Solved

Possible virus with google javascript

Posted on 2013-06-19
8
746 Views
Last Modified: 2013-11-22
In all of my browsers, IE10, Firefox21, Chrome, when I click to go to a new page (e.g. an Experts Exchange search), I often get sent to a different page (e.g. the Meatworks).

I can fix this in Firefox by disabling every advertising script with google in the name. I can't use IE or Chrome because they do not allow users to disable Ads.

However, I am perplexed that no-one else seems to have this problem, so I suspect I have a virus or some other kind of malicious software.

I have Microsoft Security Essentials which seems to keep me safe, apart from this problem.

Any suggestions.
0
Comment
Question by:GrahamDLovell
  • 4
  • 3
8 Comments
 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 250 total points
ID: 39261575
Run a full scan.  You have something called a 'Google Redirect Virus'.  If MSE doesn't find and remove it, we can suggest other things that will.
0
 
LVL 78

Accepted Solution

by:
David Johnson, CD, MVP earned 250 total points
ID: 39261640
try malwarebytes (http://www.malwarebytes.org) and scan your computer.
0
 

Author Comment

by:GrahamDLovell
ID: 39264611
Here is progress so far:

MSE didn't find anything. Malwarebytes' rapid scan also didn't find anything that MSE hadn't disabled, but a full scan found one item in an old recovery section of the disk, and I have removed it. Here is the log entry:

..\Program Files\Microsoft.NET\SDK\v1.1\QuickStart\howto\samples\xml\xmlnamespace\cp\XmlNameSpace.exe (Adware.StatBlaster) -> Quarantined and deleted successfully.

I don't get the redirects now, although I still get the annoying ads, except in Firefox, where AdBlock Plus seems to be effective.
0
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 39264645
You should examine all your addons.  I suggest you remove anything you are not using.  And almost all 'toolbars' are spyware and some are used to deliver ads and popups to you.  I don't allow ANY toolbars on my computers, not Google or Bing or Yahoo or any others.
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 

Author Comment

by:GrahamDLovell
ID: 39264658
I agree. Everyone seems to want to add a toolbar to my browsers.
0
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 39264673
When you go to a new page, every toolbar you have 'phones home' to tell it's master where you are so they can add to your 'advertising portfolio'.  Toolbars are better than tracking cookies for the advertisers.
0
 

Author Comment

by:GrahamDLovell
ID: 39378747
The problem with the "Google redirect" virus has re-emerged, and the program I thought that I had removed is still there. It is XmlNameSpace.exe. Now removed again, and the problem dropped back a step: it doesn't redirect.

However, IE still came up with bogus adverts.

I then tried removing all of the IE Add-Ins for which I didn't recognize the company name (using the menu option in Tools). I also disabled PlusIEEventHelper Class (purporting to be from Zeon Corporation).

This seems to help. I am not sure why. Any comments anyone
0
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 39378758
Then I suggest using ComboFix from Bleepingcomputer http://www.bleepingcomputer.com/download/combofix/ (Not from anywhere else!).  Run it then run MalwareBytes again.  This will take a while but I have found it to be the most effective combination of scans.  Of course, you have to be careful where you are going on the internet and what you are clicking on to avoid getting it again.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
This Micro Tutorial will demonstrate how to add subdomains to your content reports. This can be very importing in having a site with multiple subdomains.
How to create a custom search shortcut to site-search Experts Exchange using Google in the Firefox browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch your Bookmark Menu: Press 'Ctrl +…

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now