How to remove Google Redirect Virus

Thursday, May 21st, 2009 at 3:02 am
Home » Browser Hijacker » Google Redirect Virus

Google Redirect Virus description

google

Google Redirect Virus is a kind of system parasite that hijacks user’s google search results and redirects them into some rogue or malicious websites. Such websites usually promote malware or some other online scam and what’s worse, may even infect the system with more viruses. Google Redirect Virus is distributed with the help of trojans, such as Msqpdxserv.sys.

The best thing to do when having Google Redirect Virus on your system is to acquire a legitimate system security software so that to find and remove Google Redirect Virus from your computer. If you, however, want to remove Google Redirect Virus from your computer manually, you’ll need to remove malicious:

Please follow these links in order to learn how to remove each one of them. When all the removal procedures are finished, clear your browser cache and reboot the computer.

Google Redirect Virus is a Browser Hijacker

Tags: , , , , ,

43 Responses to

Google Redirect Virus

  1. jay

    ya umm.. wat about ppl who dont no enuf bout computers 2 no how to remove this shit..?

    Reply

    Luciana Reply:

    You can always install some anti-spyware and let it do the removal for you.

    Reply

    jezza Reply:

    ive installed 3 different ani spyware progs and none find it

    Reply

  2. Deena

    Which software do you recommend to download? My homepage is currently the same, but when I try click on a google web search it takes me to other site and when I type the website into the address bar it does the same.

    Reply

    Luciana Reply:

    You can download Spyware Doctor from this website. It doesn’t matter which software you choose; just make it’s anti-spyware and make sure it’s reputable.

    Reply

    Roderick Burkes Reply:

    That is complete bull. I installed a new hard drive because my old one had the google redirect virus and nothing was working to find and remove the virus. So I install the new hard drive thinking there is no way that this virus could have followed it onto a NEW hard drive. The first time I install windows and start it up, I go to google, and sure enough. There is that damn redirect virus. antispyware programs are not removing this virus. There has to be a PROVEN way to get rid of this infection.

    Reply

  3. BEan

    I have been trying to remove this softwre for ages. Any website which offers solutions seems to be blocked!

    Reply

    TheUnknownHacker Reply:

    I have the same thing and no matter how many times i delete it, it comes back. If you want to view any webpage that redirects you,
    then click the link,
    then click the address bar (so that the address of the webpage that you want to view is completely highlighted)
    and hit enter…
    Let me know if that works for you

    Reply

  4. carrie

    We used Spy doctor. things are working right now. It started out as a redirect virus then google and yahoo were blocked completly.

    Reply

  5. Jessica6

    I’ve got a computer that has that virus but it blocks Spyware Doctor for opening! I downloaded it with no problems but it will not run. I’ve tried to double click the icon, used the ‘run’ command, etc. When I click on ’start’ and find it there the program has been highlighted in pale orange though so this virus I’m sure is behind preventing it from opening.

    I ran Malware bytes & though it cleaned up a lot the virus is still there. Cleaned the registry too, manually removed host files, dlls & exe files that looked suspicious but I’m still missing something. There’s also a couple of files I just cannot delete.

    Reply

    Mircea Reply:

    try from Safe Mode.

    Reply

    lee Reply:

    Look in your registry for the extension registry settings. It’s likely something set itself up as the program to launch .exe with. That’s a nasty one, but if you find and remove that, not only will you be able to run things again, but you’ll also know what to delete.

    Reply

  6. Ariana

    I have a redirecting virus that affects all browsers (Firefox, Internet Explorer, Netscape) that none of the antiviral software I have tried will remove. I have already tried manual removal of the browsers except Netscape, removal of old versions of Java, using SuperAntivirus, Malwarebytes, Microsoft Security Essentials, and Panda Antivirus. None of them have been able to disable this malware. They do not even see it. I did a system restore to a date prior to the infection but the virus persisted.

    What now?

