a result link, I end up on some random page, even though the link shows I'd be going elsewhere." Luckily for Lance I've encountered this problem before. It's caused by a multi-faceted threat variously called TDSS, Alureon, or Tidserv.

The first time I ran into Tidserv it was inflicting exactly the same symptoms on my daughter's laptop. Unlike Lance's security-free test system, her laptop was protected by an up-to-date installation of Norton Internet Security 2010; it didn't help. She worked directly with Symantec technicians to identify and eliminate this then-new variant. Symantec's page on what they call Backdoor.Tidserv now includes a removal tool designed specifically to wipe out this threat.

Tidserv does indeed redirect search result links so you end up visiting web sites associated with the threat's authors, but that's just the most visible effect. According to Symantec it hides itself using advanced rootkit technology, displays advertisements, and opens a back door that further compromises the affected system's security.

Symantec reports that this Trojan is designed specifically to make money. It generates web traffic, collects sales leads for other dubious sites, and tries to fool the victim into paying for useless software. If those tricks don't work it can kick up the threat level by downloading additional malicious or misleading programs.

Pernicious threats like this one, threats that sometimes get past normal security, are precisely the target for Symantec's free Norton Power Eraser tool. I advised Lance to try the beta version of Norton Power Eraser 1.5, released today in conjunction with the Norton 360 Version 5 public beta. This update gives Norton Power Eraser the new ability to draw on Symantec's massive Norton Insight database to help identify threats.

Alas, Norton Power Eraser isn't yet powerful enough to remove this particular threat. Symantec supplied a brand new removal tool and reported that the removal techniques from this tool will eventually be merged into NPE. I predict eventual success, but jury is still out as the removal tool takes quite a while to finish its scan (eight hours on my clean test system).

If you click on a search link and it goes to the wrong place once, that might be a fluke. If it happens multiple times you've got a problem. Update your antivirus and run a full scan, seek a threat-specific removal tool online, or try a free tool like Norton Power Eraser. You don't want to leave a threat like Tidserv running loose on your computer.


This entry passed through the Full-Text RSS service — if this is your content and you're reading it on someone else's site, please read our FAQ page at fivefilters.org/content-only/faq.php
Five Filters featured article: Beyond Hiroshima - The Non-Reporting of Falluja's Cancer Catastrophe.

Comments are closed.

  • Zlob Downloader Trojan
    Do You need help with the zlob trojan virus? Here we have compiled a little info for you about the dangers and effects of the computer trojan, and also have resources for removal tools. […]
  • Smitfraud C Will Hijack Your Background on Your Computer! Read This to Stop It!
    Has the image on your desktop changed to something that you are completely unfamiliar with? The virus known as Smitfraud C could be the cause of something like this. We have the solution to your problems! […]
  • Need to Remove Zlob? Read This First
    Zlob is no joke, and it can be a huge hassle to remove. If you have downloaded on your computer you will want to remove it quickly and have some sort of protection to keep it off. Read on for some tips and resources that I recommend... […]
  • SmitFraud Removal Tool - Know What is Real and Fake!
    Do you have smitfraud and a program called SmitFraudFixTool has been bugging you to download and buy a program to remove the Smitfraud Downloader? You Need to read this article to find out why this program is fake! […]
  • Virtumonde Virus - How Do I Remove Virtumonde Once and For All?
    Virtumonde is a horrible and very aggressive computer virus that is prevalent online today. If you have this virus you need to remove it as soon as you can to stop serious PC problems. […]

Powered by Yahoo! Answers