≡ Menu

Google Redirect Virus – Remove Manually (recent update)

google redirect virus

I am Anup Raman, a Tech enthusiast, Blogger and Technical trainer with 10+ yrs of experience in IT related services. My experience includes 5+ yrs working for Microsoft and the remaining with Symantec and McAfee. My expertise includes fixing and finding solutions to operating system issues and removing virus manually from computer. Also authored Virus Removal Secrets Revealed, a guide on removing computer infections manually without using any security software. The troubleshooting steps mentioned here are tried and tested, same exact steps followed by professional technicians for removing google redirect virus manually. Hope you find this guide helpful in getting rid of this dangerous infection. Feel free to share this article, you might be able to help someone in need.

Google redirect virus is one of the most annoying, dangerous and toughest infection ever released on internet. Google redirect virus is responsible for redirecting google search results or normal website links to a malicious webpage. This redirected webpage is mostly related to some advertisement page or a hacker created page which is designed to gain viewers trust and extract information from them.

Google redirect virus is also called Yahoo Redirect Virus or Bing Redirect Virus, cos this not only redirects google search result, but also yahoo and bing search engine results. Recently a modification of this infection has  popped up as Nginx Redirect Virus and Happili Redirect Virus. In reality, all these infections are same but with some changes in the way it attacks a program.

Not much computer users know that Google redirect virus is not a virus, but a rootkit. Rootkit infections unlike virus, spyware or trojan infections are very difficult to remove. Rootkits are designed in such a way that, once it gets inside the computer it gets attached itself to the core operating system file. They are also designed brilliantly to avoid detection by removing their footprints. To make issues worse, google redirect rootkit is seen associated with Trojans which makes it more deadly. According to a 2011 report, Google redirect virus have already infected 45,00,000 computers wide, out of which 1/3rd is from US.

Why is Google Redirect Virus hard to remove?

Google redirect virus is tough to remove because of its ability to hide deep inside the operating system and also its ability to remove traces and footprints on how it got inside the computer. Once it gets inside, it attaches itself with core Operating System files making it looks like a legitimate file running inside the computer. Even if the infected file is detected, at times it is hard to remove cos of its association with operating system file. As of today, not a single security software in the market can guarantee you 100% protection from this infection. This explains, why your computer got infected in the first place even with a security software installed.

The article here explains on how to handpick and remove google redirect virus. From a computer technicians point of view, this is the most effective method ever developed to remove google redirect virus manually. Technicians working for some of the biggest security software brands follow the same method when they have to resort to removing google redirect virus manually. Every attempt is made to make the tutorial simple and easy to follow.

The methods mentioned here are the most effective and the original steps followed by tech support professionals all over the world to manually get rid of google redirect virus. But some of you might find the methods mentioned here complicated and too technical to follow or maybe taking too much of your time. If you don’t want to get your hands dirty and would like professional help, try Fix Redirect Virus, a dedicated group of professionals dedicated to finding fix for browser redirection and related infections. This is currently rated as the No.1 service available in the market for removing google redirect virus. Rather than paying couple hundreds for a tech shop repair, I find this service cheaper and more effective. Also you get the issue fixed in lesser time.

Please Note: I don’t own this service or is involved in developing any tools. The entire credit goes to the organization. My recommendation is only based on honest user reviews and personal feedback through comments and mail, some of which are listed under the comments section.

Highlights of their service:

  • Collection of tools which are constantly updated for handling the latest variants of this infection. Free access to their future updates. Guidance on how to use the tools also provided.
  • Quick resolution. Saves you time and countless unproductive hours.
  • Presence of multiple tools inside the package to ensure that if one tool fails, you still have other tools to try out to get rid of google redirect virus.
  • Dedicated team providing 24/7 support.
  • Service provided at an affordable price. Professional services such as tech shop repairs and virus removal services charge more than 100$ for getting rid of this infection.
  • Guaranteed Virus Removal or Get Refund.

 

 Two of the most popular methods to remove Google Redirect Virus

  • Try tools available online or go for a professional tool

There are plenty of security tools available in the market for different purposes. But none of these tools are developed specifically for removing google redirect virus. While some had success in removing the infections using one software, the same may not work for another computer. A few end up trying all different tools which create more problems by corrupting OS and device driver files . Most of the free tools are hard to trust as they have a reputation for corrupting operating system files and crashing it. So take a back up of important data before trying any free tools to be on the safer side.

You can also get help from professionals who specialize in removing this infection. I am not talking about taking your computer to a tech shop or calling geek squad which costs you lot of money. I did mention a service before which you can try it as a last resort.

  • Try to remove google redirect virus manually

There is no easier way to remove an infection other than running a scan using a tool and fixing it. But what if you already done that and failed to fix the problem. The last resort is to try removing the infection manually. This is my most favored method, but may not be the same for everyone. This is time consuming and some of you might find it hard to follow instructions cos of its technical nature.  This method is very effective, but failure to follow instructions properly or possibility of human error in identifying the infected file can render your efforts ineffective. To make it easier for everyone to follow, I created a step by step video explaining details. It shows same exact steps used by virus removal experts to remove virus infection manually. You can find the video towards end of this post.

Troubleshooting steps for removing Google Redirect Virus manually

Unlike most of the infections, in case of Google Redirect Virus you will find only one or two files which is related to the infection. But if the infection is ignored initially, the number of infected files seems to increase over a period of time. So better get rid of the infection as soon as you find redirect problems. Follow the troubleshooting methods mentioned below to get rid of google redirect virus. There is also a video below.

1) Enable hidden files by opening folder options (start –>run –> control folders),under view tab

  • enable show hidden files, folders and drives
  • uncheck hide extensions for known file types
  • uncheck hide protected operating system files

2) Open msconfig (start –>run –> msconfig)

  • Click “Start” –>  run –> msconfig)
  • Go to “boot” tab if you are using Vista or Win 7. In case of XP, select “boot.ini” tab
  • check bootlog

3) Restart computer

Restart computer for making sure that changes you made are implemented. (On restarting computer a file ntbttxt.log is created which is discussed later in troubleshooting steps)

4) Do a complete IE optimization

Read this article on how to do an Internet Explorer optimization. Internet explorer optimization is done to ensure that redirection is not as a result of problem with IE or corrupted internet settings. Even if you use a different browser other than Internet explorer, IE optimization is compulsory as IE settings acts as the basic settings for any web browser using windows operating system.

5) Open device manager (start –>run –> devmgmt.msc)

  • Click “Start” –>  run –> devmgmt.msc
  • Click “view” tab on top. Select “show hidden devices”
  • Look for “non-plug and play drivers”. Expand it to see entire list under option.
  • Check if you have any entry TDSSserv.sys. Note down name carefully. Right click on entry and uninstall it. Don’t restart computer yet, cancel it. Continue troubleshooting without restarting.

6) Open registry (start –>run–>regedit). Take a backup of registry before making changes

  • Click on edit –> find. Enter first few letters of infection name. In this case, I used TDSS and searched for any entries starting with those letters. Every time there is an entry starting with TDSS, it shows the entry on the left and value on right side.
  • If there is just an entry, but no file location mentioned, then delete it directly. Continue searching for next entry with TDSS
  • The next search took me to an entry which got details of file location on right which says C:\Windows\System32\TDSSmain.dll.You need to utilize this information. Open folder C:\Windows\System32, find and delete TDSSmain.dll mentioned here.
  • Assume that you were not able to find file TDSSmain.dll inside C:\Windows\System32.This shows entry is super hidden. You need to remove file using command prompt. Just use command to remove it. del C:\Windows\System32\TDSSmain.dll
  • Repeat same until all entries in registry starting with TDSS is removed. Make sure if those entries are pointing towards any file inside folder remove it either directly or by using command prompt.

Assume that you were not able to find TDSSserv.sys inside hidden devices under device manager, then go to Step 7.

7) Check ntbtlog.txt for corrupted file

google redirect virus6 Google Redirect Virus   Remove Manually (recent update)

By doing Step 2, a log file called ntbtlog.txt is generated inside C:\Windows. It’s a small text file containing lot of entries which might run to more than 100 pages if you take a printout. You need to scroll down slowly and check if you have any entry TDSSserv.sys which shows that there is an infection. Follow steps mentioned in Step 6.

 In above mentioned case, I mentioned only about TDSSserv.sys, but there are other types of rootkits which do same damage. Let’s take case of 2 entries H8SRTnfvywoxwtx.sys and _VOIDaabmetnqbf.sys listed under device manager in my friends PC. The logic behind understanding if it is a dangerous file or not is mainly by their name. These name makes no sense and I don’t think any self respecting company will give a name like this to their files. Here, I used first few letters H8SRT and _VOID and did steps mentioned in Step 6 to remove infected file. (Please Note: H8SRTnfvywoxwtx.sys and _VOIDaabmetnqbf.sys are just an example. The corrupted files can come in any name, but it will be easy to recognize because of the long file name and presence of random numbers and alphabets in the name.)

Please try these steps at your own risk. steps mentioned above won’t crash your computer. But to be on the safer side, it is better to take a backup of important files and ensure that you have option to repair or re-install operating system using OS disk.

Some users might find troubleshooting mentioned here complicated. Let’s face it, infection itself is complicated and even the experts struggle in order to get rid of this infection.

Watch Manual Removal Steps for Removing Google Redirect Virus

You now have clear instructions including step by step video on how to get rid of google redirect virus. Also you know what to do if this didn’t work out. Take action immediately before the infection spreads to more files and render the PC unusable. Share this tutorial. It makes a huge difference to someone facing the same problem. Good Luck.

Fix Redirect Virus

About the author: I am Anup Raman. A Tech Enthusiast|Blogger|Tech Trainer with 10+ yrs experience in the field of IT. My expertise are in Operating Systems, mainly Windows and Computer security which comes from my experience, working as Tech Support and Trainer for Microsoft, Symantec and McAfee. Loves blogging about Technical Troubleshooting, discussing latest Gadgets, Games and doing Reviews.

266 comments… add one

Leave a Comment

  • lala

    I’m using google chrome browser. Everytime I search for something and click the link at a new tab, it shows “Redirect Notice”. I’m not redirected to any ad sites. It’s just frustrating that I can’t use open link in new tab without having this redirect notice.

    • It don’t seems to be a browser redirect issue. Go to Chrome Settings -> Advanced settings -> In the end, there is an option “reset settings”. Resetting chrome browser to original settings should fix the problem.

  • Rolando

    I receive a daily email from Fancy.com with new products they offer. The products picture arent shown and instead of the photo there is a ? sign. When I click the sign send me to an another page that start with redir.fancy.com Is this the virus?
    Thanks

    • Fancy.com seems to me as a legitimate website. redir.fancy.com link seems to be a redirected link from the website. This is not an issue with Google redirect. Seems to be an issue with fancy.com not able to provide a proper link to check their products.

  • Janet

    After downloading a free app called LostApp to find my son’s cellphone, my google search keeps going to yahoo. Do you need to see my ntbt list to know what I need to do?
    Thanks,
    Janet

    • This is not a redirect virus. The App must have changed some settings in browser. Go to the browser settings and change default search from Yahoo to Google.

  • Dennis

    Hi,

    I got a brand new PC and noticed that my Google is being “redirected” to custom search pages (using Google API). The support forum of Google is very unresponsive about the issue.

    Anyway, i’m not sure if i’m dealing with the “redirect virus” here.
    Here’s a video of the issue i’m having:

    http://www.youtube.com/watch?v=tTIa35GLXnc

    • I can assure this is not a redirect issue. This is something to do with Google search settings. I will post when I find a solution.

  • Emily

    Hi,
    My pc have been infected by Right surf, and i cant get it out. I followed your steps, but on the cmd black screen, i cant find the infected file.
    this is what i have on ntbtlog.txt: Loaded driver \SystemRoot\system32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys

    how can i proceed?
    everytime i try a google search, i cant do it, because i get a massage saying i have no proxy.
    When i try searching on yahoo it works perfecty.

  • Emily

    Brilliant! Thank you!

  • Tania

    Hi Anup,

    Thanks for the wonderful instructions. I am experiencing a problem in deleting the suspicious file in the cmd mode.
    I am getting the below error. (Just copy pasted it for you to see please)

    C:\Users\TANIA>del c:\Windows\System32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3
    a4f6}w64.sys
    c:\Windows\System32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys
    Access is denied.

    C:\Users\TANIA>attrib-r-h-a-s c:\Windows\System32\drivers\{b2db3058-74ee-4ace-bc
    d8-8cd0fbe3a4f6}w64.sys
    ‘attrib-r-h-a-s’ is not recognized as an internal or external command,
    operable program or batch file.

    I donot have Norton but a running version of McAffee. It keeps detecting viruses and is active.
    Should I delete it?
    Help needed from the expert.
    Thanks

    • attrib -r -h -a -s filename with location.
      There is a space after attrib and also space for every properties
      Norton or McAfee may interfere with troubleshooting, so it is better to remove them or at least disable at the time of troubleshooting.

  • Tracy M. Faller

    Hey there I am so grateful I found your blog, I really found you by mistake, while I was looking on Yahoo for something else, Anyways I am here now and would just
    like to say thanks a lot for a incredible post and a all round thrilling blog (I also love the theme/design), I don’t have time to browse it all at the moment but
    I have book-marked it and also added your RSS feeds, so when I have time I will be
    back to read a great deal more, Please do keep up the
    awesome job.

  • Nic Baird

    I’m just testing to see if these comments are real!

  • Evin

    Brilliant ! Thanks :)

  • Elias

    Fixed by following steps mentioned here. I am an IT student. This changed my perception of finding and fixing virus problems.

  • Lanse

    Thanks Anup for your guidance. Your professional service helped me in getting rid of Google redirect virus in no time.

  • Jenna

    Thanks a lot. Worked perfectly for me/.

  • Derek

    Just fixed my Google Redirect. I was looking at this article, performed step 2 (msconfig), and noticed a really strange call in the “startup” tab of msconfig. It was to a “msgsm323.dll” in my “c:\users\\AppData\Roaming” directory. Something had installed it there and then added it to my startup. I disabled it from the startup and the problem is gone. I have looked at the startup folder many times in an attempt to solve this problem, and there was nothing there. Until I viewed it through msconfig today, it was hidden from me.

  • Dennise

    Hi Anup,

    You are brilliant. You win when all other sites failed. Thank you!!

  • Georgia

    Hello Anup,

    I am also from IT and truly appreciate the tutorial and video. Very good detailed instructions with alternative solutions. I had a very productive morning getting rid of this nasty virus, thanks to you! Well done.

  • Louis

    The steps dint work, but the guys you suggested got it fixed in 15 minutes max. Anyway, good work here.

  • Janine

    Thanks Anup for the help. I went for your professional service straight away and got it fixed.

  • David

    hey, Anup, I just watched your YouTube vid and got excited when I found 2 suspicious looking files in my boot log. I went to the drivers folder but they aren’t there!

    Loaded driver \SystemRoot\system32\drivers\N360x64502020.003\SYMDS64.SYS
    Loaded driver \SystemRoot\system32\drivers\N360x64502020.003\SYMEFA64.SYS

    I also did a search for them in the ‘regedit’ as well but they’re not there either…any ideas????

    • This is not an infected file. This is related to N360 software in your computer.

  • rob

    Hi buddy thanks for the advise all worked perfectly stuffed around with heaps of others which did absolutely nothing. You were correct about the host file not being able to save so all i did was copied it to me desk top in a new folder (host1) made the relevant chages by deleleting the virus local host and saving it on the desk top. I then removed the original by deleting it and then simply copied and pasted the newly saved one back into the normal etc folder all worked perfect. Also as a sideline issue all windows updates have since been installed as the virus was preventing these to load.
    cheers Mate god luck

  • Kirsk

    Thanks Anup.Your instructions were spot on and finally I got rid of this nasty google redirect virus.You are great.

  • Raith

    I took your pro help.Got it fixed in no time.Well worth the money spent compared to the hell I went through with this virus.Thanks for your guidance and wonderful tutorial

  • Blade

    you are right…google redirect virus is the most annoying.I had infections before,but none as hopeless as this.Anyways I got it removed.Thanks

  • Lucy Parker

    I followed your instructions for sometime, but got bored quickly.Too much for me to digest.The service that you mentioned here did all the work for me and got it fixed in little time.Thanks Anup

  • Nadiya

    Not my cup of tea. But your pro service got it fixed up quickly. Thanks for the guidance :-)

  • Stephen

    This google redirect virus is a tough sucker.Thanks to your instructions.Got everything figured out and seems everything is working fine.

  • Travern

    The best $30 ever spent.I knew your method is tough,so took the easy route and I am glad I did it.Anyway,I just want to appreciate the effort you took to educate and guide evryone who are infected with this virus.God Bless Anup.

  • Jagees

    Just had the worst time with my computer ever.It kept redirecting my sites for a month now,but it took sometime for me to realise it is infected with google redirect virus.Thanks to your instructions everything is working fine now.Wish everyone here good luck for getting rid of this infection.

  • Richard Gonzalo

    So far I have used Norton Internet security full scan to try and remove the virus automatically but no luck. If you have any suggestions for programs that can remove it automatically, please le me know.