    Reply

  7. Dan Zee

    Yeah, same problem here. Superantispyware and Malwarebytes cleaned out the bad files, but there’s something in the registry that redirects Google searches. My only workaround is to use AltaVista to search. There seems to be a lot of useless articles like this that claim to tell you how to remove the redirect virus, but that tell you nothing.

    Reply

  8. Srinath

    Try deleting C:\Windows\system32\Wdmaud.sys……………

    Reply

    bryan Reply:

    Please note that wdmaud.sys located in C:\Windows\System32\drivers\ is is a Windows core system file, it’s a safe file.

    But wdmaud.sys in C:\Windows\system32\ is a trojan/Google redirect also known as Rootkit.Win32.Agent.fwt.

    Reply

  9. Don

    Has ANYONE found a ay to get rid of this redirect virus yet !!! I have been trying for several days now without any luck at all. I found an article on it that said to “Disable” it instead of deleting it. Said that if you deleted it, that it would reinstall itself when you rebooted. I am about to the point that I am ready to just wipe my hard drive and reinstall the O/S if I cannot find a fix for this problem.

    Reply

  10. Srinath

    Hi all, I have fond a solution that works fine. In WindowsXP, Check C:\Windows\System32\Drivers\atapi.sys. If it is 95KB 0r 93KB it is infected(It should be 94 KB). It is a genuine file,but gets infected because of Virus.So Expand the File from i386)folder.If the file is not replaced the computer may not boot or may end up in BSOD Error. Eg of Expand command (expand C:\i386\atapi.sy_ C:\Windows\System32\Drivers\atapi.sys). ENJOY !!!!!!!!!!!!!!!

    Reply

    char Reply:

    srinath, i have the same virus as everyone here. my ” C:\Windows\System32\Drivers\atapi.sys. If it is 95KB 0r 93KB it is infected(It should be 94 KB) ” my file say 94.2 KB…is it infected????

    Reply

    Terry Reply:

    Post by Srinath worked for me. Great help Srinath . Keep it up.

    Reply

    Stacey Reply:

    I am so not computer literate. how do I go about actually doing this please? I have no idea where to start.

    Reply

    Stacey Reply:

    I got rid of it. What worked for me with my XP was to go to start, then search, All files, etc, then type in etc, once you see the folder labelled etc then right click on it to remove read only under properties, then hit on it and I deleted all the host files that were crazy, there were a bunch like ad this and sex that etc then i went back and right clicked on etc to put read only again rebooted and it was gone.

    Reply

  11. Ellay

    I got the redirect virus and used Hitman Pro 3.5 (downloaded for cnet downloads) and it seems to have gotten rid of the virus without messing up anything else.

    Reply

  12. Eric

    How can i can i fix the problem when everytime i try to type hitman in the browser, it redirects me

    Reply

  13. annab

    Use another search engine.

    Reply

  14. Richard Bendert

    I appear to have the google redirect virus. I can’t download anything to fix it because it redirects it. I used a separate computer and used the download link to download sdsetup_aff.exe from this website then copied it to the infected computer. Unfortunately the first thing the software does is try to update and gets “Redirected” causing it to fail so I can’t use the software.

    Help!!!

    Reply

  15. Carl

    If you need to do searches till you solve the problem you can always copy and paste the search results address into the address bar and that shouldnt do a redirect. Also for Firefox there is a plug-in that’s supposed to solve that. I installed it and it helped but wasnt 100%.
    I think I finally eliminated the virus after trying all the free spyware programs . I had more items detected with Malware Bytes than any of the others. People say Combo Fix will knock it out but that its not a good tool for folks that arent experienced with it.
    I’d also recommend doing all the windows updates and update your browser. Good luck

    Reply

  16. Terry

    Post by Srinath worked for me . Great help Srinath . Thanks

    Reply

  17. nnikba

    Post by Srinath worked for me also . Great help Srinath . Thanks
    I tried many software and scan before without result!

