• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 07:02
CET 13:02
KST 21:02
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 3 - Playoffs Preview0RSL Season 3 - RO16 Groups C & D Preview0RSL Season 3 - RO16 Groups A & B Preview2TL.net Map Contest #21: Winners12Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10
Community News
Weekly Cups (Nov 24-30): MaxPax, Clem, herO win2BGE Stara Zagora 2026 announced15[BSL21] Ro.16 Group Stage (C->B->A->D)4Weekly Cups (Nov 17-23): Solar, MaxPax, Clem win3RSL Season 3: RO16 results & RO8 bracket13
StarCraft 2
General
Chinese SC2 server to reopen; live all-star event in Hangzhou Maestros of the Game: Live Finals Preview (RO4) BGE Stara Zagora 2026 announced Weekly Cups (Nov 24-30): MaxPax, Clem, herO win SC2 Proleague Discontinued; SKT, KT, SGK, CJ disband
Tourneys
Sparkling Tuna Cup - Weekly Open Tournament RSL Offline Finals Info - Dec 13 and 14! StarCraft Evolution League (SC Evo Biweekly) Sea Duckling Open (Global, Bronze-Diamond) $5,000+ WardiTV 2025 Championship
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 502 Negative Reinforcement Mutation # 501 Price of Progress Mutation # 500 Fright night Mutation # 499 Chilling Adaptation
Brood War
General
The top three worst maps of all time Foreign Brood War BGH Auto Balance -> http://bghmmr.eu/ Data analysis on 70 million replays BW General Discussion
Tourneys
Small VOD Thread 2.0 [Megathread] Daily Proleagues [BSL21] RO16 Group D - Sunday 21:00 CET [BSL21] RO16 Group A - Saturday 21:00 CET
Strategy
Current Meta Game Theory for Starcraft How to stay on top of macro? PvZ map balance
Other Games
General Games
Nintendo Switch Thread Stormgate/Frost Giant Megathread Path of Exile ZeroSpace Megathread The Perfect Game
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Mafia Game Mode Feedback/Ideas TL Mafia Community Thread
Community
General
European Politico-economics QA Mega-thread US Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread The Big Programming Thread
Fan Clubs
White-Ra Fan Club
Media & Entertainment
Anime Discussion Thread [Manga] One Piece Movie Discussion!
Sports
2024 - 2026 Football Thread Formula 1 Discussion
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
Where to ask questions and add stream? The Automated Ban List
Blogs
I decided to write a webnov…
DjKniteX
Physical Exertion During Gam…
TrAiDoS
James Bond movies ranking - pa…
Topin
Thanks for the RSL
Hildegard
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1468 users

Virus/Trojan Redirects Internet

Blogs > micronesia
Post a Reply
micronesia
Profile Blog Joined July 2006
United States24745 Posts
February 17 2009 04:54 GMT
#1
So I've been pretty lucky about not letting bad stuff happen to my computer... but one day after running all that defensive software recommended in the thread http://www.teamliquid.net/forum/viewmessage.php?topic_id=87753 I noticed this happening:

1)
  • Type ravenholm into google
  • Click on the first hit (wikipedia article)
  • Get redirected to http://www.manga.com/?ref=AW2396753 or some other dumb site


2)
  • Type fios into google
  • Click on the first hit (verizon website)
  • Get redirected to http://www.mamma.com/Mamma?query=fios or some porn website and end up at the correct website another time...


For a goof I tried another search (smith) and ended up at the smith college website as you might expect...

I brought up my McAfee console for the first time ever (free antivirus crap I got from my university) and manually updated the definitions or whatever the deal is, and am running a scan on my system. It said:

autorun.inf
location: c:\
detected as: Generic!atr
Type: Trojan
Status: No Action Taken (Delete Failed)

So I'm trying to decide how I can aid the software in cleaning it... I tried looking for the file manually, but even after I showed hidden files, there was no autorun.inf there

The timing of this is truly ironic. Maybe adaware is malware!