  • Janine Sheikh

    Suggestions please for removing from a Mac Laptop??

    • Unfortunately, I am not good with troubleshooting google redirect virus on Mac machine. I never got an opportunity to work on this infection on a Mac,even though we had some reported case of google redirect in Mac.

      Hopefully, someone who reads this might be able to give you some valuable suggestion.You may also try the professional service mentioned here.

  • Johnnie

    Hi Anup,
    I appreciate the time and effort you took to put down clear instructions to help many people like me suffering from google redirect virus.My computer knowledge is limited to browsing internet and sedning some docs here and there.But frankly,all the instructions were like F and B’s to me.Anyway thanks for putting the information for a guy like me.Your recommended guys got my issues fixed in less than 30mts.It seems everything is back to normal now.Thank you and God Bless you.

    • Unfortunate that the instructions were tough on you.The infection itself is that complicated to try traditional troubleshooting. Anyways glad you finally got it fixed :-)

  • Mande

    Everything worked fine.Thanks to you :-) God Bless

  • Gerald

    Thanks to your tutorial.It was worth the effort it took to get rid of it.Hope more people will find your instructions to get rid of google redirect virus.

  • Kalki

    Hi Anup, Thanks for the instructions and detailed video. I was able to get rid of the infection following your steps. But somehow it came back after almost 2 weeks. Maybe I did something wrong there. Finally I tried the pro service that you recommended. It’s been a month now, the redirection has not returned and everything seems to be working fine. Thought I should give you a feedback for your efforts.

    • Thanks Kalki for the feedback. Glad to know everything seems to be working ok. I wish everybody take time to leave feedback like you.It always help others and me as well with the latest updates.

  • Adil Rehman

    Hi Anup,

    I just wanted to thank you for helping so many people.

    For those who wonder why they do not have a corrupted file.

    This was/could be just a temporary GRV that was saved in the cache or/and Session files.
    After I deleted my history (I am using firefox) and restarted my PC everything functioned normally again.

    Like I said, still thank you Anup and I hope I could help those who were wondering because of the missing corrupted files.

    • Atleast a small percentage of issues that makes the website redirect is not caused by the actual redirect virus. It can be because of an issue with temporary files, corrupted host file and issues with browser. That is why I insist to do the troubleshooting in the order that I mentioned here. Sometimes you don’t have to go through the entire troubleshooting to get it fixed.

      Glad the issue is fixed :-) You were lucky that the issue was comparatively minor in your case. Thanks very much for the feedback.

  • Sharkel

    Thanks Anup for the help.YOU ARE THE MAN

  • Keane

    Thanks to your step by step tutorial the issues are no more showing in my computer. I will keep it under observation for any signs of infection this weekend. If yes, I am gonna throw out my machine.

  • PENNY

    You are my guardian angel :-) THANKS ANUP. YOU WON WHEN EVERY OTHER METHODS FAILED ME

  • Nora

    All my issues are fixed following your instructions.Thanks

  • sajan

    thanks for the wonderful service.to be frank,i was bit hesitant initially,but it fixed all problems.everything is working fine now.i am glad i used your service.

  • Shawna

    Hi Anup,
    Very informative but I am not able to locate a suspicious file in ntbtlog.txt in the loaded drivers list.Maybe I’ll check with you later.

  • Clement

    Anup, these were the best instructions I ever went through to remove the infection.The problem file was located in c: windows\system32\export8.dll.Everything is working fine now.Thanks to you.

  • James

    Hi Anup
    I have had a little problem. I am unable to enable bootlog from the “Boot” tab. In fact, it does not allow me to chang anything at all in this tab.
    In the general tab, currently “normal startup” is sellected. I selected “selective stratup” to see if it will allow me to select the “Boot Log” option. However, although it looked like it allowed me chose “selective start uo” but when I restarted to computer nothing has been saved and it was still in “normal setup”.
    I tried to F8 at the start and chose “enable bootlog” manually but again it did not give me an error but it did not created the bootlog file.
    What I am doing wrong?
    Thanks

    • This issue seems to be complicated. I believe it might be because of a corrupted security software in your computer which is preventing from making any changes. You may try the troubleshooting after removing whichever security software you have on the computer. The security software may look like it is working perfectly, but chances of it corrupted is high. Once the issue is fixed, you may install it back.

  • Brenda Williams

    Thanks Anup for the wonderful service.I have been struggling with this since the new year.Not sure, if I can handle your instructions here.But confident that your guys would help me out.My computer is working fine and no more redirects.As somebody already said here,the best money I spent on internet.

    Brenda, Ohio

  • Anup, thank so much for your video instructions they were great. i’m pretty savvy when it comes to following direction and fixing computers. But it seems the infection was deep rooted. I used your professional service and it was well worth spending that money.Now my computer is not at all redirecting and everything works fine than before.Thanks again for the help.

  • fynorrahs

    I’m attempting to fix a computer running Windows XP that has this virus however when I begin step 1 and ran into issues. The “hidden files, folders and drives” does not include “drives” When I follow all three steps I get a window that warns that the system will become inoperable if I continue. Should I proceed anyway? I’m concerned that I will not be able to complete the steps if I proceed.

    • That is okay. Ignore the message and proceed. It is just a warning.Watch the video and you will understand what I meant.

  • Dee

    I am following your excellent instructions on ridding my computer of a redirected virus or viri. I have a problem I cannot solve. I run Windows 7, and am listed as the Administrator. When I attempt to SAVE the changes made to the NOTEPAD, wherein I deleted all the many redirections, I get an message saying I do not have the authority to save these changes, even though I am shown as the Administrator. Can you help with this?

  • Anjela

    Anup, thanks for the wonderful article and effort you put in to help us fix the issue.this is the first time ever getting infected with a virus and from your article, I found it has a name google redirect virus. It’s scary and bit funny when you think about how much trouble some brainy morons can do to us. I decided to go for your professional service for the reason that the steps mentioned here is too technical for me.I appreciate the video tutorial which made it look simple, but that also is too much for me.Your guys were quick in fixing the virus in less than 15mts.It was well worth the money spent and thanks again for doing such a wonderful job.

  • John

    Cool Bro.Thanks for the details.Your service is great.

  • Ness

    Did everything as you said and bingo…everything is good and set to go.Thanks for making my life easy.

  • Sentrilo

    Thanks Anup for the wonderful service.All issues are fixed and back to normal.God Bless

  • Connie

    This is the only article I find relevant on the topic after hours of searching fix for google redirect virus. Your service is amazing and got all my issues fixed within 15mts. God Bless you and America. Wish you a great new year ahead

  • Tammy

    Hi Anup,
    Please help. I found these files in ntbtlog.txt and I think these files are infected, but I can delete it. Tried step 6 but couldn’t find those files there nor in the system32/drivers folder. I also already set the “show the hidden files and folders”. Thanks much.

    Loaded driver \SystemRoot\system32\drivers\52958508.sys
    Loaded driver \SystemRoot\system32\drivers\81517530.sys
    Loaded driver \SystemRoot\system32\drivers\66635406.sys
    Loaded driver \SystemRoot\system32\drivers\45015299.sys

    • Hi Tammy,

      First of all congrats on finding the infected entry.This is a classical example of corrupted entries in google redirect virus cases.
      The reason for not able to remove this file might be because it have special attributes attached to it.Remove the attribute for the file using the command below.

      Open command prompt in administrator mode.Execute the below command.
      attrib –r –h –a –s C:\Windows\system32\drivers\xy­z123.sys(give the location and name of the file.in this eg.C:\Windows\system32\drivers­\xyz123.sys)
      After executing this command, the attributes attached to the file will be removed.

      Now try to remove it using del command
      del C:\Windows\system32\drivers\xy­z123.sys
      If you get any error message,the infected entries in the ntbtlog might be a false positive.Ignore the file and continue with the rest of the suspicious files.

      Fell free to keep me updated on the result.

      Anup Raman

      • NW

        Thanks Anup for guiding me properly. This is the best money I ever spent on fixing any computer issue.It also took care of some other unrelated browser issues.

  • Jaine

    Thanks Anup for the wonderful article.Your pro service got rid of google redirect virus.I am so happy to have stumbled your article.

  • holscherkc

    I sincerely wanted to thank you for this resource. Hands down the best tutorial I’ve found yet to combat the Google Redirect Virus.

  • JC

    Awsome service.Very professional service and quick resolution.Thanks to you.

  • Drake

    You are the BOSS MAN….your instructions were heavenly.Just got rid of this deadly sucker :-)

  • Mani

    Thanks Anup.Hope you are doing well.I know you did a great job in helping us get rid of this infection manually.It was thorough,but maybe I was not competent enough to do the troubleshooting on my own.The professional service you recommended was brilliant.I was lucky to get my issues fixed in less than 15 minutes.I did lose money but was well worth by saving me lot of time and headache researching on the topic.

    Let me know if you are interested for an IT lead position in my company.You will be a great asset to my organisation.Mail me.

  • Ryan

    Hi Anup,

    Very clear and good information.Yes, I finally fixed it with your professional service.

  • Dana Seth

    That was awesome.Just 20 minutes of running tool fixed my problem.I could have saved time if I listened to you before.Thanks for the wonderful and helpful instructions.

  • SOS

    Thanks Anup,the video was very helpful in helping me remove the infection.

  • Feby Ann

    Hi,

    I am from germany.I feel lucky to find your instructions online.nothing worked for me until I saw the instructions given here.Now everything works fine.Thanks you for helping me.

  • Zero

    I found a driver listed on my ntbtlog that looks suspicious but google shows no results when i searched for it.
    bootlog states the path as:
    Loaded driver \SystemRoot\System32\Drivers\a5k8kwa2.SYS
    When i try to delete the file the driver can not be found using this path or by seaching all files and folders on my computer.

    Could this be the cause of the redirect? How can I find and delete this driver?

    • Hi,

      Not sure if it is a corrupted file without much details.please check your mail

  • Ray John

    Well written article and video tutorial.Your style of explaining in chronological order made it easy for me to find the infected file.For some reason I could not remove it completely.Additionally, tried my own ways but could not find a way out(I am bit technical with computers).So I paid for the service and got the issue fixed.I would surely recommend this article to my friends in technical forum.You will soon be a known name in blogging world.

    God Bless!!!!!!!!

  • Stuart

    Job well done….

  • Sam

    Thanks Anup for the wonderful article and video tutorial.There were some infections in ntbtlog.Tried you recommendation for cleaning up using tools.It went smooth and fast.in 30mts I am virus free.Keep up the good work.

  • Rome

    I have these suspicious files in my boot log they are: C:\WINDOWS\system32\drivers\N360604000.009\SRTSPX.SYS

    and

    C:\WINDOWS\system32\drivers\N360604000.009\SRTSP.SYS

    I looked them up on Google and got a lot of references to the redirection problem. When I tried to delete them using: Start-Run-cmd-black screen-del It said “access is denied” although I was logged in as administrator. When I tried to delete the straight from the folder it said: these files are in use. Any suggestions on how to force delete these? Please feel free to email me thanks.

    • Both files are related to Norton 360. You can just uninstall Norton from your computer.Maybe these files are infected.Once the problem is fixed, re-install Norton.

      Do keep me updated.

      Good Luck
      Anup

  • Knox

    your video is amazing.rarely youtube have such educational videos.i feel educated myself after going through your guide.Anup,a heartfelt thank u.i’m waiting for more such videos and subscribed to your channel.

  • Darren

    Thanks to your pro service.They quickly got it out in no time.saved my time as well.

  • Bennet

    I lost track of the number of tools I tried to get this infection fixed.If I could find the person that came up with the scour.com virus I would inflict intense pain upon them.Thanks for the detailed and wonderful tutorial.Highly recommend your professional service.I just regret, I didn’t try it before.

  • Suresh

    Thanks for the detailed tutorial.Got it fixed by your pro service.Took no time and worked like a charm.Please keep up this good work.

  • spears

    Thanks Bro.The steps worked for me.Now my google is working fine.

  • Mark Pearce

    Hi Anup, I’m not able to save the Hosts file as a .txt – an error message appears “You don’t have permission to save in this location. Contact the admistraor to obtain permission. I have admin rights – it’s only a laptop computer on my wireless network at home.

    My Hosts file looks corrupted – see below the last three lines.

    # Copyright (c) 1993-2006 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a ‘#’ symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host

    127.0.0.1 localhost
    ::1 localhost

  • Samual

    I was working on this for almost a week now.Your instructions are point on target,just fixed all my problems.Thanks for the video instructions and a wonderful article

  • Sandy

    Thanks to your article, I am browsing websites without any problem.You just ended more than 2 weeks of my trouble.Your recommendations were spot on.

  • Tony Jacob

    My ntbt had too many infected entries.I was not able to remove it using command window,but instead went for professional support.It was worth every single penny paid.Thanks for helping me in getting rid of this scum.

  • Miguel

    I have learned a lot from this article. 100% hardcore technical but explained so simply that you don’t have to be a expert to do it.Thanks to your technique, I found dqzev.dll inside system32.Problem solved after deleting it.You are my god damn hero!!!!!
    Wish I can buy you a beer :-( (Seriously dude, Let me know if you are from around Newark or New Jersey)

  • Max Ryan

    I was just searching for this info for a while. After six hours of continuous Googleing, finally I got it in your website. Google should have placed you in the top for the kind of information provided here. Thanks for helping me get rid of this nasty virus.

  • Mandy

    :-)Thanks. this helped a lot………….

  • Anitha

    Thanks Anup for your recommendation.I am computer impaired but thanks for the short cut you recommended end of this post.Well worth the money spent.

  • Armando Ochoa

    Thanks Anup! your video was great. it helped me clear my google redirect virus. quick question. should i uncheck the “boot log” box from the system config window? thanks

    • Yes, you may uncheck the “bootlog” as it is only needed for creating ntbtlog file. You can also go to ‘control folders’,view tab,restore defaults to put back your PC the way it was before.
      :-) Glad this tutorial helped.Please do share this video for someone who might need it.

  • Jennifer

    Hi Anup,

    I work for Microsoft desktop support.Just came across your article on DNS server error.Then I came across google redirect article.I appreciate good technical articles from people who know what they are talking about.You are an amazing technician and a good narrator.The article here is very technical,but your video narration is simple and very well done.I can vouch for my grandma able to follow these steps.Please keep in touch,I can use your expertise especially with Windows 8 issues hanging around its release :-).Anyways,your site just became one of my favorite reference site.Thanks to your work for helping others.

    Jennifer

    • Thanks Jennifer for giving me the goose bumps :-)
      It’s always nice to talk to a MS Technician as I was once in your position.Learned most of my troubleshooting skills from there.
      Check your email.I will be happy to learn troubleshooting windows 8 issues.

  • Benson

    Thanks Anup for the wonderful tutorial.I got my problems fixed with fixredirect as you recommended.It was amazing and got it fixed in very less time.But that would not have been possible if I didnt stumple upon your article.Kudos to you.

  • Cindy

    I did use the software you recommended and it fixes the issue very quickly. I’m very glad I found your post thank you !

  • Nadene

    Thanks for making my week end worth while spending time to fix this sucker.There were no infected files in my ntbtlog.It seems the infection was hidden deep inside.Finally,I took your suggestion and got rid of it using professional tools.Boom….redirection is gone.Cant thank you enough for saving me a lot of headache.God Bless

  • Paul

    Greetings Anup , I proceeded with steps 1-3 , restart , and now the computer will not finish booting , task manager shows zero applications. I can see the desktop picture but no toolbar along the bottom . Any help would be appreciated.
    Prior to doing the 3 steps it was booting with no problems.
    Cheers , Paul

    • Paul

      I forgot to add I have tried this in safe mode also.

      • Hi Paul, Step 2 and 3 is about selecting boot tab and boot.ini and restart the computer. It will never cause any problem, unless you might have accidentally selected some other option in msconfig.
        Try this.
        1)After restarting computer,press ctrl+alt+del key at the same time
        2)You will get an option to select taskmanager.open it.
        3)click file ->newtask ->type ‘msconfig’. This will open msconfig
        4)select ‘general’ tab ->select ‘normal startup’
        Then restart computer.You should be good to go.

        The next time for getting boot.ini, follow this procedure.Restart the computer. As soon as your computer starts, keep tapping F8 key, it will show an advanced boot menu.There will be an option “enable boot logging”. Select the option to boot to desktop.This will automatically create ntbtlog.txt file in the default location.
        Do feel free to contact me if you need any further assistance.Please give me a max 12hrs to respond.Also do check your mail to see if I have already sent you any instructions.
        Good luck

      • Paul,

        Any update

  • Peter Oliver

    Amazing blog mate

  • Sharon

    Hi, I am trying to follow your instructions on how to get rid of this virus (excellent instructions, btw) but I do not have the ntbtlog.txt file anywhere on my computer. I have done a search and nothing is coming up. I also cannot find any of the TDSS entries in my registry. I have ran so many TDSS killers, removals, etc… and they’re not finding anything. :-/

    • Hi Sharon,

      Please try this. Restart the computer. As soon as your computer starts, keep tapping F8 key, it will show an advanced boot menu.There will be an option “enable boot logging”. Select the option to boot to desktop.This will automatically create ntbtlog.txt file in the default location.

