If you are still being redirected to radom sites. Do the following:
go to trendmicro go to feetools and download the Rootkit buster, removed the rootkits. http://free.antivirus.com/
After the reboot, use Malwarebytes to remove the other infected files. www.malwarebytes.org/mbam.
Also, you can check the host file, which is found in C:\windows\system32\driver
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
Main Topics
Browse All Topics





by: JeremySBrownPosted on 2009-09-17 at 20:16:46ID: 25362732
Run a temporary file remover...CCleaner is a good one and it's free.
r.com/comb ofix/how-t o-use-comb ofix
g/mbam.php
http://www.ccleaner.com/
Download Combofix by sUBs.
http://www.bleepingcompute
Before running Combofix, temporary disable any firewall(s) shield(s) ect...to prevent any conflicts with Combofix. After Combofix is done scanning, it will create a log, for futher instructions, save and paste the results by Attach File, or by Code Snippet so other experts and myself can take a look at it. Once after the log looks clean, you may enable your firewall(s) shield(s) ect. Combofix will disconnect your machine from the Internet. Your Internet connection will be automatically restored just before Combofix completes its scan. If Combofix runs into problems, your Internet connection can be manually restored by restarting your machine.
You'll might need to rename the file before saving to your desktop so it will not be blocked.
Please note: Don't run Combofix in Safe Mode.
Try scanning with Malwarebytes' Anti-Malware.
http://www.malwarebytes.or