*****
ModeratorThere are animal crackers for people and there are people crackers for animals.
SpiritoftheTunA
Profile Blog Joined August 2006
United States20903 Posts
February 17 2009 04:58 GMT
#2
try combofix, itslike fucking magic
posting on liquid sites in current year
ssj114
Profile Blog Joined September 2008
Afghanistan461 Posts
February 17 2009 04:59 GMT
#3
http://remove-malware.com/videos/how-to-remove-malware-for-free-video/
Sandboxie + SUA + DEP, Windows Firewall + NAT Router
Binky1842
Profile Blog Joined July 2004
United States2599 Posts
February 17 2009 05:12 GMT
#4
google the name of the detected file, in your case Generic!atr, and follow the help the search hits provide you.
keep your definition up to date >.<

i hope that's what youre asking for anyways. GL
"The zoo could not confirm that Binky was the attacker, but only Binky had blood on his face following the incident"
SpiritoftheTunA
Profile Blog Joined August 2006
United States20903 Posts
February 17 2009 05:15 GMT
#5
On February 17 2009 14:12 Binky1842 wrote:
google the name of the detected file, in your case Generic!atr, and follow the help the search hits provide you.
keep your definition up to date >.<

i hope that's what youre asking for anyways. GL

generic trojans can come in many forms

i suggest http://www.bleepingcomputer.com/combofix/how-to-use-combofix
posting on liquid sites in current year
ulszz
Profile Blog Joined June 2007
Jamaica1787 Posts
Last Edited: 2009-02-17 05:22:45
February 17 2009 05:22 GMT
#6
try hijack this, it works wonders. just google what looks suspicious when hjt shows you the log. i'm sure u can figure it out.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html
everliving, everfaithful, eversure
ShoCkeyy
Profile Blog Joined July 2008
7815 Posts
February 17 2009 06:37 GMT
#7
I've always used trend micro. They're amazing. PC Cillen o.o
Life?
micronesia
Profile Blog Joined July 2006
United States24745 Posts
February 17 2009 07:03 GMT
#8
As I said in the OP, I updated my virus definitions. It took care of the source of the problem when I ran a 2 hour scan lol... I physically removed the autorun.inf since the virus scanner couldn't do it. Hopefully this takes care of it (I tested google out and everything seems to be working now)

I'll keep this blog 'bookmarked' so to speak, for the next time I need help cleaning my computer so ty everyone.
ModeratorThere are animal crackers for people and there are people crackers for animals.
Racenilatr
Profile Blog Joined August 2008
United States2756 Posts
February 17 2009 13:59 GMT
#9
worked for me every time lol. That happens alot to me on internet explorer or something. I would say cut back on the porn though because too much porn=adware+malware
KOFgokuon
Profile Blog Joined August 2004
United States14899 Posts
February 17 2009 14:08 GMT
#10
gl hope it doesn't act up more
dm47
Profile Blog Joined March 2008
82 Posts
February 17 2009 16:31 GMT
#11
sounds like Trojan.vundo. I had this a while ago and it would redirect the first 5-6 pages that show up on google search to other websites. I used Malwarebytes' Anti-malware to fix it and I would definitely recommend that if you have any other problems. Because from what I'm read... Malwarebytes' is one of the few apps/AV's that can actually remove it. I have Nod32 and it didn't do jack squat.
I hate optimists.
SCC-Faust
Profile Blog Joined November 2007
United States3736 Posts
February 17 2009 16:44 GMT
#12
On February 17 2009 14:22 ulszz wrote:
try hijack this, it works wonders. just google what looks suspicious when hjt shows you the log. i'm sure u can figure it out.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html


I'd be super careful with this though.

One time I tried this and it totally bombed my computer, had to system restore.
I want to fuck Soulkey with a Zelderan.
gg_hertzz
Profile Blog Joined January 2004
2152 Posts
February 17 2009 21:21 GMT
#13
this happened to me not too long ago had to reinstall everything.
ulszz
Profile Blog Joined June 2007
Jamaica1787 Posts
February 17 2009 21:48 GMT
#14
On February 18 2009 01:44 SCC-Faust wrote:
Show nested quote +
On February 17 2009 14:22 ulszz wrote:
try hijack this, it works wonders. just google what looks suspicious when hjt shows you the log. i'm sure u can figure it out.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html


I'd be super careful with this though.