      Let me know if you need any further assistance.Give me maximum 12 hrs time frame to answer to your queries on your email.
      Good Luck.

  • Diane

    I can’t thank you enough.This problem had me for almost a month,but thought it was google’s problem.But this article opened my eyes to what was happening.Unfortunately,this was too technical for an old lady like me.But thanks to your suggestion in the end.I used it and now it seems everything is working fine.Will keep you updated on my progress.

  • Bridgette

    Thnaks to your service.My computer is virus free now.Enjoy your weekend.

  • Nora

    Thanks Anup, the video was very helpful :-)

  • Gracey

    I loved your article.Shared it with my friends here.All issues fixed by your paid support.Best money I spent for my laptop :-)

  • Kapanpun

    Nice site and article sir :)

  • Ashley

    Thanks Anup for the spot on instructions.Your service is amazing.Got all issues fixed in almost 30mts.Without doubt,the best instructions on this topic.

  • Felix

    These tech skills are amazing.My problem was with H8SRTnfvywogretx.sys hiding inisde system32.Found out easily using your instructions.I am a German native and don’t think this article is listed anyweher for german readers.Will surely share this for my people.Thanks.

  • Jason Lewis

    Just like Tiffany said, worked like a charm.Thanks mate.

  • Angus

    This is my first time commenting on any website.I felt obliged to put a comment here for your efforts.

    From your accent it seems you are not a native english speaker, but it was clear,crisp and very well explained.Funny,that I found your voice very soothing. reminded me of teacher struggling to teach small kids.I feel empowered technically atleast a bit.

    Well,back to the main topic.Yes,I got it fixed finally.Could not find any infected file inside the log file.Paid service got everything fixed.I am not disappointed,it was well worth the money spent.

    Thanks Anup for all the help

  • Ivan

    I second that!!!!!!!!!!!! this tutorial is some genius work. Thanks to your help

  • Tiffany

    I tried all of your steps and couldn’t find any files with those names and I couldn’t find any with unusual names. I tried your professional support, and it worked like a charm. It only took a few minutes for it to scan everything too. Thank you very much.

  • Daniel

    Thanks Buddy.It worked.

  • Keerthi

    Hello Sir,

    I found information about google redirect virus very useful and was able to get rid of it. Thanks for the detailed guidance.Thank you

  • Francesca

    I agree.too lazy to follow your method.the professional tools worked for me.Thanks

  • Randy

    Anup, thanks for the mail.You were right about Norton.The license expired sometime back and it had crashed.I swear,it never showed me any warning regarding it’s status.The removal tool from the link did a great job in removing Norton.Now my computer speed is back to normal.I am still shocked knowing Norton created so much issues in my computer.It is now out of my list forever.

    Regarding google redirect, I chose your professional support.Not that I don’t want to follow your method,but I was too exhausted after spending hours trying to fix other issues apart from browser redirection.Anyways,they got the issues fixed in less than 20mts.Thanks from bottom of my heart for your timely suggestions and help to get all my computer issues fixed.

  • Jay

    Fixredirectvirus guys were very helpful in getting my problems solved.But it’s you I thank the most for all the wonderful instructions.God bless!!!!!!!

  • Merlyn

    Hi Anup,

    Your instructions were spot on.Yes,I finally got it fixed by the virus removal experts.Thanks for all the help.

  • Johan

    Just got it fixed using your recommended service.Thanks buddy

  • Dr. M

    I consider myself an IT expert,but this was way out of my league.Your instructions helped me find H8SRTwvshxz.sys inside system32 folder.The moment I removed it from command prompt,it stopped redirecting.You are a genius,and you did a great job in explaining this complicated problem.I shared this article with my social circles.Thank you

  • Brenda Olsen

    Thanks Anup for detailed instructions.Everything fixed.

  • Sandeep

    Your instructions are amazing.Finally everything is back to normal.THanks

  • Jennifer

    Hi Anup, I followed your intructions to manually remove the corrupted file, but I am not able to identify any suspicious looking file names in the ntbtlog.

    • Hi Jennifer,

      Sorry to know the issue is not fixed.There are limitations for me especially when you deal with such a smart and deadly virus. These are times when I wish to be physically present in front of computer and see what is happening inside which unfortunately is not possible. Apart from giving all the details steps mentioned here, the only thing possible is to give my “what next” suggestions.You may try for professional support which I mentioned here.I can assure you it is worth spending money for.

      Also please check your mail.

    • Andrew

      Hi Anup,
      Even i couldn’t see any suspicious files in the boot log file. I got it fixed using your service.It resolved my problem.
      Once Thanks for your detailed steps.

  • skyiotisv

    Thanks Anup for the wonderful tutorial.Could not get this fixed by following your method.Maybe I screwed up.But I took your advice for professional help.They did a great job in fixing it.But all the credit goes to you for proper guidance.Enjoy your weekend.
    PEOPLE LIKE YOU MAKE THE WORLD A BETTER PLACE :-)

  • Brandon

    when im in boot tab i cant click on anything in it plzz help

    • No Problem.

      Restart the computer. As soon as your computer starts, keep tapping F8 key, it will show an advanced boot menu.There will be an option “enable boot logging”. This will automatically create ntbtlog.txt file in the default location.

      Good Luck

    • Brandon,

      Check your mail. Please do update me on the result.

      Thanks
      Anup Raman

  • Ben

    thank you for the simple and detailed instructions.got rid of google redirect virus.hopefully it stay this forever.

  • Hi Anup…I followed all of your instructions, steps, etc. I was able to improve some of the performance in browsers. But, I am still seeing some infection where I type “Joe Smith” in Google bar either in FF or Chrome, and it opens another tab window and throws a bogus page up. If I am lucky, it will keep searching Joe Smith on original tab and resolve itself. So, it’s partially working, but still flaky. Do you have any suggestions?

    I went back into Hosts file to check on new additions and it’s still clean. I noticed that it changed the file name to “Hosts.txt”. Is that standard?

    Thanks for your help!

    • To me it looks more of a web browser issue than a redirect issue. Maybe you have too many spyware or adwares files hidden inside. Please try a scan using superantispyware free edition and also using ccleaner. Ccleaner is helpful in removing all crap files from your computer but not the google redirect virus rootkit.

      Regarding host file,remove .txt extension.It should be fine.

      This should help.Good Luck

  • Paul

    Thanks, I followed your instructions and found Msqpdxserv.sys using ntbtlog.Everything back to normal once it was removed.

  • Chibi Ruah

    Thanks alot for this video (very well done). Because of it, I was able to gain control of my computer again.

  • Liara

    I am so grateful for this article.Thanks Again. Really Great.

  • Kierke Gaard

    I cannot stress how thankful I am for this video. Thank you for taking the time to make such a great step by step video. You explained clearly to the viewer as to what to do and used great visuals. Most “how to videos” on youtube typically have terrible audio and poor instructions. I struggled with this virus for days. I believe I got it from cnet. Cnet was a site I use to trust. Thanks to you I successfully removed this virus. I feel educated. I have subscribed to your channel. Again THANK YOU

  • Alan Lardymple

    Hi Anup,

    I am Alan,accountant from Winchester with a beautiful wife and lovely kids to care for.My official laptop got infected recently with google redirect virus.Was shocked at first as I never downloaded any game or visit porn site using this lappie.Afters seeing your video,I realised my atapi.sys file is infected with 867KB.I almost died when you said it is a 50/50 chance whenever this file is infected.But thanks to your recommendation.Fixredirectvirus was able to help me out with their tools.Almost took 30 minutes to completely scan and fix the darn thing.Everything looks good.Hope it stays forever.

    If the information could have lost,I would have been kicked out of my job easily.I cannot afford to lose my job especially in this economy.You just saved my life and career.Now my entire family is your fan.

    Thanks forever

  • Mary Ann

    I completely agree.It was worth money spent.Thanks Anup for trying to help fix my issue.I guess,some problems can only be fixed by software.

    • Hi Mary,
      Good to know the issue is fixed.After checking the details, I was sure the infection was worse.It seems you have multiple infections hiding inside.Apart from the suggestions that I gave, there was nothing that I could have tried other than taking remote access and troubleshooting on your computer.Anyways it’s good to see all the issues are taken care of.

  • Gonsales

    Thanks for the tool. Google is not redirecting anymore.Well worth every penny spent.

  • Alex

    Hey Anup,

    I been trying to fix my computer and I follow your steps. I found this suspicious file :
    Loaded driver \??\C:\Windows\system32\MpEngineStore\MpKslefee8882.sys . I tried google and didnt find any info in it. So I am curious if I should delete it or leave it alone. Also, when I check my ntbtlog.txt I notice that they repeat over and over… Is that normal.

    Thanks

    • Yes, this is an infected entry. Get rid of it either directly by deleting or delete using command prompt.

      Repeating is common. Check if it is repeating pointing towards the same location. If you have the entry in other locations, get rid of that too.

      Finally check registry with this file name as I mentioned towards the end of the video.

      Good Luck

  • edgers Jex

    Thanks for the help.You are right to the point to get this fixed.

  • Reinse Roy

    Got tired of scrolling through ntlog.Not suitable for people like me.Paid for the service you suggested to get rid of virus.Now it is gone.Thanks for the taking time to help me out.

  • san

    Thanks buddy.everything worked.seems to be working fine now.

  • Linda Strauss

    I was too lazy to follow steps.Took your advise on professional help.In less than 10mts got my issue fixed.I could have got it fixed by following your steps,who knows?Anyways it was well worth the money spent.I will recommend this site to all my contacts.Thanks for your time and help.

  • Adam

    Man you certainly know what you are speaking.Almost gave up on your instructions.I was luck to notice your comments on youtube video to lookout for C:\Users\username\AppData\Loca­l\Downloaded Installations\Apple Computer\curobkdlz.dll.Removing it did the trick.Hopefully this is fixed forever

  • Alfred

    Anup,sorry man.what you said here is not meant for me.but i took your advice and took the paid service.my issue got fixed in 15mts after 2 scans.respect :)

  • Cena

    Your video dint help,but it moght be my mistake in following instructions properly.took your suggestion and went for professional help.Voila….Now I’m virus free and life is back to normal.Everybody should appreciate the pain that you took in explaining and help people like us.God bless!!!!!!!

  • Mohsin

    Took your advise.Scan fixed google redirect virus in 10minutes.
    Thanks for your time.
    Bye

  • Cheng Li

    Thanks for the guidance.just finished fixing google redirect virus.hope it wont haunt me again :-)

  • Lenny G

    THANK YOU!I’ve been trying to get rid of this thing for ages,and nothing else has worked.This is the only video/blog/administrator response that has worked.
    Cheers!

  • Jenna

    Lots and lots of hugs and kisses for this detailed tutorial.my facebook is back online.You are my King 8-()

  • Umb_Sail

    Loaded driver SystemRootsystem32driverstifm21.sys
    Loaded driver SystemRootsystem32DRIVERSsdbus.sys
    Loaded driver SystemRootsystem32DRIVERSCmBatt.sys
    Loaded driver SystemRootsystem32DRIVERSi8042prt.sys
    Loaded driver SystemRootsystem32DRIVERSkbdclass.sys
    Loaded driver SystemRootsystem32DRIVERSSynTP.sys
    Loaded driver SystemRootsystem32DRIVERSmouclass.sys
    Loaded driver SystemRootsystem32DRIVERStdcmdpst.sys
    Loaded driver SystemRootsystem32DRIVERScdrom.sys
    Loaded driver SystemRootsystem32DRIVERSGEARAspiWDM.sys
    Loaded driver SystemRootsystem32DRIVERSdne2000.sys
    Loaded driver SystemRootsystem32DRIVERSmsiscsi.sys
    Loaded driver SystemRootsystem32DRIVERSrasl2tp.sys
    Loaded driver SystemRootsystem32DRIVERSndistapi.sys
    Loaded driver SystemRootsystem32DRIVERSndiswan.sys
    Loaded driver SystemRootsystem32DRIVERSraspppoe.sys
    Loaded driver SystemRootsystem32DRIVERSraspptp.sys
    Loaded driver SystemRootsystem32DRIVERSrassstp.sys
    Loaded driver SystemRootsystem32DRIVERStermdd.sys
    Loaded driver SystemRootsystem32DRIVERSswenum.sys
    Loaded driver SystemRootsystem32DRIVERSmssmbios.sys
    Loaded driver SystemRootsystem32DRIVERSumbus.sys
    Loaded driver SystemRootsystem32DRIVERSusbhub.sys
    Loaded driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Loaded driver SystemRootsystem32driversRTKVHDA.sys
    Loaded driver SystemRootsystem32DRIVERSAGRSM.sys
    Loaded driver SystemRootsystem32driversmodem.sys
    Loaded driver SystemRootSystem32DriversFs_Rec.SYS
    Loaded driver SystemRootSystem32DriversNull.SYS
    Loaded driver SystemRootSystem32DriversBeep.SYS
    Loaded driver SystemRootSystem32driversvga.sys
    Loaded driver SystemRootSystem32DRIVERSRDPCDD.sys
    Loaded driver SystemRootsystem32driversrdpencdd.sys
    Loaded driver SystemRootSystem32DriversMsfs.SYS
    Loaded driver SystemRootSystem32DriversNpfs.SYS
    Loaded driver SystemRootSystem32DRIVERSrasacd.sys
    Loaded driver SystemRootsystem32DRIVERStdx.sys
    Loaded driver SystemRootSystem32DRIVERSnetbt.sys
    Loaded driver SystemRootsystem32DRIVERSsmb.sys
    Loaded driver SystemRootsystem32driversafd.sys
    Loaded driver SystemRootsystem32DRIVERSpacer.sys
    Loaded driver SystemRootsystem32DRIVERSnetbios.sys
    Loaded driver SystemRootsystem32DRIVERSwanarp.sys
    Did not load driver SystemRootSystem32DriversTosrfcom.SYS
    Loaded driver SystemRootsystem32DRIVERSrdbss.sys
    Loaded driver SystemRootsystem32driversnsiproxy.sys
    Loaded driver SystemRootSystem32Driversdfsc.sys
    Loaded driver SystemRootsystem32DRIVERSmonitor.sys
    Loaded driver SystemRootsystem32driversluafv.sys
    Did not load driver SystemRootsystem32DRIVERSMpFilter.sys
    Loaded driver SystemRootsystem32driversdrmkaud.sys
    Loaded driver SystemRootsystem32DRIVERSlltdio.sys
    Loaded driver SystemRootsystem32DRIVERSnwifi.sys
    Loaded driver SystemRootsystem32DRIVERSndisuio.sys
    Loaded driver SystemRootsystem32DRIVERSrspndr.sys
    Loaded driver SystemRootsystem32driversHTTP.sys
    Loaded driver SystemRootSystem32DRIVERSsrvnet.sys
    Loaded driver SystemRootsystem32DRIVERSbowser.sys
    Loaded driver SystemRootSystem32driversmpsdrv.sys
    Loaded driver SystemRootsystem32driversmrxdav.sys
    Loaded driver SystemRootsystem32DRIVERSmrxsmb.sys
    Loaded driver SystemRootsystem32DRIVERSmrxsmb10.sys
    Loaded driver SystemRootsystem32DRIVERSmrxsmb20.sys
    Loaded driver SystemRootSystem32DRIVERSsrv2.sys
    Loaded driver SystemRootSystem32DRIVERSsrv.sys
    Did not load driver SystemRootSystem32DRIVERSsrv.sys
    Loaded driver ??C:Windowssystem32DriversCVPNDRVA.sys
    Loaded driver SystemRootsystem32driverspeauth.sys
    Loaded driver SystemRootSystem32Driverssecdrv.SYS
    Loaded driver SystemRootSystem32driverstcpipreg.sys
    Loaded driver SystemRootsystem32DRIVERScdfs.sys

  • Umb_Sail

    If possible can you please look over my ntbtlog. The ones I thought were suspicious I googled and found that they are good files, but that they can get corrupted. So I am not sure what to do.  I am also not sure about this: Loaded driver ??C:Windowssystem32DriversCVPNDRVA.sys.
    Thank you I greatly appreciate it.
     