    Reply

  18. moi

    So Expand the File from i386)folder.If the file is not replaced the computer may not boot or may end up in BSOD Error. Eg of Expand command (expand C:\i386\atapi.sy_ C:\Windows\System32\Drivers\atapi.sys). ENJOY !!!!!!!!!!!!!!!

    ^^^
    could someone please explain that a bit more clearly?

    sorry, but i’ve read it many times, opened the C:\WINDOWS\system32\drivers
    and attempted to figure out how to get rid of the google redirect virus, but
    i’m having trouble because every “help” suggestion is similar to the one above.

    many of us don’t understand what you said. i openly admit i didn’t.

    could you please explain that a bit better? please use the carriage return every now and then.

    thanks so much.

    Reply

  19. Terry

    Insert your Windows XP CD-ROM into the drive. Click Start, Run and type CMD.EXE. Use the Expand command.

    Example

    expand X:\i386\atapi.sy_ -r c:\windows\system32\drivers\

    Where X:\ is your CD-ROM drive letter. The above command assumes Windows is installed in C:\ drive. If not, change the drive letter / Path accordingly.

    Srinath , Am I correct ?

    Reply

    alam khan Reply:

    D:drive amd64 i386 virus file not delete pls melp me

    Reply

  20. Srinath

    Terry – The right command is

    expand X:\i386\atapi.sy_ -r c:\windows\system32\drivers\atapi.sys

    and all other info you gave are perfectly correct

    Reply

  21. Terry

    thanks and sorry for that! I see a file oko6.dll . Is this a virus file?

    Reply

  22. Rajendra

    Shrinath, tried u r solution.
    expand h:\i386\atapi.sy_ -r h:\windows\system32\drivers\atapi.sys this command is not working, some window flashes but file is not replaced. My win xp is on h: as i386 is also at same place. Pl help I am tired of every solution and badly need google services as unable to even login gmail etc.

    Reply

  23. Britteny

    I am experiencing the same problems with the virus. None of the anti-virus anti-malware things I have downloaded can find it. Srinath
    pointed out a solution but my computer is old. It came with Windows XP I do not have a OS disk for it. So how do I expand the file? Is there another solution available?

    Please help.. and explain in simple terms. I’m not the most computer literate person out there.

    Reply

  24. Amy

    I am having the same problem. I can not get onto any website at all except Google. I get Internet Explorer cannot display the webpage error. I can do searches but if I click on the link or type in an address in the address bar I get that error.
    I do not have a CD rom because my computer is used and I did not get one.
    Is there anything else I can do?
    Thanks!

    Reply

  25. George

    It is connected to Java. Just go to Control Panel, click on the Java icon, delete temporary files located there, restart your computer, and voila, it’s gone.

    Reply

  26. Samiej72

    Reboot your computer in safe mode and delete the following file in the following folder. Fixed my redirect problem like a champ!!

    File: api-ms-win-core-memory-l1-1-032.dll
    Folder: C:\Windows\SysWOW64

    Reply

  27. Rick

    To replace the atapi.sys file. You have to expand from an original location to a save location on the hard drive such as a TEMP folder. You then have to reboot with an original disk or bartpc or something to get you at a dos like screen after reboot. Then manually copy the file to two folders where it exists.. Being in a Dos like mode allows you to over write the infected files.

    good luck

    Reply

  28. Bobalou

    Hey all! I had success with George’s remedy! go to Start, Control Panel, click on Java, go down to Temp Internet Files, click settings, then click on Delete files tab at bottom, (both checkmarks) then hit ok! finally tried the windows\syst32\drivers\etc\hosts (edit file)..thanks George!

    Reply

  29. tbaaah

    George’s remedy worked for me as well, at least for now. I’ll have to give it a while to see if it creeps back in.

    Reply

  30. awesome mini goldendoodle breeder info

    Asking questions are actually good thing if you
    are not understanding something entirely, except this article provides nice understanding
    yet.

    Reply

Leave a Reply

Download does not start? Try a mirror download here