One time I tried this and it totally bombed my computer, had to system restore.

ya, just make sure you google the processes before you delete them. sorry bout that though, prolly was a huge pain in the ass.
everliving, everfaithful, eversure
micronesia
Profile Blog Joined July 2006
United States24745 Posts
February 18 2009 04:06 GMT
#15
On February 18 2009 01:31 dm47 wrote:
sounds like Trojan.vundo. I had this a while ago and it would redirect the first 5-6 pages that show up on google search to other websites. I used Malwarebytes' Anti-malware to fix it and I would definitely recommend that if you have any other problems. Because from what I'm read... Malwarebytes' is one of the few apps/AV's that can actually remove it. I have Nod32 and it didn't do jack squat.

Thanks I did this today and it seemed to help (had to transfer the updated definitions from another computer since the trojan was blocking it haha...
ModeratorThere are animal crackers for people and there are people crackers for animals.
Please log in or register to reply.
Live Events Refresh
WardiTV 2025
12:00
Group Stage 1 - Group B
TaKeTV 98
Rex64
WardiTV0
LiquipediaDiscussion
Sparkling Tuna Cup
10:00
Weekly #114
TriGGeR vs SKillousLIVE!
Percival vs TBD
CranKy Ducklings230
LiquipediaDiscussion
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
SpeCial 64
Rex 64
trigger 59
StarCraft: Brood War
BeSt 1568
Hyuk 808
Jaedong 778
Stork 413
EffOrt 383
firebathero 366
Last 272
Killer 262
Hyun 241
910 221
[ Show more ]
Mini 197
ZerO 167
sorry 99
Bale 99
Barracks 90
ggaemo 61
Mind 52
Shinee 42
Sharp 40
zelot 36
Noble 26
ToSsGirL 19
HiyA 16
Dota 2
singsing3912
XcaliburYe452
League of Legends
C9.Mang0378
Counter-Strike
x6flipin370
Super Smash Bros
Mew2King35
Westballz14
Heroes of the Storm
Khaldor221
Other Games
B2W.Neo946
RotterdaM172
nookyyy 49
ZerO(Twitch)17
Organizations
StarCraft: Brood War
CasterMuse 37
lovetv 6
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 13 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• C_a_k_e 2609
• lizZardDota299
League of Legends
• Jankos3923
Upcoming Events
OSC
2h 58m
IPSL
4h 58m
Bonyth vs KameZerg
BSL 21
7h 58m
Bonyth vs StRyKeR
Tarson vs Dandy
Replay Cast
20h 58m
Wardi Open
23h 58m
StarCraft2.fi
1d 3h
Monday Night Weeklies
1d 4h
Replay Cast
1d 11h
WardiTV 2025
1d 23h
StarCraft2.fi
2 days
[ Show More ]
PiGosaur Monday
2 days
StarCraft2.fi
3 days
Tenacious Turtle Tussle
3 days
The PondCast
3 days
WardiTV 2025
3 days
StarCraft2.fi
4 days
WardiTV 2025
4 days
StarCraft2.fi
5 days
RSL Revival
5 days
IPSL
6 days
Sziky vs JDConan
RSL Revival
6 days
Classic vs TBD
herO vs Zoun
Liquipedia Results

Completed

Proleague 2025-12-04
RSL Revival: Season 3
Light HT

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
YSL S2
BSL Season 21
CSCL: Masked Kings S3
Slon Tour Season 2
Acropolis #4 - TS3
WardiTV 2025
META Madness #9
Kuram Kup
SL Budapest Major 2025
ESL Impact League Season 8
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22

Upcoming

BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
Bellum Gens Elite Stara Zagora 2026
HSC XXVIII
Big Gabe Cup #3
RSL Offline Finals
PGL Cluj-Napoca 2026
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter Qual
eXTREMESLAND 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.