    Service Pack 2 8 14 2012 06:55:27.375
    Loaded driver SystemRootsystem32ntoskrnl.exe
    Loaded driver SystemRootsystem32hal.dll
    Loaded driver SystemRootsystem32kdcom.dll
    Loaded driver SystemRootsystem32mcupdate_GenuineIntel.dll
    Loaded driver SystemRootsystem32PSHED.dll
    Loaded driver SystemRootsystem32BOOTVID.dll
    Loaded driver SystemRootsystem32CLFS.SYS
    Loaded driver SystemRootsystem32CI.dll
    Loaded driver SystemRootsystem32driversWdf01000.sys
    Loaded driver SystemRootsystem32driversWDFLDR.SYS
    Loaded driver SystemRootsystem32driversacpi.sys
    Loaded driver SystemRootsystem32driversWMILIB.SYS
    Loaded driver SystemRootsystem32driversmsisadrv.sys
    Loaded driver SystemRootsystem32driverspci.sys
    Loaded driver SystemRootsystem32DRIVERSLPCFilter.sys
    Loaded driver SystemRootSystem32driverspartmgr.sys
    Loaded driver SystemRootsystem32DRIVERScompbatt.sys
    Loaded driver SystemRootsystem32DRIVERSBATTC.SYS
    Loaded driver SystemRootsystem32driversvolmgr.sys
    Loaded driver SystemRootSystem32driversvolmgrx.sys
    Loaded driver SystemRootsystem32driversintelide.sys
    Loaded driver SystemRootsystem32driversPCIIDEX.SYS
    Loaded driver SystemRootsystem32DRIVERSpcmcia.sys
    Loaded driver SystemRootSystem32driversmountmgr.sys
    Loaded driver SystemRootsystem32driversatapi.sys
    Loaded driver SystemRootsystem32driversataport.SYS
    Loaded driver SystemRootsystem32driversfltmgr.sys
    Loaded driver SystemRootsystem32driversfileinfo.sys
    Loaded driver SystemRootsystem32DRIVERSMpFilter.sys
    Loaded driver SystemRootSystem32DriversPxHelp20.sys
    Loaded driver SystemRootSystem32Driversksecdd.sys
    Loaded driver SystemRootsystem32driversndis.sys
    Loaded driver SystemRootsystem32driversmsrpc.sys
    Loaded driver SystemRootsystem32driversNETIO.SYS
    Loaded driver SystemRootSystem32driverstcpip.sys
    Loaded driver SystemRootSystem32driversfwpkclnt.sys
    Loaded driver SystemRootSystem32DriversNtfs.sys
    Loaded driver SystemRootsystem32driversvolsnap.sys
    Loaded driver SystemRootsystem32DRIVERSTVALZ_O.SYS
    Loaded driver SystemRootSystem32Driversspldr.sys
    Loaded driver SystemRootSystem32Driversmup.sys
    Loaded driver SystemRootSystem32driversecache.sys
    Loaded driver SystemRootsystem32driversdisk.sys
    Loaded driver SystemRootsystem32driversCLASSPNP.SYS
    Loaded driver SystemRootsystem32driverscrcdisk.sys
    Loaded driver SystemRootsystem32DRIVERStunnel.sys
    Loaded driver SystemRootsystem32DRIVERStunmp.sys
    Loaded driver SystemRootsystem32DRIVERSintelppm.sys
    Loaded driver SystemRootSystem32driversdxgkrnl.sys
    Loaded driver SystemRootsystem32DRIVERSigdkmd32.sys
    Loaded driver SystemRootsystem32DRIVERSHDAudBus.sys
    Loaded driver SystemRootsystem32DRIVERSathr.sys
    Loaded driver SystemRootsystem32DRIVERSRtlh86.sys
    Loaded driver SystemRootsystem32DRIVERSusbuhci.sys
    Loaded driver SystemRootsystem32DRIVERSusbehci.sys
    Loaded driver SystemRootsystem32DRIVERSohci1394.sys
     

  • mija_em

     Loaded driver SystemRootsystem32driversWudfPf.sys
    Loaded driver SystemRootsystem32DRIVERSlltdio.sys
    Loaded driver SystemRootsystem32DRIVERSnwifi.sys
    Loaded driver SystemRootsystem32DRIVERSndisuio.sys
    Loaded driver SystemRootsystem32DRIVERSrspndr.sys
    Loaded driver SystemRootsystem32DRIVERSTurboB.sys
    Loaded driver SystemRootsystem32DRIVERSvwifimp.sys
    Loaded driver ??C:Program Files (x86)ASUSATK PackageATKGFNEXASMMAP64.sys
    Loaded driver SystemRootsystem32driversHTTP.sys
    Loaded driver SystemRootsystem32DRIVERSbowser.sys
    Loaded driver SystemRootSystem32driversmpsdrv.sys
    Loaded driver SystemRootsystem32DRIVERSmrxsmb.sys
    Loaded driver SystemRootsystem32DRIVERSmrxsmb10.sys
    Loaded driver SystemRootsystem32DRIVERSmrxsmb20.sys
    Loaded driver ??C:Program FilesFileOpenServicesfowp64.sys
    Loaded driver SystemRootsystem32driverspeauth.sys
    Loaded driver SystemRootSystem32Driverssecdrv.SYS
    Loaded driver SystemRootSystem32DRIVERSsrvnet.sys
    Loaded driver SystemRootSystem32driverstcpipreg.sys
    Loaded driver SystemRootSystem32DRIVERSsrv2.sys
    Loaded driver SystemRootSystem32DRIVERSsrv.sys
    Did not load driver SystemRootSystem32DRIVERSsrv.sys
    Loaded driver SystemRootSystem32Driversfastfat.SYS
    Loaded driver ??C:Windowssystem32driversmbam.sys
    Loaded driver SystemRootsystem32DRIVERSasyncmac.sys
     
    Thanks

  • mija_em

    HI
    I also am not finding any suspicious files ???
    Microsoft (R) Windows (R) Version 6.1 (Build 7600)  8 15 2012 09:43:56.109
    Loaded driver SystemRootsystem32ntoskrnl.exe
    Loaded driver SystemRootsystem32hal.dll
    Loaded driver SystemRootsystem32kdcom.dll
    Loaded driver SystemRootsystem32mcupdate_GenuineIntel.dll
    Loaded driver SystemRootsystem32PSHED.dll
    Loaded driver SystemRootsystem32CLFS.SYS
    Loaded driver SystemRootsystem32CI.dll
    Loaded driver SystemRootsystem32driversWdf01000.sys
    Loaded driver SystemRootsystem32driversWDFLDR.SYS
    Loaded driver SystemRootsystem32DRIVERSACPI.sys
    Loaded driver SystemRootsystem32DRIVERSWMILIB.SYS
    Loaded driver SystemRootsystem32DRIVERSmsisadrv.sys
    Loaded driver SystemRootsystem32DRIVERSpci.sys
    Loaded driver SystemRootsystem32DRIVERSvdrvroot.sys
    Loaded driver SystemRootSystem32driverspartmgr.sys
    Loaded driver SystemRootsystem32DRIVERScompbatt.sys
    Loaded driver SystemRootsystem32DRIVERSBATTC.SYS
    Loaded driver SystemRootsystem32DRIVERSvolmgr.sys
    Loaded driver SystemRootSystem32driversvolmgrx.sys
    Loaded driver SystemRootsystem32driverspciide.sys
    Loaded driver SystemRootsystem32driversPCIIDEX.SYS
    Loaded driver SystemRootSystem32driversmountmgr.sys
    Loaded driver SystemRootsystem32DRIVERSiaStor.sys
    Loaded driver SystemRootsystem32DRIVERSatapi.sys
    Loaded driver SystemRootsystem32DRIVERSataport.SYS
    Loaded driver SystemRootsystem32DRIVERSmsahci.sys
     Loaded driver SystemRootsystem32driversamdxata.sys
    Loaded driver SystemRootsystem32driversfltmgr.sys
    Loaded driver SystemRootsystem32driversfileinfo.sys
    Loaded driver SystemRootSystem32DriversNtfs.sys
    Loaded driver SystemRootSystem32Driversmsrpc.sys
    Loaded driver SystemRootSystem32Driversksecdd.sys
    Loaded driver SystemRootSystem32Driverscng.sys
    Loaded driver SystemRootSystem32driverspcw.sys
    Loaded driver SystemRootSystem32DriversFs_Rec.sys
    Loaded driver SystemRootsystem32driversndis.sys
    Loaded driver SystemRootsystem32driversNETIO.SYS
    Loaded driver SystemRootSystem32Driversksecpkg.sys
    Loaded driver SystemRootSystem32driverstcpip.sys
    Loaded driver SystemRootSystem32driversfwpkclnt.sys
    Loaded driver SystemRootsystem32DRIVERSvmstorfl.sys
    Loaded driver SystemRootsystem32DRIVERSvolsnap.sys
    Loaded driver SystemRootSystem32Driversspldr.sys
    Loaded driver SystemRootSystem32driversrdyboost.sys
    Loaded driver SystemRootsystem32DRIVERSnvpciflt.sys
    Loaded driver SystemRootSystem32Driversmup.sys
    Loaded driver SystemRootSystem32drivershwpolicy.sys
    Loaded driver SystemRootSystem32DRIVERSfvevol.sys
    Loaded driver SystemRootsystem32DRIVERSdisk.sys
    Loaded driver SystemRootsystem32DRIVERSCLASSPNP.SYS
    Loaded driver SystemRootsystem32DRIVERScdrom.sys
    Loaded driver SystemRootSystem32DriversNull.SYS
    Loaded driver SystemRootSystem32DriversBeep.SYS
    Loaded driver SystemRootSystem32driversvga.sys
    Loaded driver SystemRootSystem32DRIVERSRDPCDD.sys
    Loaded driver SystemRootsystem32driversrdpencdd.sys
    Loaded driver SystemRootsystem32driversrdprefmp.sys
    Loaded driver SystemRootSystem32DriversMsfs.SYS
    Loaded driver SystemRootSystem32DriversNpfs.SYS
    Loaded driver SystemRootsystem32DRIVERStdx.sys
    Loaded driver SystemRootsystem32driversafd.sys
    Loaded driver SystemRootSystem32DRIVERSnetbt.sys
    Loaded driver SystemRootsystem32DRIVERSwfplwf.sys
    Loaded driver SystemRootsystem32DRIVERSpacer.sys
    Loaded driver SystemRootsystem32DRIVERSvwififlt.sys
    Loaded driver SystemRootsystem32DRIVERSnetbios.sys
    Loaded driver SystemRootsystem32DRIVERSwanarp.sys
    Loaded driver SystemRootsystem32DRIVERStmtdi.sys
    Loaded driver SystemRootsystem32DRIVERStermdd.sys
    Loaded driver SystemRootsystem32DRIVERSrdbss.sys
    Loaded driver SystemRootsystem32driversnsiproxy.sys
    Loaded driver SystemRootsystem32DRIVERSmssmbios.sys
    Loaded driver SystemRootSystem32driversdiscache.sys
    Loaded driver SystemRootsystem32driverscsc.sys
    Loaded driver SystemRootSystem32Driversdfsc.sys
    Loaded driver SystemRootsystem32DRIVERSblbdrive.sys
    Loaded driver ??C:Program Files (x86)ASUSATK PackageATK WMIACPIatkwmiacpi64.sys
    Loaded driver SystemRootsystem32DRIVERStunnel.sys
    Loaded driver SystemRootSystem32driversdxgkrnl.sys
    Loaded driver SystemRootsystem32DRIVERSnvlddmkm.sys
    Did not load driver SystemRootSystem32driversdxgkrnl.sys
    Loaded driver SystemRootsystem32DRIVERSigdkmd64.sys
    Loaded driver SystemRootsystem32DRIVERSHECIx64.sys
    Loaded driver SystemRootsystem32driversusbehci.sys
    Loaded driver SystemRootsystem32DRIVERSHDAudBus.sys
    Loaded driver SystemRootsystem32DRIVERSathrx.sys
    Loaded driver SystemRootsystem32DRIVERSvwifibus.sys
    Loaded driver SystemRootsystem32DRIVERSRt64win7.sys
    Loaded driver SystemRootsystem32DRIVERSi8042prt.sys
    Loaded driver SystemRootsystem32DRIVERSkbfiltr.sys
    Loaded driver SystemRootsystem32DRIVERSkbdclass.sys
    Loaded driver SystemRootsystem32DRIVERSETD.sys
    Loaded driver SystemRootsystem32DRIVERSmouclass.sys
    Loaded driver SystemRootsystem32DRIVERSCmBatt.sys
    Loaded driver SystemRootsystem32DRIVERSwmiacpi.sys
    Loaded driver SystemRootsystem32DRIVERSintelppm.sys
    Loaded driver SystemRootsystem32DRIVERSCompositeBus.sys
    Loaded driver SystemRootsystem32DRIVERSserscan.sys
    Loaded driver SystemRootsystem32driversksthunk.sys
    Loaded driver SystemRootsystem32DRIVERSAgileVpn.sys
    Loaded driver SystemRootsystem32DRIVERSrasl2tp.sys
    Loaded driver SystemRootsystem32DRIVERSndistapi.sys
    Loaded driver SystemRootsystem32DRIVERSndiswan.sys
    Loaded driver SystemRootsystem32DRIVERSraspppoe.sys
    Loaded driver SystemRootsystem32DRIVERSraspptp.sys
    Loaded driver SystemRootsystem32DRIVERSrassstp.sys
    Loaded driver SystemRootsystem32DRIVERSrdpbus.sys
    Loaded driver SystemRootsystem32DRIVERSswenum.sys
    Loaded driver SystemRootsystem32DRIVERSbtath_bus.sys
    Loaded driver SystemRootsystem32DRIVERSumbus.sys
    Did not load driver SystemRootSystem32driversvga.sys
    Loaded driver SystemRootsystem32DRIVERSusbhub.sys
    Loaded driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Loaded driver SystemRootsystem32driversRTKVHD64.sys
    Loaded driver SystemRootsystem32DRIVERSIntcDAud.sys
    Loaded driver SystemRootsystem32DRIVERSbtfilter.sys
    Loaded driver SystemRootSystem32DriversBTHUSB.sys
    Loaded driver SystemRootsystem32DRIVERSusbccgp.sys
    Loaded driver SystemRootsystem32DRIVERShidusb.sys
    Loaded driver SystemRootsystem32DRIVERSkbdhid.sys
    Loaded driver SystemRootsystem32DRIVERSmouhid.sys
    Loaded driver SystemRootSystem32Driversusbvideo.sys
    Loaded driver SystemRootsystem32DRIVERSmonitor.sys
    Loaded driver SystemRootsystem32DRIVERSrfcomm.sys
    Loaded driver SystemRootsystem32driversBthEnum.sys
    Loaded driver SystemRootsystem32DRIVERSbthpan.sys
    Loaded driver SystemRootsystem32DRIVERSbtath_rcp.sys
    Loaded driver SystemRootsystem32driversbtath_a2dp.sys
    Loaded driver SystemRootsystem32DRIVERSbtath_hcrp.sys
    Loaded driver SystemRootsystem32DRIVERSbtath_flt.sys
    Loaded driver SystemRootsystem32DRIVERSbtath_lwflt.sys
    Loaded driver SystemRootsystem32driversluafv.sys
    Loaded driver ??C:Program Files (x86)Trend MicroClient Server Security AgentTmPreFlt.sys
    Loaded driver ??C:Program Files (x86)Trend MicroClient Server Security AgentVSApiNt.sys
    Loaded driver ??C:Program Files (x86)Trend MicroClient Server Security AgentTmXPFlt.sys

  • IanMurphy

    What if the virus is hidden or camouflaged in one of the normal .sys files?  I don’t have any obvious generated drivers but I’ve googled some such as RDPCDD.sys and rdpencdd.sys which say they are microsoft files but can get corrupted.  I’d prefer to not use anti virus programs since its hard to tell which are completely legitimate..

    • Good Question. One way is to compare the file size of a suspicious file with that of a healthy file. For eg, atapi.sys file is susceptible to this infection. The usual file size ranges from 20KB – 70 KB which again depend on factors such as type of OS and device drivers. In some of the infected computers, I found the size was above 100KB and sometime even up to 300-400KB.The solution is to replace the infected atapi.sys file with the same file from a healthy computer. But it is very risky, as there is 50-50 chance of computer crashing after that. I wont recommend this to anyone, unless you have backed up all files and well prepared for doing a repair or clean installation in worst case scenario. By the way, repair installation may or may not work in fixing the corrupted file.
      The other way to check if the file is corrupted is using a file integrity checking software. There are lot of software both free and paid ones available. You may try that. Personally this method didn’t workout for me whenever I tried, so I stay away from recommending that.
      If nothing else worked, I definitely recommend going for the professional support I mentioned here. From almost 300 feedback’s that I received in last 3 mths, only 2 failed to fix the issue using their service. So I surely recommend them.

  • kliss9

    i hope i am not too late finding this. i cannot find any suspicious drivers after following all the steps. any help would be great. i Couldnt figure out how to fit this in a single comment Thanks!

    Loaded driver SystemRootsystem32DRIVERSGEARAspiWDM.sys
    Loaded driver SystemRootsystem32DRIVERSAcceler.sys
    Loaded driver SystemRootsystem32DRIVERSintelppm.sys
    Loaded driver SystemRootsystem32driverswmiacpi.sys
    Loaded driver SystemRootsystem32DRIVERSCmBatt.sys
    Loaded driver SystemRootsystem32DRIVERSAMPPAL.sys
    Loaded driver SystemRootsystem32driversCompositeBus.sys
    Loaded driver SystemRootsystem32DRIVERSAgileVpn.sys
    Loaded driver SystemRootsystem32DRIVERS rasl2tp.sys
    Loaded driver SystemRootsystem32DRIVERSndistapi.sys
    Loaded driver SystemRootsystem32DRIVERSndiswan.sys
    Loaded driver SystemRootsystem32DRIVERSraspppoe.sys
    Loaded driver SystemRootsystem32DRIVERSraspptp.sys
    Loaded driver SystemRootsystem32DRIVERSrassstp.sys
    Loaded driver SystemRootsystem32DRIVERSteefer2.sys
    Loaded driver SystemRootsystem32driversswenum.sys
    Loaded driver SystemRootsystem32driversumbus.sys
    Loaded driver SystemRootsystem32DRIVERSWDKMD.sys
    Did not load driver SystemRootSystem32driversvga.sys
    Loaded driver SystemRootsystem32DRIVERSusbhub.sys
    Loaded driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Loaded driver SystemRootsystem32driversRTKVHD64.sys
    Loaded driver SystemRootsystem32driversksthunk.sys
    Loaded driver SystemRootsystem32DRIVERSIntcDAud.sys
    Loaded driver SystemRootsystem32DRIVERSusbccgp.sys
    Loaded driver SystemRootSystem32Driversusbvideo.sys
    Loaded driver SystemRootsystem32DRIVERSCtClsFlt.sys
    Loaded driver SystemRootsystem32DRIVERShidusb.sys
    Loaded driver SystemRootsystem32driverskbdhid.sys
    Loaded driver SystemRootsystem32DRIVERSmouhid.sys
    Loaded driver SystemRootsystem32DRIVERSmonitor.sys
    Loaded driver SystemRootsystem32driversluafv.sys
    Loaded driver SystemRootsystem32driversWudfPf.sys
    Loaded driver SystemRootsystem32DRIVERSlltdio.sys
    Loaded driver SystemRootsystem32DRIVERSnwifi.sys
    Loaded driver SystemRootsystem32DRIVERSndisuio.sys
    Loaded driver SystemRootsystem32DRIVERSrspndr.sys
    Loaded driver SystemRootsystem32DRIVERSTurboB.sys
    Loaded driver SystemRootsystem32DRIVERSvwifimp.sys
    Loaded driver ??C:Windowssystem32driversWpsHelper.sys
    Loaded driver SystemRootsystem32driversHTTP.sys
    Loaded driver SystemRootsystem32DRIVERSbowser.sys
    Loaded driver SystemRootSystem32driversmpsdrv.sys
    Loaded driver SystemRootsystem32DRIVERSmrxsmb.sys

  • kliss9

    Loaded driver SystemRootsystem32DRIVERSmrxsmb10.sys
    Loaded driver SystemRootsystem32DRIVERSmrxsmb20.sys
    Loaded driver SystemRootsystem32driverspeauth.sys
    Loaded driver SystemRootSystem32Driverssecdrv.SYS
    Loaded driver SystemRootSystem32DRIVERSsrvnet.sys
    Loaded driver SystemRootSystem32driverstcpipreg.sys
    Loaded driver SystemRootSystem32DRIVERSsrv2.sys
    Loaded driver SystemRootSystem32DRIVERSsrv.sys
    Did not load driver SystemRootSystem32DRIVERSsrv.sys
    Loaded driver SystemRootSystem32Driversfastfat.SYS

    •  @kliss9 There are no corrupted entries in this ntbtlog. Please check your mail.

  • kliss9

    i hope i am not too late finding this. i cannot find any suspicious driver. any help would be great. Thanks!
    Loaded driver SystemRootsystem32DRIVERSGEARAspiWDM.sys
    Loaded driver SystemRootsystem32DRIVERSAcceler.sys
    Loaded driver SystemRootsystem32DRIVERSintelppm.sys
    Loaded driver SystemRootsystem32driverswmiacpi.sys
    Loaded driver SystemRootsystem32DRIVERSCmBatt.sys
    Loaded driver SystemRootsystem32DRIVERSAMPPAL.sys
    Loaded driver SystemRootsystem32driversCompositeBus.sys
    Loaded driver SystemRootsystem32DRIVERSAgileVpn.sys
    Loaded driver SystemRootsystem32DRIVERS rasl2tp.sys
    Loaded driver SystemRootsystem32DRIVERSndistapi.sys
    Loaded driver SystemRootsystem32DRIVERSndiswan.sys
    Loaded driver SystemRootsystem32DRIVERSraspppoe.sys
    Loaded driver SystemRootsystem32DRIVERSraspptp.sys
    Loaded driver SystemRootsystem32DRIVERSrassstp.sys
    Loaded driver SystemRootsystem32DRIVERSteefer2.sys
    Loaded driver SystemRootsystem32driversswenum.sys
    Loaded driver SystemRootsystem32driversumbus.sys
    Loaded driver SystemRootsystem32DRIVERSWDKMD.sys
    Did not load driver SystemRootSystem32driversvga.sys
    Loaded driver SystemRootsystem32DRIVERSusbhub.sys
    Loaded driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Did not load driver SystemRootSystem32DriversNDProxy.SYS
    Loaded driver SystemRootsystem32driversRTKVHD64.sys
    Loaded driver SystemRootsystem32driversksthunk.sys
    Loaded driver SystemRootsystem32DRIVERSIntcDAud.sys
    Loaded driver SystemRootsystem32DRIVERSusbccgp.sys
    Loaded driver SystemRootSystem32Driversusbvideo.sys
    Loaded driver SystemRootsystem32DRIVERSCtClsFlt.sys
    Loaded driver SystemRootsystem32DRIVERShidusb.sys
    Loaded driver SystemRootsystem32driverskbdhid.sys
    Loaded driver SystemRootsystem32DRIVERSmouhid.sys
    Loaded driver SystemRootsystem32DRIVERSmonitor.sys
    Loaded driver SystemRootsystem32driversluafv.sys
    Loaded driver SystemRootsystem32driversWudfPf.sys
    Loaded driver SystemRootsystem32DRIVERSlltdio.sys
    Loaded driver SystemRootsystem32DRIVERSnwifi.sys
    Loaded driver SystemRootsystem32DRIVERSndisuio.sys
    Loaded driver SystemRootsystem32DRIVERSrspndr.sys
    Loaded driver SystemRootsystem32DRIVERSTurboB.sys
    Loaded driver SystemRootsystem32DRIVERSvwifimp.sys
    Loaded driver ??C:Windowssystem32driversWpsHelper.sys
    Loaded driver SystemRootsystem32driversHTTP.sys
    Loaded driver SystemRootsystem32DRIVERSbowser.sys
    Loaded driver SystemRootSystem32driversmpsdrv.sys
    Loaded driver SystemRootsystem32DRIVERSmrxsmb.sys

  • Pascal

    This is a awesome and sharp article. I like it greatly

  • Sarah Tylor

    Just followed evrything you said.Everything is fine now.Finally I can sleep in peace
    Thanks Anup.

  • Scearce Nealey

    I chose pro service as I am neither good in following your instructions nor had the time to waste.Got my issue fixed.They were able to fix in less than 10mts.Thanks to redirectvirus removal team and thanks to you for taking the time to reach out and guide people like me

    cheers…

  • Alen Graeme

    Thanks!!!! google redirect virus gone now

  • Burlesque Brighton

    Anup,

    Thanks for the valuab;e suggestion.you were right bout the file.fixredirect team was really helpful.even they struggled,but got it removed using some advanced scan.glad the nigtmare is finally over

  • ken

    Hi i tried all of your suggestions and i still have the virus – maybe i have not correctly identified the virus in my ntbtlog.txt

    here is mine can you check it please.

    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rassstp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\RimSerial_AMD64.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mcdbus.sys
    Loaded driver \SystemRoot\system32\drivers\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\dtsoftbus01.sys
    Loaded driver \SystemRoot\system32\drivers\umbus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ew_jubusenum.sys
    Did not load driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\drivers\RTKVHD64.sys
    Loaded driver \SystemRoot\system32\drivers\ksthunk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\IntcDAud.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbccgp.sys
    Loaded driver \SystemRoot\System32\Drivers\usbvideo.sys
    Loaded driver \SystemRoot\system32\DRIVERS\hidusb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouhid.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lvuvc64.sys
    Loaded driver \SystemRoot\system32\drivers\usbaudio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lvrs64.sys
    Loaded driver \SystemRoot\system32\DRIVERS\monitor.sys
    Loaded driver \SystemRoot\system32\drivers\luafv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\Sftvollh.sys
    Loaded driver \SystemRoot\system32\drivers\WudfPf.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lltdio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nwifi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rspndr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\TurboB.sys
    Loaded driver \SystemRoot\system32\drivers\HTTP.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srvnet.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bowser.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv2.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv.sys
    Did not load driver \SystemRoot\System32\DRIVERS\srv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\avgidsfiltera.sys
    Loaded driver \SystemRoot\system32\drivers\peauth.sys
    Loaded driver \SystemRoot\System32\Drivers\secdrv.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\Sftfslh.sys
    Loaded driver \SystemRoot\system32\DRIVERS\Sftplaylh.sys
    Loaded driver \SystemRoot\System32\drivers\tcpipreg.sys
    Loaded driver \SystemRoot\system32\DRIVERS\avgidsdrivera.sys
    Loaded driver \SystemRoot\system32\DRIVERS\Sftredirlh.sys

    thank you so much for your time! :)

  • Issac Maez

    I just want to say, you are brilliant. The steps you mentioned here are some great genius sh** Having worked for Microsoft, I get the logic of what you trying to achieve here.You opened my eyes in a different way,I can use this idea/logic for fixing some other complicated stuffs.I will let you know the details soon,maybe you can write another topic on that. I really enjoyed you’re website.You really have outstanding articles. Thanks for sharing.

  • John Glenn

    These technical stuff is too complicated for me.Took professional help as you advised…..Hiya!!!!!!!!!!! got it fixed in first try. A week of pain eradicated in just under 4mts.you are a genius:-);-)

    God Bless you and Family

  • ted

    ANY SUGGESTIONS?:
    Microsoft (R) Windows (R) Version 6.1 (Build 7600)
    7 29 2012 16:06:01.375
    Loaded driver \SystemRoot\system32\ntoskrnl.exe
    Loaded driver \SystemRoot\system32\hal.dll
    Loaded driver \SystemRoot\system32\kdcom.dll
    Loaded driver \SystemRoot\system32\mcupdate_GenuineIntel.dll
    Loaded driver \SystemRoot\system32\PSHED.dll
    Loaded driver \SystemRoot\system32\CLFS.SYS
    Loaded driver \SystemRoot\system32\CI.dll
    Loaded driver \SystemRoot\system32\drivers\Wdf01000.sys
    Loaded driver \SystemRoot\system32\drivers\WDFLDR.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\ACPI.sys
    Loaded driver \SystemRoot\system32\DRIVERS\WMILIB.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\msisadrv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\pci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vdrvroot.sys
    Loaded driver \SystemRoot\system32\DRIVERS\isapnp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mpio.sys
    Loaded driver \SystemRoot\System32\drivers\partmgr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\compbatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\BATTC.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\volmgr.sys
    Loaded driver \SystemRoot\System32\drivers\volmgrx.sys
    Loaded driver \SystemRoot\system32\DRIVERS\intelide.sys
    Loaded driver \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\aliide.sys
    Loaded driver \SystemRoot\system32\DRIVERS\amdide.sys
    Loaded driver \SystemRoot\system32\DRIVERS\cmdide.sys
    Loaded driver \SystemRoot\System32\drivers\mountmgr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\msdsm.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nvraid.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\pciide.sys
    Loaded driver \SystemRoot\system32\DRIVERS\viaide.sys
    Loaded driver \SystemRoot\system32\DRIVERS\iaStorV.sys
    Loaded driver \SystemRoot\system32\DRIVERS\atapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ataport.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\lsi_sas.sys
    Loaded driver \SystemRoot\system32\DRIVERS\storport.sys
    Loaded driver \SystemRoot\system32\DRIVERS\msahci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HpSAMD.sys
    Loaded driver \SystemRoot\system32\DRIVERS\adp94xx.sys
    Loaded driver \SystemRoot\system32\DRIVERS\adpahci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\adpu320.sys
    Loaded driver \SystemRoot\system32\DRIVERS\amdsata.sys
    Loaded driver \SystemRoot\system32\DRIVERS\amdsbs.sys
    Loaded driver \SystemRoot\system32\DRIVERS\amdxata.sys
    Loaded driver \SystemRoot\system32\DRIVERS\arc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\arcsas.sys
    Loaded driver \SystemRoot\system32\DRIVERS\elxstor.sys
    Loaded driver \SystemRoot\system32\DRIVERS\iirsp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lsi_fc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lsi_sas2.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lsi_scsi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\megasas.sys
    Loaded driver \SystemRoot\system32\DRIVERS\MegaSR.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nfrd960.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nvstor.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ql2300.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ql40xx.sys
    Loaded driver \SystemRoot\system32\DRIVERS\SiSRaid2.sys
    Loaded driver \SystemRoot\system32\DRIVERS\sisraid4.sys
    Loaded driver \SystemRoot\system32\DRIVERS\stexstor.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vsmraid.sys
    Loaded driver \SystemRoot\system32\drivers\fltmgr.sys
    Loaded driver \SystemRoot\system32\drivers\fileinfo.sys
    Loaded driver \SystemRoot\System32\Drivers\Ntfs.sys
    Loaded driver \SystemRoot\System32\Drivers\msrpc.sys
    Loaded driver \SystemRoot\System32\Drivers\ksecdd.sys
    Loaded driver \SystemRoot\System32\Drivers\cng.sys
    Loaded driver \SystemRoot\System32\drivers\pcw.sys
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.sys
    Loaded driver \SystemRoot\system32\drivers\ndis.sys
    Loaded driver \SystemRoot\system32\drivers\NETIO.SYS
    Loaded driver \SystemRoot\System32\Drivers\ksecpkg.sys
    Loaded driver \SystemRoot\System32\drivers\tcpip.sys
    Loaded driver \SystemRoot\System32\drivers\fwpkclnt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\volsnap.sys
    Loaded driver \SystemRoot\System32\Drivers\spldr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\sbp2port.sys
    Loaded driver \SystemRoot\System32\drivers\rdyboost.sys
    Loaded driver \SystemRoot\System32\Drivers\mup.sys
    Loaded driver \SystemRoot\System32\drivers\hwpolicy.sys
    Loaded driver \SystemRoot\System32\DRIVERS\fvevol.sys
    Loaded driver \SystemRoot\system32\DRIVERS\disk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\system32\drivers\rdpencdd.sys
    Loaded driver \SystemRoot\system32\drivers\rdprefmp.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\tdx.sys
    Loaded driver \SystemRoot\system32\drivers\afd.sys
    Loaded driver \SystemRoot\System32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wfplwf.sys
    Loaded driver \SystemRoot\system32\DRIVERS\pacer.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vwififlt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Did not load driver \SystemRoot\system32\DRIVERS\serial.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\drivers\nsiproxy.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
    Loaded driver \SystemRoot\System32\drivers\discache.sys
    Loaded driver \SystemRoot\System32\Drivers\dfsc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\blbdrive.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tunnel.sys
    Loaded driver \SystemRoot\system32\DRIVERS\intelppm.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wmiacpi.sys
    Loaded driver \SystemRoot\System32\drivers\dxgkrnl.sys
    Loaded driver \SystemRoot\system32\DRIVERS\igdkmd64.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbuhci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\Rt64win7.sys
    Loaded driver \SystemRoot\system32\DRIVERS\athrx.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vwifibus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\SynTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CmBatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CompositeBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\serscan.sys
    Loaded driver \SystemRoot\system32\drivers\ksthunk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AgileVpn.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rassstp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\umbus.sys
    Did not load driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\drivers\CHDRT64.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CAXHWAZL.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CAX_DPV.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CAX_CNXT.sys
    Loaded driver \SystemRoot\system32\drivers\modem.sys
    Loaded driver \SystemRoot\system32\drivers\IntcHdmi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbccgp.sys
    Loaded driver \SystemRoot\System32\Drivers\usbvideo.sys
    Loaded driver \SystemRoot\system32\DRIVERS\monitor.sys
    Loaded driver \SystemRoot\system32\drivers\luafv.sys
    Loaded driver \SystemRoot\system32\drivers\WudfPf.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lltdio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nwifi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rspndr.sys
    Loaded driver \SystemRoot\system32\drivers\HTTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vwifimp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bowser.sys
    Loaded driver \SystemRoot\System32\drivers\mpsdrv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    Loaded driver \SystemRoot\system32\drivers\peauth.sys
    Loaded driver \SystemRoot\System32\Drivers\secdrv.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\srvnet.sys
    Loaded driver \SystemRoot\System32\drivers\tcpipreg.sys
    Loaded driver \SystemRoot\system32\DRIVERS\XAudio64.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv2.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv.sys
    Did not load driver \SystemRoot\System32\DRIVERS\srv.sys

  • Cynthia

    Hi. Followed your instructions but still have the redirect problem. I read somewhere that the wdmaud.drv (23KB) located in C:\WINDOWS\system32 and C:\WINDOWS\Driver Cache\i386\sp3.cab could be the culprit but it won’t let me delete it (I realize that a similar file with a different extension called wdmaud.sys (82KB) is a safe file that should not be deleted). The atapi.sys file in the Drivers folder is 95 KB so clearly there is a problem.

    Here is my ntbtlog.txt file. Please let me know if it looks okay and if there’s something else I can try. Going crazy! Thanks!

    Service Pack 3 7 29 2012 13:57:07.375
    Loaded driver \WINDOWS\system32\ntoskrnl.exe
    Loaded driver \WINDOWS\system32\hal.dll
    Loaded driver \WINDOWS\system32\KDCOM.DLL
    Loaded driver \WINDOWS\system32\BOOTVID.dll
    Loaded driver ACPI.sys
    Loaded driver \WINDOWS\system32\DRIVERS\WMILIB.SYS
    Loaded driver pci.sys
    Loaded driver isapnp.sys
    Loaded driver PCIIde.sys
    Loaded driver \WINDOWS\System32\Drivers\PCIIDEX.SYS
    Loaded driver intelide.sys
    Loaded driver MountMgr.sys
    Loaded driver ftdisk.sys
    Loaded driver dmload.sys
    Loaded driver dmio.sys
    Loaded driver PartMgr.sys
    Loaded driver VolSnap.sys
    Loaded driver atapi.sys
    Loaded driver disk.sys
    Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    Loaded driver fltMgr.sys
    Loaded driver sr.sys
    Loaded driver KSecDD.sys
    Loaded driver Ntfs.sys
    Loaded driver NDIS.sys
    Loaded driver Mup.sys
    Loaded driver avgrkx86.sys
    Loaded driver avgidshx.sys
    Loaded driver \SystemRoot\system32\DRIVERS\intelppm.sys
    Loaded driver \SystemRoot\System32\DRIVERS\ati2mtag.sys
    Loaded driver \SystemRoot\System32\DRIVERS\b57xp32.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbuhci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\System32\DRIVERS\IntelC53.sys
    Loaded driver \SystemRoot\System32\DRIVERS\IntelC51.sys
    Loaded driver \SystemRoot\System32\DRIVERS\IntelC52.sys
    Loaded driver \SystemRoot\System32\DRIVERS\mohfilt.sys
    Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
    Loaded driver \SystemRoot\system32\drivers\smwdm.sys
    Loaded driver \SystemRoot\system32\drivers\aeaudio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\fdc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\parport.sys
    Loaded driver \SystemRoot\system32\DRIVERS\serial.sys
    Loaded driver \SystemRoot\system32\DRIVERS\serenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys
    Loaded driver \SystemRoot\system32\drivers\Afc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
    Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys
    Loaded driver \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\psched.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rdpdr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\update.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Loaded driver \SystemRoot\system32\drivers\MODEMCSA.sys
    Loaded driver \SystemRoot\system32\DRIVERS\flpydisk.sys
    Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
    Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
    Did not load driver \SystemRoot\System32\Drivers\i2omgmt.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\avgmfx86.sys
    Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\usbccgp.sys
    Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\avgtdix.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\System32\drivers\afd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\usbprint.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HPZius12.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HPZid412.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HPZipr12.sys
    Loaded driver \SystemRoot\system32\DRIVERS\avgldx86.sys
    Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
    Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
    Loaded driver \SystemRoot\system32\drivers\splitter.sys
    Loaded driver \SystemRoot\system32\drivers\aec.sys
    Loaded driver \SystemRoot\system32\drivers\swmidi.sys
    Loaded driver \SystemRoot\system32\drivers\DMusic.sys
    Loaded driver \SystemRoot\system32\drivers\kmixer.sys
    Loaded driver \SystemRoot\system32\drivers\drmkaud.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys
    Loaded driver \SystemRoot\System32\Drivers\ParVdm.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\avgidsshimx.sys
    Loaded driver \SystemRoot\system32\DRIVERS\srv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\avgidsfilterx.sys
    Loaded driver \SystemRoot\system32\DRIVERS\avgidsdriverx.sys
    Did not load driver \SystemRoot\system32\DRIVERS\ipnat.sys
    Loaded driver \SystemRoot\System32\Drivers\HTTP.sys
    Loaded driver \SystemRoot\system32\drivers\kmixer.sys

  • Sarah

    Hello. I’ve been trying to get rid of this thing for a few weeks, but I haven’t had any success. You said that a good way to tell an infection apart from a legitimate .sys was to look at the name, but all the names look nonsensical to me. I’m sorry to be a bother, but I found nothing after following your instructions. I tried scanning with free Malwarebytes and free AVG before. Could you please help me look for anything that shouldn’t be there?

    [Also, I never get directed to Hapili or Nginx. I get sent to sites that start with a string of numbers, usually. When I click the back button, I see that I usually get sent through something like get-click-answers-fast and butterflysearch. I’ve been looking around on the internet for help, and no one I’ve seen with a redirect problem has mentioned my specific redirects. I hope that helps.]

    Microsoft (R) Windows (R) Version 6.1 (Build 7600)
    7 28 2012 21:37:30.375
    Loaded driver \SystemRoot\system32\ntoskrnl.exe
    Loaded driver \SystemRoot\system32\hal.dll
    Loaded driver \SystemRoot\system32\kdcom.dll
    Loaded driver \SystemRoot\system32\mcupdate_AuthenticAMD.dll
    Loaded driver \SystemRoot\system32\PSHED.dll
    Loaded driver \SystemRoot\system32\CLFS.SYS
    Loaded driver \SystemRoot\system32\CI.dll
    Loaded driver \SystemRoot\system32\drivers\Wdf01000.sys
    Loaded driver \SystemRoot\system32\drivers\WDFLDR.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\ACPI.sys
    Loaded driver \SystemRoot\system32\DRIVERS\WMILIB.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\msisadrv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\pci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vdrvroot.sys
    Loaded driver \SystemRoot\System32\drivers\partmgr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\compbatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\BATTC.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\volmgr.sys
    Loaded driver \SystemRoot\System32\drivers\volmgrx.sys
    Loaded driver \SystemRoot\System32\drivers\mountmgr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\atapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ataport.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\msahci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
    Loaded driver \SystemRoot\system32\drivers\amdxata.sys
    Loaded driver \SystemRoot\system32\drivers\fltmgr.sys
    Loaded driver \SystemRoot\system32\drivers\fileinfo.sys
    Loaded driver \SystemRoot\System32\Drivers\Ntfs.sys
    Loaded driver \SystemRoot\System32\Drivers\msrpc.sys
    Loaded driver \SystemRoot\System32\Drivers\ksecdd.sys
    Loaded driver \SystemRoot\System32\Drivers\cng.sys
    Loaded driver \SystemRoot\System32\drivers\pcw.sys
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.sys
    Loaded driver \SystemRoot\system32\drivers\ndis.sys
    Loaded driver \SystemRoot\system32\drivers\NETIO.SYS
    Loaded driver \SystemRoot\System32\Drivers\ksecpkg.sys
    Loaded driver \SystemRoot\System32\drivers\tcpip.sys
    Loaded driver \SystemRoot\System32\drivers\fwpkclnt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\volsnap.sys
    Loaded driver \SystemRoot\System32\Drivers\spldr.sys
    Loaded driver \SystemRoot\System32\drivers\rdyboost.sys
    Loaded driver \SystemRoot\System32\Drivers\mup.sys
    Loaded driver \SystemRoot\System32\drivers\hwpolicy.sys
    Loaded driver \SystemRoot\system32\DRIVERS\hpdskflt.sys
    Loaded driver \SystemRoot\System32\DRIVERS\fvevol.sys
    Loaded driver \SystemRoot\system32\DRIVERS\disk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\avgrkx64.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AVGIDSEH.Sys
    Loaded driver \SystemRoot\system32\DRIVERS\AtiPcie.sys
    Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
    Loaded driver \SystemRoot\system32\DRIVERS\avgmfx64.sys
    Loaded driver \SystemRoot\system32\drivers\NISx64\1200000.080\SRTSPX64.SYS
    Loaded driver
    Loaded driver
    Loaded driver \SystemRoot\system32\drivers\NISx64\1200000.080\SRTSP64.SYS
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\system32\drivers\rdpencdd.sys
    Loaded driver \SystemRoot\system32\drivers\rdprefmp.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\tdx.sys
    Loaded driver \SystemRoot\system32\DRIVERS\avgtdia.sys
    Loaded driver \SystemRoot\System32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\system32\drivers\afd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wfplwf.sys
    Loaded driver \SystemRoot\system32\DRIVERS\pacer.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vwififlt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\drivers\nsiproxy.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
    Loaded driver \SystemRoot\System32\drivers\discache.sys
    Loaded driver \SystemRoot\System32\Drivers\dfsc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\blbdrive.sys
    Loaded driver \SystemRoot\system32\DRIVERS\avgldx64.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tunnel.sys
    Loaded driver \SystemRoot\system32\DRIVERS\amdppm.sys
    Loaded driver \SystemRoot\system32\DRIVERS\atipmdag.sys
    Loaded driver \SystemRoot\System32\drivers\dxgkrnl.sys
    Loaded driver \SystemRoot\system32\DRIVERS\atikmpag.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bcmwl664.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vwifibus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\Rt64win7.sys
    Loaded driver \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbohci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbfilter.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\SynTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\Accelerometer.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CmBatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wmiacpi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CompositeBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wacomvhid.sys
    Loaded driver \SystemRoot\system32\DRIVERS\clwvd.sys
    Loaded driver \SystemRoot\system32\drivers\ksthunk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AgileVpn.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rassstp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\circlass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\umbus.sys
    Did not load driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouhid.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wacommousefilter.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\drivers\AtiHdmi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\stwrt64.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbccgp.sys
    Loaded driver \SystemRoot\System32\Drivers\usbvideo.sys
    Loaded driver \SystemRoot\system32\drivers\btwampfl.sys
    Loaded driver \SystemRoot\System32\Drivers\BTHUSB.sys
    Loaded driver \SystemRoot\System32\Drivers\fastfat.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rfcomm.sys
    Loaded driver \SystemRoot\system32\drivers\BthEnum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bthpan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\btwavdt.sys
    Loaded driver \SystemRoot\system32\drivers\btwaudio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\btwl2cap.sys
    Loaded driver \SystemRoot\system32\DRIVERS\btwrchid.sys
    Loaded driver \SystemRoot\system32\DRIVERS\monitor.sys
    Loaded driver \SystemRoot\system32\drivers\luafv.sys
    Loaded driver \SystemRoot\system32\drivers\WudfPf.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lltdio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nwifi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rspndr.sys
    Loaded driver \SystemRoot\system32\drivers\HTTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bowser.sys
    Loaded driver \SystemRoot\System32\drivers\mpsdrv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys
    Loaded driver \SystemRoot\system32\drivers\peauth.sys
    Loaded driver \SystemRoot\System32\Drivers\secdrv.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\srvnet.sys
    Loaded driver \SystemRoot\System32\drivers\tcpipreg.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv2.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv.sys
    Did not load driver \SystemRoot\System32\DRIVERS\srv.sys
    Loaded driver \SystemRoot\system32\drivers\MSPQM.sys
    Loaded driver \SystemRoot\system32\drivers\MSPCLOCK.sys

  • Great Gary

    i hate google redirect virus,but you rock man.i just fixed it,thnks to you.

  • a6fz3vjh.SYS definitely looks suspicious.Sometimes these files maynot be visible as it is superhidden. To remove such files, please try the steps in command prompt.

    Open command prompt in administrator mode
    attrib –r –h –a –s C:\Windows\system32\drievrs\a6fz3vjh.SYS (Please note, you need to type the location of your file. The attrib command removes the attributes of the file which help it to remain superhidden inside computer)
    del C:\Windows\system32\drievrs\a6fz3vjh.SYS

    Regarding “Nulls”, I have no idea. I guess it is the first time I am seeing this.My suggestion, remove the ntbtlog file and then restart which creates a new one.Check if the new one is better.

    Let me know if you need to know anything else.

    Good Luck

  • MARION

    Thanks Anup for the wonderful tutorial. I did try all the steps mentioned here, but I had to use the tool that you recommended to finally fix it. However, I appreciate the pain and effort that you took to explain everything wonderfully.My friend runs a tech shop and he too saw your article and follow the same. To him, your article was the best regarding google redirect virus issue and he is using it for his customers. People like you makes the world better place to live. Take care.

  • Lidija

    Hi First of all, thanks a lot for your great effort to help us here to get rid of Google redirect virus. I had followed your step-by-step instructions carefully, but, unfortunately, I didn’t find anything. However, I would like you to check my ntbtlog.txt, just in case you see something suspicious there:

    Loaded driver \WINDOWS\system32\ntoskrnl.exe
    Loaded driver \WINDOWS\system32\hal.dll
    Loaded driver \WINDOWS\system32\KDCOM.DLL
    Loaded driver \WINDOWS\system32\BOOTVID.dll
    Loaded driver ACPI.sys
    Loaded driver \WINDOWS\system32\DRIVERS\WMILIB.SYS
    Loaded driver pci.sys
    Loaded driver isapnp.sys
    Loaded driver pciide.sys
    Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    Loaded driver MountMgr.sys
    Loaded driver ftdisk.sys
    Loaded driver dmload.sys
    Loaded driver dmio.sys
    Loaded driver PartMgr.sys
    Loaded driver VolSnap.sys
    Loaded driver atapi.sys
    Loaded driver disk.sys
    Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    Loaded driver fltMgr.sys
    Loaded driver sr.sys
    Loaded driver PxHelp20.sys
    Loaded driver KSecDD.sys
    Loaded driver Ntfs.sys
    Loaded driver NDIS.sys
    Loaded driver uagp35.sys
    Loaded driver Mup.sys
    Loaded driver \SystemRoot\system32\DRIVERS\intelppm.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nv4_mini.sys
    Loaded driver \SystemRoot\system32\DRIVERS\fdc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\parport.sys
    Loaded driver \SystemRoot\system32\DRIVERS\serial.sys
    Loaded driver \SystemRoot\system32\DRIVERS\serenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\gameenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
    Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys
    Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys
    Loaded driver \SystemRoot\system32\drivers\smwdm.sys
    Loaded driver \SystemRoot\system32\drivers\aeaudio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbohci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\sisnic.sys
    Loaded driver \SystemRoot\system32\DRIVERS\IntelC53.sys
    Loaded driver \SystemRoot\system32\DRIVERS\IntelC51.sys
    Loaded driver \SystemRoot\system32\DRIVERS\IntelC52.sys
    Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\psched.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rdpdr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\update.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
    Loaded driver \SystemRoot\system32\drivers\MODEMCSA.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\flpydisk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
    Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
    Did not load driver \SystemRoot\System32\Drivers\i2omgmt.SYS
    Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
    Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Did not load driver \SystemRoot\system32\DRIVERS\kbdhid.sys
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys
    Loaded driver \SystemRoot\System32\Drivers\aswTdi.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\System32\Drivers\aswRdr.SYS
    Loaded driver \SystemRoot\System32\drivers\afd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
    Loaded driver \SystemRoot\System32\Drivers\aswSP.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\System32\Drivers\aswSnx.SYS
    Loaded driver \SystemRoot\System32\Drivers\Aavmker4.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\hidusb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdhid.sys
    Loaded driver \SystemRoot\System32\Drivers\Udfs.SYS
    Loaded driver \??\C:\WINDOWS\system32\drivers\mbam.sys
    Loaded driver \SystemRoot\System32\Drivers\aswFsBlk.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Loaded driver \SystemRoot\System32\Drivers\aswMon2.SYS
    Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys
    Loaded driver \SystemRoot\System32\Drivers\ParVdm.SYS
    Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
    Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
    Loaded driver \SystemRoot\system32\drivers\splitter.sys
    Loaded driver \SystemRoot\system32\drivers\aec.sys
    Loaded driver \SystemRoot\system32\drivers\swmidi.sys
    Loaded driver \SystemRoot\system32\drivers\DMusic.sys
    Loaded driver \SystemRoot\system32\drivers\kmixer.sys
    Loaded driver \SystemRoot\system32\drivers\drmkaud.sys
    Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\srv.sys
    Loaded driver \??\C:\CyberLink\PowerDVD11\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys
    Loaded driver \??\C:\CyberLink\PowerDVD11\PowerDVD11\Common\NavFilter00.fcl
    Did not load driver \SystemRoot\system32\DRIVERS\ipnat.sys
    Loaded driver \SystemRoot\System32\Drivers\HTTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipfltdrv.sys
    Loaded driver \SystemRoot\system32\drivers\kmixer.sys
    Loaded driver \SystemRoot\system32\drivers\kmixer.sys

    Also, when I check msinfo32 -> software environment -> loaded modules, what should I look for there, except for those viruses you’ve already mentioned?

    One more thing: when I had unchecked the option “hide protected operating system files”, some files appeared in C: partition. One of them is called hiberfil.sys and it is very huge file (1.24 GB). Is it some standard system file or not?

    tjThanks a lot once more, in advance :)
    All the best regards!

    • Hi Lidija,

      Went through the file list and couldn’t find any suspicious file in ntbtlog.txt.

      The files listed in loaded modules is the same as ntbtlog.txt. The reason to check loaded modules is cos sometimes the files which are not listed in ntbtlog.txt can be seen in loaded modules.I always make it a point to check both locations.

      Regarding hiberfil.sys, dont worry about that. It is the file responsible for virtual memory. Every computer will have a hiberfil.sys file.

      Hope you will be able to fix the issue. Let me know if you need to know anything else.

      Good Luck.

  • JOhn

    WWhat does it mean in the ntbtlog.txt when a driver is loaded but there isn’t one listed behind it, in otherwords it says Loaded Driver and then it is blank after this ?

    • I’ve seen this on other PCs in the past and surely it looked suspicious. The main suspicion was regarding any super hidden drivers getting loaded in the computer. But In the end, it proved nothing and we could not find any problem. So I assume it should not be a problem.

  • Marianne

    Thank you so much for this, fixed google redirect virus problem using the tool!
    Cheers!
    Marianne

  • Ismael Hongeva

    Thank you very much. Some virus has overidden the host file in my computer. Deleting that solved the problem.
    Thank you again.

  • jcd

    Thanks! finally got this bloody redirect off my computer, I’ve been using bing for almost a year!
    Thanks again!

  • Scottt

    thank you for this video……
    I discovered that the comment marks were removed from in front of my local host lines in the host file.

  • John Paul

    Hi Anup,

    I really need your help. I’m at my wit’s end trying to solve this problem. I have used freeware before and for a while the problem was gone but a week ago the redirect virus came back. It’s a bit more awful this time, the freeware can’t solve it anymore. I’ve tried following your instructions and for a while everything seemed to be going well until the moment I can’t find tdss, h8srt and _VOID on the ntbtlog.txt. Now I don’t really know which is the file causing the problem. Can you help me out? These are the ones I’ve found in the ntbtlog.txt.
    Microsoft (R) Windows (R) Version 6.1 (Build 7600)
    7 11 2012 16:53:54.109
    Loaded driver \SystemRoot\system32\ntkrnlpa.exe
    Loaded driver \SystemRoot\system32\halmacpi.dll
    Loaded driver \SystemRoot\system32\kdcom.dll
    Loaded driver \SystemRoot\system32\mcupdate_GenuineIntel.dll
    Loaded driver \SystemRoot\system32\PSHED.dll
    Loaded driver \SystemRoot\system32\BOOTVID.dll
    Loaded driver \SystemRoot\system32\CLFS.SYS
    Loaded driver \SystemRoot\system32\CI.dll
    Loaded driver \SystemRoot\system32\drivers\Wdf01000.sys
    Loaded driver \SystemRoot\system32\drivers\WDFLDR.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\ACPI.sys
    Loaded driver \SystemRoot\system32\DRIVERS\WMILIB.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\msisadrv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\pci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vdrvroot.sys
    Loaded driver \SystemRoot\System32\drivers\partmgr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\compbatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\BATTC.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\volmgr.sys
    Loaded driver \SystemRoot\System32\drivers\volmgrx.sys
    Loaded driver \SystemRoot\System32\drivers\mountmgr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\iaStor.sys
    Loaded driver \SystemRoot\system32\DRIVERS\atapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ataport.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\msahci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\amdxata.sys
    Loaded driver \SystemRoot\system32\drivers\fltmgr.sys
    Loaded driver \SystemRoot\system32\drivers\fileinfo.sys
    Loaded driver \SystemRoot\System32\Drivers\AsDsm.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lullaby.sys
    Loaded driver \SystemRoot\System32\Drivers\Ntfs.sys
    Loaded driver \SystemRoot\System32\Drivers\msrpc.sys
    Loaded driver \SystemRoot\System32\Drivers\ksecdd.sys
    Loaded driver \SystemRoot\System32\Drivers\cng.sys
    Loaded driver \SystemRoot\System32\drivers\pcw.sys
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.sys
    Loaded driver \SystemRoot\system32\drivers\ndis.sys
    Loaded driver \SystemRoot\system32\drivers\NETIO.SYS
    Loaded driver \SystemRoot\System32\Drivers\ksecpkg.sys
    Loaded driver \SystemRoot\System32\drivers\tcpip.sys
    Loaded driver \SystemRoot\System32\drivers\fwpkclnt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\epfwwfp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\volsnap.sys
    Loaded driver \SystemRoot\System32\Drivers\spldr.sys
    Loaded driver \SystemRoot\System32\drivers\rdyboost.sys
    Loaded driver \SystemRoot\System32\Drivers\mup.sys
    Loaded driver \SystemRoot\System32\drivers\hwpolicy.sys
    Loaded driver \SystemRoot\System32\DRIVERS\fvevol.sys
    Loaded driver \SystemRoot\system32\DRIVERS\disk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\dtsoftbus01.sys
    Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\ehdrv.sys
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\system32\drivers\rdpencdd.sys
    Loaded driver \SystemRoot\system32\drivers\rdprefmp.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\tdx.sys
    Loaded driver \SystemRoot\system32\drivers\afd.sys
    Loaded driver \SystemRoot\System32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wfplwf.sys
    Loaded driver \SystemRoot\system32\DRIVERS\pacer.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vwififlt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\EpfwLWF.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\drivers\nsiproxy.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
    Loaded driver \SystemRoot\System32\drivers\discache.sys
    Loaded driver \SystemRoot\System32\Drivers\dfsc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\blbdrive.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tunnel.sys
    Loaded driver \SystemRoot\System32\drivers\dxgkrnl.sys
    Loaded driver \SystemRoot\system32\DRIVERS\igdkmd32.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HECI.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\athw.sys
    Loaded driver \SystemRoot\system32\DRIVERS\jmcr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\JME.sys
    Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\Apfiltr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    Loaded driver \SystemRoot\system32\DRIVERS\Impcd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CmBatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\intelppm.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ATKACPI.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CompositeBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AgileVpn.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rassstp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\umbus.sys
    Did not load driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\drivers\CHDRT32.sys
    Loaded driver \SystemRoot\system32\DRIVERS\IntcDAud.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbccgp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\snp2uvc.sys
    Loaded driver \SystemRoot\system32\drivers\btusbflt.sys
    Loaded driver \SystemRoot\System32\Drivers\BTHUSB.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rfcomm.sys
    Loaded driver \SystemRoot\system32\drivers\BthEnum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bthpan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bthmodem.sys
    Loaded driver \SystemRoot\system32\drivers\modem.sys
    Loaded driver \SystemRoot\system32\DRIVERS\btwavdt.sys
    Loaded driver \SystemRoot\system32\drivers\btwaudio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\btwl2cap.sys
    Loaded driver \SystemRoot\system32\DRIVERS\btwrchid.sys
    Loaded driver \SystemRoot\system32\DRIVERS\monitor.sys
    Loaded driver \SystemRoot\system32\drivers\luafv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\eamonm.sys
    Loaded driver \SystemRoot\system32\drivers\WudfPf.sys
    Loaded driver \SystemRoot\system32\DRIVERS\epfw.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lltdio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nwifi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rspndr.sys
    Loaded driver \??\C:\Program Files\ASUS\ATK Package\ATKGFNEX\ASMMAP.sys
    Loaded driver \SystemRoot\system32\drivers\HTTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bowser.sys
    Loaded driver \SystemRoot\System32\drivers\mpsdrv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    Did not load driver \SystemRoot\system32\DRIVERS\parport.sys
    Loaded driver \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys
    Loaded driver \SystemRoot\system32\drivers\peauth.sys
    Loaded driver \SystemRoot\System32\Drivers\secdrv.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\srvnet.sys
    Loaded driver \SystemRoot\System32\drivers\tcpipreg.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv2.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv.sys
    Did not load driver \SystemRoot\System32\DRIVERS\srv.sys

    I’m sorry for the trouble but I will really appreciate your help. Thank you!

    • Hi John,

      Went through the entire list, but couldn’t find anything suspicious here. Couple of files that I doubted,later confirmed as from ASUS and ESET firewall. I am sure there is no infection related entries here.

      Hope you have done all the troubleshooting steps properly as mentioned in the video and article.Since the infection came back, it seems this time it might have got complicated and hiding deep inside operating system. These are situations where I genuinely wish if I could see and work on computer physically.Frankly, I am out of ideas here.Maybe use the pro help as mentioned in article.Hope that goes well.

      Thanks
      Anup

      • John Paul

        I see. I’ll try to follow your suggestion. Thanks a lot!

  • Levitra

    Hi Anup,

    I am completely dumb when it comes to computer.This so called infection got me too,but my cousin got rid of it.This is to thank you for the detailed video as my cousin said this really helped him to fix it.Hugs and Kisses Levi

  • Omar

    hello! I have gone through your steps and have finally reached the step where you look through the ntbtlog.txt, and well I think I found some that are suspicious, but I’m not sure. Could you please check the ones below! I would appreciate it greatly! thanks! Sorry that its so long.
    I’d like to point out N360502010.003\SYMDS.SYS

    Also my McAfee program keeps blocking a connection. I don’t know what it means, maybe that is the answer to my problem with the google redirect thing. Here are the ID and the name it detects.Any thoughts?

    ID Address: 69.43.161.166 (the last 3 numbers change occasionally.)
    Name: Rundll32

    Loaded driver \SystemRoot\system32\ntkrnlpa.exe
    Loaded driver \SystemRoot\system32\hal.dll
    Loaded driver \SystemRoot\system32\kdcom.dll
    Loaded driver \SystemRoot\system32\PSHED.dll
    Loaded driver \SystemRoot\system32\BOOTVID.dll
    Loaded driver \SystemRoot\system32\CLFS.SYS
    Loaded driver \SystemRoot\system32\CI.dll
    Loaded driver \SystemRoot\system32\drivers\Wdf01000.sys
    Loaded driver \SystemRoot\system32\drivers\WDFLDR.SYS
    Loaded driver \SystemRoot\system32\drivers\acpi.sys
    Loaded driver \SystemRoot\system32\drivers\WMILIB.SYS
    Loaded driver \SystemRoot\system32\drivers\msisadrv.sys
    Loaded driver \SystemRoot\system32\drivers\pci.sys
    Loaded driver \SystemRoot\System32\drivers\partmgr.sys
    Loaded driver \SystemRoot\system32\drivers\volmgr.sys
    Loaded driver \SystemRoot\System32\drivers\volmgrx.sys
    Loaded driver \SystemRoot\system32\drivers\pciide.sys
    Loaded driver \SystemRoot\system32\drivers\PCIIDEX.SYS
    Loaded driver \SystemRoot\System32\drivers\mountmgr.sys
    Loaded driver \SystemRoot\system32\drivers\atapi.sys
    Loaded driver \SystemRoot\system32\drivers\ataport.SYS
    Loaded driver \SystemRoot\system32\drivers\nvstor32.sys
    Loaded driver \SystemRoot\system32\drivers\storport.sys
    Loaded driver \SystemRoot\system32\drivers\fltmgr.sys
    Loaded driver \SystemRoot\system32\drivers\N360502010.003\SYMDS.SYS
    Loaded driver \SystemRoot\system32\drivers\fileinfo.sys
    Loaded driver \SystemRoot\system32\drivers\mfehidk.sys
    Loaded driver \SystemRoot\system32\drivers\N360502010.003\SYMEFA.SYS
    Loaded driver \SystemRoot\System32\Drivers\PxHelp20.sys
    Loaded driver \SystemRoot\System32\Drivers\ksecdd.sys
    Loaded driver \SystemRoot\system32\drivers\ndis.sys
    Loaded driver \SystemRoot\system32\drivers\msrpc.sys
    Loaded driver \SystemRoot\system32\drivers\NETIO.SYS
    Loaded driver \SystemRoot\System32\drivers\tcpip.sys
    Loaded driver \SystemRoot\System32\drivers\fwpkclnt.sys
    Loaded driver \SystemRoot\System32\Drivers\Ntfs.sys
    Loaded driver \SystemRoot\system32\drivers\volsnap.sys
    Loaded driver \SystemRoot\System32\Drivers\spldr.sys
    Loaded driver \SystemRoot\System32\Drivers\mup.sys
    Loaded driver \SystemRoot\System32\drivers\ecache.sys
    Loaded driver \SystemRoot\system32\drivers\disk.sys
    Loaded driver \SystemRoot\system32\drivers\CLASSPNP.SYS
    Loaded driver \SystemRoot\system32\drivers\crcdisk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tunnel.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tunmp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\amdk8.sys
    Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\PS2.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbohci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ohci1394.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSXHWBS2.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSX_DP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
    Loaded driver \SystemRoot\system32\drivers\modem.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nvmfdx32.sys
    Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
    Loaded driver \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    Loaded driver \SystemRoot\System32\drivers\dxgkrnl.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nvlddmkm.sys
    Loaded driver \SystemRoot\system32\DRIVERS\msiscsi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rassstp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
    Loaded driver \SystemRoot\system32\DRIVERS\umbus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\drivers\RTKVHDA.sys
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\system32\drivers\rdpencdd.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\rasacd.sys
    Loaded driver \SystemRoot\system32\drivers\mfetdik.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tdx.sys
    Loaded driver \SystemRoot\system32\drivers\mfewfpk.sys
    Loaded driver \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
    Loaded driver \SystemRoot\System32\Drivers\N360502010.003\SYMTDIV.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\smb.sys
    Loaded driver \SystemRoot\System32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\system32\drivers\afd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\pacer.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mfenlfk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\system32\drivers\N360502010.003\Ironx86.SYS
    Loaded driver \SystemRoot\system32\drivers\N360502010.003\SRTSPX.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\drivers\nsiproxy.sys
    Loaded driver
    Loaded driver \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    Loaded driver \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
    Loaded driver \SystemRoot\System32\Drivers\dfsc.sys
    Loaded driver
    Loaded driver \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    Loaded driver \SystemRoot\system32\drivers\mfeavfk.sys
    Loaded driver \SystemRoot\system32\drivers\mfefirek.sys
    Loaded driver \SystemRoot\system32\DRIVERS\monitor.sys
    Loaded driver \SystemRoot\system32\drivers\luafv.sys
    Loaded driver \SystemRoot\system32\drivers\drmkaud.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lltdio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rspndr.sys
    Loaded driver \SystemRoot\system32\drivers\HTTP.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srvnet.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bowser.sys
    Loaded driver \SystemRoot\System32\drivers\mpsdrv.sys
    Loaded driver \SystemRoot\system32\drivers\mrxdav.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv2.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv.sys
    Did not load driver \SystemRoot\System32\DRIVERS\srv.sys
    Did not load driver \SystemRoot\system32\drivers\parport.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    Loaded driver \SystemRoot\system32\drivers\peauth.sys
    Loaded driver \SystemRoot\System32\Drivers\secdrv.SYS
    Loaded driver \SystemRoot\System32\drivers\tcpipreg.sys
    Loaded driver \SystemRoot\system32\DRIVERS\xaudio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\WUDFRd.sys
    Did not load driver \SystemRoot\system32\drivers\mfeavfk.sys
    Loaded driver \Device\mfeavfk01.sys
    Loaded driver \SystemRoot\system32\drivers\mfeapfk.sys
    Loaded driver \SystemRoot\system32\drivers\mfebopk.sys
    Loaded driver \SystemRoot\system32\drivers\cfwids.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tunnel.sys
    Did not load driver \SystemRoot\system32\drivers\N360502010.003\SRTSPX.SYS
    Loaded driver
    Loaded driver
    Loaded driver \SystemRoot\System32\Drivers\N360502010.003\SRTSP.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\cdfs.sys

    • Went through the entire list, but didnt find anything suspicious. N360502010.003\SYMDS.SYS seems to be a file from Norton 360 which you might have installed before.There are multiple instances of N360502010.003 files listed here which is strange. Since you use McAfee, I assume that you don’t use N360 anymore. Please remove N360 properly from computer.You can get uninstallation tools for N360 from symantec website. Also it will be nice to re-install McAfee if you can,as presence of N360 might have created compatibility issues.

      The problem in your computer reminds me of one single issue I handled a long time back.The client had some N360 files in computer which he could not remove properly.I removed it using uninstallation tools and some manual steps.Once I did that,the redirection was completely fixed.I dont think rogue N360 files can somehow create redirects.But in this case, to this day I dont have any explanation.

      • Ronin

        Your professional service is very fast and effective.Thanks for guiding me properly.

  • Andrew Daine

    Thanks to your pro tool. It fixed it.

  • Gary Gratious

    Thanks for your recommendation.Easy to use tools and issue fixed within 10mts.
    Jesus be with you.

  • Mariann Porcaro

    No offense, but too technical for me to follow your video.I went for your tools and got it fixed. Anyways a heartfelt gratitude from me and my family.We been living with this bloody thing for 2 weeks and now it feels like finally the haunting is over.

  • Michele Nista

    Very nice tutorial. Got it fixed by fixredirect tool.
    A Big Hug to U!!!!!!!!!!!!!!

  • Anup,

    Hello. By following the protocol you outline here in your blog would I be able to delete “Blekko” from my laptop? I have tried using Malwarebytes, SUPERAntiSpyWare, CC Cleaner, etc. without any luck. I only have the problem in IE…not Safari or FireFox. Blekko just keeps taking over as the default homepage on IE. Any suggestions you might have are most welcome and appreciated.

    Thank you.

    Gary

    • Yes, you can try the steps mentioned here to remove this infection. Also make sure to do an IE optimisation http://atechjourney.com/how-to-do-a-complete-internet-explorer-optimization.html/ which is very important.

      • Anup,

        Thank you for the extremely quick reply. I will definitely give this a shot and keep you updated. This Blekko seems to be SO very difficult to get rid of. I also noticed that at the same time I somehow was unfortunate enough to have Babylon as well. Deleting and removing Babylon has been simple. I will definitely work on implementing all of your tips and tricks for removing Blekko. Again, thank you.

        Gary

  • Davis Holliday

    Thank you for fixing the biggest headache I ever had in my computer.
    Your tool helped me fix the issue.Next time I know where to look for if I have to fix any issues.Nice job.

  • Admin,

    Help, I have tried everything from the forums. I’m now looking at the ntbtlog file and have no idea what is supposed to be there Can you go through this log and help me out I have no idea what to look for. If there is an infection it is supposed to be here?
    Loaded driver \SystemRoot\system32\ntoskrnl.exe
    Loaded driver \SystemRoot\system32\hal.dll
    Loaded driver \SystemRoot\system32\kdcom.dll
    Loaded driver \SystemRoot\system32\mcupdate_GenuineIntel.dll
    Loaded driver \SystemRoot\system32\PSHED.dll
    Loaded driver \SystemRoot\system32\CLFS.SYS
    Loaded driver \SystemRoot\system32\CI.dll
    Loaded driver \SystemRoot\system32\drivers\Wdf01000.sys
    Loaded driver \SystemRoot\system32\drivers\WDFLDR.SYS
    Loaded driver \SystemRoot\system32\drivers\ACPI.sys
    Loaded driver \SystemRoot\system32\drivers\WMILIB.SYS
    Loaded driver \SystemRoot\system32\drivers\msisadrv.sys
    Loaded driver \SystemRoot\system32\drivers\pci.sys
    Loaded driver \SystemRoot\system32\drivers\vdrvroot.sys
    Loaded driver \SystemRoot\System32\drivers\partmgr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\compbatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\BATTC.SYS
    Loaded driver \SystemRoot\system32\drivers\volmgr.sys
    Loaded driver \SystemRoot\System32\drivers\volmgrx.sys
    Loaded driver \SystemRoot\System32\drivers\mountmgr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\iaStor.sys
    Loaded driver \SystemRoot\system32\drivers\amdxata.sys
    Loaded driver \SystemRoot\system32\drivers\fltmgr.sys
    Loaded driver \SystemRoot\system32\drivers\fileinfo.sys
    Loaded driver \SystemRoot\System32\Drivers\PxHlpa64.sys
    Loaded driver \SystemRoot\System32\Drivers\Ntfs.sys
    Loaded driver \SystemRoot\System32\Drivers\msrpc.sys
    Loaded driver \SystemRoot\System32\Drivers\ksecdd.sys
    Loaded driver \SystemRoot\System32\Drivers\cng.sys
    Loaded driver \SystemRoot\System32\drivers\pcw.sys
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.sys
    Loaded driver \SystemRoot\system32\drivers\ndis.sys
    Loaded driver \SystemRoot\system32\drivers\NETIO.SYS
    Loaded driver \SystemRoot\System32\Drivers\ksecpkg.sys
    Loaded driver \SystemRoot\System32\drivers\tcpip.sys
    Loaded driver \SystemRoot\System32\drivers\fwpkclnt.sys
    Loaded driver \SystemRoot\system32\drivers\volsnap.sys
    Loaded driver \SystemRoot\System32\Drivers\spldr.sys
    Loaded driver \SystemRoot\System32\drivers\rdyboost.sys
    Loaded driver \SystemRoot\System32\Drivers\mup.sys
    Loaded driver \SystemRoot\System32\drivers\hwpolicy.sys
    Loaded driver \SystemRoot\System32\DRIVERS\fvevol.sys
    Loaded driver \SystemRoot\system32\DRIVERS\disk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
    Loaded driver \SystemRoot\system32\drivers\cdrom.sys
    Loaded driver \SystemRoot\system32\DRIVERS\RsFx0103.sys
    Loaded driver \SystemRoot\System32\Drivers\aswSnx.SYS
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\system32\drivers\rdpencdd.sys
    Loaded driver \SystemRoot\system32\drivers\rdprefmp.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\tdx.sys
    Loaded driver \SystemRoot\System32\Drivers\aswTdi.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\system32\drivers\afd.sys
    Loaded driver \SystemRoot\System32\Drivers\aswrdr2.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wfplwf.sys
    Loaded driver \SystemRoot\system32\DRIVERS\pacer.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vwififlt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\system32\drivers\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\drivers\nsiproxy.sys
    Loaded driver \SystemRoot\system32\drivers\mssmbios.sys
    Loaded driver \SystemRoot\System32\drivers\discache.sys
    Loaded driver \SystemRoot\System32\Drivers\dfsc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\blbdrive.sys
    Loaded driver \SystemRoot\System32\Drivers\aswSP.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\tunnel.sys
    Loaded driver \SystemRoot\System32\drivers\dxgkrnl.sys
    Loaded driver \SystemRoot\system32\DRIVERS\igdkmd64.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbuhci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\system32\drivers\HDAudBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bcmwl664.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vwifibus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\yk62x64.sys
    Loaded driver \SystemRoot\system32\drivers\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\Apfiltr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\drivers\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CmBatt.sys
    Loaded driver \SystemRoot\system32\drivers\wmiacpi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\intelppm.sys
    Loaded driver \SystemRoot\system32\drivers\CompositeBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AgileVpn.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rassstp.sys
    Loaded driver \SystemRoot\system32\drivers\swenum.sys
    Loaded driver \SystemRoot\system32\drivers\umbus.sys
    Did not load driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\stwrt64.sys
    Loaded driver \SystemRoot\system32\drivers\ksthunk.sys
    Loaded driver \SystemRoot\System32\Drivers\RtsUStor.sys
    Loaded driver \SystemRoot\system32\DRIVERS\monitor.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbccgp.sys
    Loaded driver \SystemRoot\System32\Drivers\usbvideo.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CtClsFlt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\PTDUBus.sys
    Loaded driver \SystemRoot\system32\DRIVERS\PTDUMdm.sys
    Loaded driver \SystemRoot\system32\drivers\modem.sys
    Loaded driver \SystemRoot\system32\DRIVERS\PTDUVsp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\PTDUWWAN.sys
    Loaded driver \SystemRoot\system32\DRIVERS\PTDUWFLT.sys
    Loaded driver \SystemRoot\system32\drivers\luafv.sys
    Loaded driver \??\C:\Windows\system32\drivers\aswMonFlt.sys
    Loaded driver \SystemRoot\System32\Drivers\aswFsBlk.SYS
    Loaded driver \SystemRoot\system32\drivers\WudfPf.sys
    Loaded driver \SystemRoot\system32\DRIVERS\lltdio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nwifi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rspndr.sys
    Loaded driver \SystemRoot\system32\DRIVERS\vwifimp.sys
    Loaded driver \SystemRoot\system32\drivers\HTTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bowser.sys
    Loaded driver \SystemRoot\System32\drivers\mpsdrv.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    Loaded driver \SystemRoot\system32\drivers\peauth.sys
    Loaded driver \SystemRoot\System32\Drivers\secdrv.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\srvnet.sys
    Loaded driver \SystemRoot\System32\drivers\tcpipreg.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv2.sys
    Loaded driver \SystemRoot\System32\DRIVERS\srv.sys
    Did not load driver \SystemRoot\System32\DRIVERS\srv.sys
    Loaded driver \SystemRoot\System32\Drivers\fastfat.SYS
    Loaded driver \??\C:\PROGRA~2\VERIZO~1\VZACCE~1\SMSIVZAM5X64.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\asyncmac.sys
    Loaded driver \SystemRoot\system32\drivers\25421259.syse.

    • That was huge. Checked the names.Didnt find anything suspicious other than the last one 25421259.syse.

      Is it 25421259.syse. or 25421259.sys? Since the file name is just some random numbers, this may or maynot be an infected file.Search for this file name in registry and I am sure it will help you to determine if it’s a valid file or not.

      If everything is done properly and still not able to fix, try fixing this problem using software. My suggestion is based on the fact that I dont see any suspicious file in ntbtlog.txt except the last one that I mentioned and also hoping that you have properly done all the other troubleshooting mentioned in the video.

      Let me know the result.Good Luck

  • John Cook

    Forgot to mention. I ran Norton and it found no viruses.

  • John Cook

    My Google search is not being redirected but, it is not working either. When I start typing letter, the intellisense starts making suggestion, regardless if I click on one of the suggestions and then press enter or double click it, it does not do anything, it just sits there. Even if I type the whole phrase and click on the search button it does nothing. Any help? Thanks for taking the time to help.

    JC

  • Sammy

    Dear Anup,
    Thanks for your prompt response. I thought I did the manual troubleshooting correctly but I guess I must have missed some infected files which I didn’t recognise as infected. The virus did seem to disappear but was back again once I rebooted. I gave up and took my laptop to the deskside support team at work. They also tried to remove the virus without any joy and I ended up having a complete system refresh! It’s finally gone but knowing my luck I’ll probably end up with the virus again because I don’t know how I got it in the first place… so I don’t know what to avoid :(
    Thank you for your useful tips and advice. I’ve bookmarked your articles/blog for future reference!

  • Sammy

    Dear Anup, I have the annoying ‘easyA-Z.com’ Google redirect virus on my laptop and I can’t get rid of it. I’ve run Symantec anti-virus, Malwarebytes, Hitman Pro, SuperAntiSpyware and CClean several times and after the initial scan no threats were found. Is there anything else you can suggest for this particular virus please? I also followed your manual steps above but no joy.

    • Sammy,

      From the list of tools that you used, without doubt you have done everything right.I hope you have done the manual troubleshooting properly cos if you got it wrong,the issue might come back.Manual troubleshooting is very effective,but chances of missing out infected files is very high.My final suggestion is to use the professional service offered for removing google redirect virus.The good part is you can claim a refund, if in case if it failed to fix your problem.It is far better than taking to a tech shop and get it fixed.

      Let me know if it helped.

  • Jason

    Thank you so much for this great article i have been having many problems with these google redirect viruses on my computer they have been infecting a lot of my work and its very bad thank you very much

  • Staci

    Hi there! Your information helped out a ton! Unfortunately for me, your deleting tips didn’t work. In my case, Norton Internet Security was the one behind the virus, and in the end we had to completely uninstall them. It all began when I stopped my service with them about a week ago. Then today they had me restart my computer. Right after the restart is when the “redirecting” started happening. I found an entire file folder full of bad files from them. Be aware NIS users!! NISx64 was the file folder name to look out for!!

  • Markus

    I have struggled with this problem for a couple of days now without resolution (having tried everything mentioned). One interesting tidbit I thought I would throw in is that the problem can be gotten around (for google anyway) pretty simply. The virus seems to only look for the http://www.google.com url in the browser, if I type in say http://www.google.com/search?hl=en&source=hp&q=south+lyon+hotel&gbv=1, which is a previously good google search, the search works and from the google page that comes up I can successfully search other topics. I stumbled on this today and I thought is was significant because the virus clearly looks for a very specific url to attack. Any insights?

    • :-) strange work around. I tried this a long time back and it didn’t worked that time and so never tried it again. Maybe this is just happening on your PC and cannot be standardized based on this experience. However, let me work with some infected PC’s. The result will help us in understanding if this is a valid work around for this issue.

      Anyway, it is clear this is only a work around and not a complete fix to this problem.

      Meanwhile, I invite comments from people who tried this and would like to hear the results from you.

  • I’m not sure where you are getting your info, but great topic. I needs to spend some time learning more or understanding more. Thanks for wonderful information I was looking for this info for my mission.

  • Everything is very open with a precise description of the challenges. It was truly informative. Your website is very useful. Thanks for sharing!

  • Katt

    Thank you!

  • Katt

    I found this in my “non-plug and play drivers” area: MpKsld18f9a41
    That doesn’t look normal, but I can’t find anything on it when I type the name into any search engines and I’m afraid of uninstalling something important on my computer. When I click on it, the information says that the publisher and location are unknown. Am I good to uninstall this?

    • “MpKsld18f9a41″ seems to be a file from Microsoft Antimalware updates which are sent regularly.The random numbers that you see in the file name keeps changing after each update. This is a good file and don’t need to be deleted unless Microsoft Antimalware update is creating some problem.
      When you get strange file names like these, it is better to use the first few letters of the file name and then search in google.cos the later part might have been randomly created.

  • Chan Shillingford

    Great post. Thanks for the info.

  • Superb article. Cool.

  • Shubert

    detected a sys file in system32 folder.struggled a bit, but i finally figured it out. this articles is really great : D. helped me out a lot, cheers

  • Efren Caller

    Wonderful posting. Remember to keep up the very really good performance.

  • Glad…it helped :-)

  • andymcdaniels

    I don’t have a tddss.sys entry anywhere in my registry. At all. I know how to look for it. I’ve been in the ntbtlogs in the device manager hidden files, all over system32, nothing. And this virus is killing my computer fast. I did find something called tdx.sys that comes up frequently in the ntbtlog but never in the device manager. I can’t find anything that goes by the other names for this virus, either. I don’t know what to do. I used malwarebytes and it found them, proclaimed to remove them, then they came back and nothing I use, not even tddskiller. I’m completely exhausted of options. Please help!

    • Apologize if this reply came late.

      I dont think tdx.sys is an infected file.It must be a driver related file. Check for other files with weird names. like combination of letters and numbers which dont make any sense.
      Did you try the Hitman Pro? Try it and let me know the details.

  • Will

    Made it all the way to step 5 easily, however, I don’t have any entries with such names, but I do have the virus. I don’t know how to fix it now, but I guess I will continue to look for a fix. Thanks for all the help you could give.

    Good thing I can outsmart this virus by using my mouse to open links.

    • These are some of the names that I gave here. TDSSmain.dll, _VOIDaabmetnqbf.sys, H8SRTnfvywoxwtx.sys. The virus might come with lot of other names. If you look at these names, it is weird and that is how you identify that this might be a suspicious file.
      Check msinfo32 -> Software environment –> loaded modules. Check that list. It might help, if there is any infected file loaded.
      Also check the size of atapi.sys file in c:\windows\system32\drivers folder. If the size is more than a 100KB, that is the infected file. Try to replace it.

  • Brett Jaillet

    Do you know your blog is suggested by a number of other blogs? Nice stuff. Thank you very much!

  • hey this is my first time visiting this site but it looks good so far, not just another drone blog lol.

  • Anwar

    hi!,I really like your writing very so much! percentage we keep up a correspondence more approximately your article on AOL? I require a specialist on this area to resolve my problem. May be that is you! Looking ahead to peer you.

  • Colin

    I just tried to use all of your steps, I did not have any TDSSserv.sys, H8SRTnfvywoxwtx.sys, or _VOIDaabmetnqbf.sys. So I am kind of dead in the water here. No fix yet.

    • Colin, sorry to hear that.

      There should be something inside. Apart from ntbtlog file, do check msinfo32 -> Software environment –> loaded modules. Check that list. It might help.
      Also check the size of atapi.sys file in c:\windows\system32\drivers folder. If the size is more than a 100KB, that is the infected file. Try to replace it.
      I hope you already tried different free tools to get rid of the infection.

      Let me know how it went.Good luck.

  • Stieger

    Only a smiling visitor here to share the love (:, btw great design .

  • Gjerde

    Youre so cool! I dont suppose Ive learn anything like this before. So good to seek out any person with some authentic thoughts on this subject. realy thanks for beginning this up. this web site is one thing that’s wanted on the internet, somebody with slightly originality. helpful job for bringing something new to the web!

  • Derek

    Bloody Fantastic…. It worked ;-);-)

  • Clive Rodriguez

    First of all….loved the way of explaining things. I am not much of a techy, but your suggestion to use the virus removal tool worked for me.Just thought of informing you.Good Job with your site.Merry X’mas and a happy yr in advance

    • Anup

      @Clive good to see that your issue is fixed and thanks for the feedback. Enjoy a great Christmas and have a great year ahead.

      @Nisha @Cynthia — Yes, I am planning to put on a video. Will do that as soon as I get time… Good to know the issues are fixed.

      @John Thanks for the feedback

  • Nisha Patel

    Agree with Cynthia…please add a video.I am totally lost after reading these steps.But I am sure you did a great job in helping people.

  • John of arc

    I like Your Article about Google redirect virus – Remove Manually Perfect just what I was searching for! :-)

  • Cynthia Estefan

    Hi Anup,
    Thanks for the wonderful article and guidance. The steps you mentioned is a bit complicated for a dumb computer user like me. I am sure these steps might have helped others.It would have been helpful for people like me, if you had a vidoe describing what you said.

    As you suggested, I got this damn issue sorted out finally with fixredirectvirus.org fixed.

  • search engine virus

    I like the helpful information you supply on your articles. I will bookmark your blog and check again here frequently. I’m fairly certain I will be informed lots of new stuff right right here! Best of luck for the next!

  • Jason Smith

    This is wonderful. None of the tools helped me in fixing, but manually I managed to remove it. Bit complicated though.Thanks for your help

    Good job!!!!!!!!!!

    • Anup

      Good to know it worked….. :-)