• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 20:09
CEST 02:09
KST 09:09
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL19] Finals Recap: Standing Tall9HomeStory Cup 27 - Info & Preview18Classic wins Code S Season 2 (2025)16Code S RO4 & Finals Preview: herO, Rogue, Classic, GuMiho0TL Team Map Contest #5: Presented by Monster Energy6
Community News
Flash Announces Hiatus From ASL52Weekly Cups (June 23-29): Reynor in world title form?12FEL Cracov 2025 (July 27) - $8000 live event16Esports World Cup 2025 - Final Player Roster16Weekly Cups (June 16-22): Clem strikes back1
StarCraft 2
General
The SCII GOAT: A statistical Evaluation The GOAT ranking of GOAT rankings Statistics for vetoed/disliked maps How does the number of casters affect your enjoyment of esports? Esports World Cup 2025 - Final Player Roster
Tourneys
Korean Starcraft League Week 77 Master Swan Open (Global Bronze-Master 2) RSL: Revival, a new crowdfunded tournament series [GSL 2025] Code S: Season 2 - Semi Finals & Finals $5,100+ SEL Season 2 Championship (SC: Evo)
Strategy
How did i lose this ZvP, whats the proper response Simple Questions Simple Answers
Custom Maps
[UMS] Zillion Zerglings
External Content
Mutation # 480 Moths to the Flame Mutation # 479 Worn Out Welcome Mutation # 478 Instant Karma Mutation # 477 Slow and Steady
Brood War
General
Flash Announces Hiatus From ASL BGH Auto Balance -> http://bghmmr.eu/ Player “Jedi” cheat on CSL Unit and Spell Similarities Help: rep cant save
Tourneys
[Megathread] Daily Proleagues [BSL20] Grand Finals - Sunday 20:00 CET Small VOD Thread 2.0 [BSL20] GosuLeague RO16 - Tue & Wed 20:00+CET
Strategy
Simple Questions, Simple Answers I am doing this better than progamers do.
Other Games
General Games
Stormgate/Frost Giant Megathread Nintendo Switch Thread Path of Exile What do you want from future RTS games? Beyond All Reason
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
Things Aren’t Peaceful in Palestine US Politics Mega-thread Trading/Investing Thread Russo-Ukrainian War Thread The Games Industry And ATVI
Fan Clubs
SKT1 Classic Fan Club! Maru Fan Club
Media & Entertainment
Anime Discussion Thread [Manga] One Piece [\m/] Heavy Metal Thread
Sports
Formula 1 Discussion 2024 - 2025 Football Thread NBA General Discussion TeamLiquid Health and Fitness Initiative For 2023 NHL Playoffs 2024
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
Blogs
Culture Clash in Video Games…
TrAiDoS
from making sc maps to makin…
Husyelt
Blog #2
tankgirl
StarCraft improvement
iopq
Trip to the Zoo
micronesia
Customize Sidebar...

Website Feedback

Closed Threads



Active: 606 users

Virus/Trojan Redirects Internet

Blogs > micronesia
Post a Reply
micronesia
Profile Blog Joined July 2006
United States24666 Posts
February 17 2009 04:54 GMT
#1
So I've been pretty lucky about not letting bad stuff happen to my computer... but one day after running all that defensive software recommended in the thread http://www.teamliquid.net/forum/viewmessage.php?topic_id=87753 I noticed this happening:

1)
  • Type ravenholm into google
  • Click on the first hit (wikipedia article)
  • Get redirected to http://www.manga.com/?ref=AW2396753 or some other dumb site


2)
  • Type fios into google
  • Click on the first hit (verizon website)
  • Get redirected to http://www.mamma.com/Mamma?query=fios or some porn website and end up at the correct website another time...


For a goof I tried another search (smith) and ended up at the smith college website as you might expect...

I brought up my McAfee console for the first time ever (free antivirus crap I got from my university) and manually updated the definitions or whatever the deal is, and am running a scan on my system. It said:

autorun.inf
location: c:\
detected as: Generic!atr
Type: Trojan
Status: No Action Taken (Delete Failed)

So I'm trying to decide how I can aid the software in cleaning it... I tried looking for the file manually, but even after I showed hidden files, there was no autorun.inf there

The timing of this is truly ironic. Maybe adaware is malware!

*****
ModeratorThere are animal crackers for people and there are people crackers for animals.
SpiritoftheTunA
Profile Blog Joined August 2006
United States20903 Posts
February 17 2009 04:58 GMT
#2
try combofix, itslike fucking magic
posting on liquid sites in current year
ssj114
Profile Blog Joined September 2008
Afghanistan461 Posts
February 17 2009 04:59 GMT
#3
http://remove-malware.com/videos/how-to-remove-malware-for-free-video/
Sandboxie + SUA + DEP, Windows Firewall + NAT Router
Binky1842
Profile Blog Joined July 2004
United States2599 Posts
February 17 2009 05:12 GMT
#4
google the name of the detected file, in your case Generic!atr, and follow the help the search hits provide you.
keep your definition up to date >.<

i hope that's what youre asking for anyways. GL
"The zoo could not confirm that Binky was the attacker, but only Binky had blood on his face following the incident"
SpiritoftheTunA
Profile Blog Joined August 2006
United States20903 Posts
February 17 2009 05:15 GMT
#5
On February 17 2009 14:12 Binky1842 wrote:
google the name of the detected file, in your case Generic!atr, and follow the help the search hits provide you.
keep your definition up to date >.<

i hope that's what youre asking for anyways. GL

generic trojans can come in many forms

i suggest http://www.bleepingcomputer.com/combofix/how-to-use-combofix
posting on liquid sites in current year
ulszz
Profile Blog Joined June 2007
Jamaica1787 Posts
Last Edited: 2009-02-17 05:22:45
February 17 2009 05:22 GMT
#6
try hijack this, it works wonders. just google what looks suspicious when hjt shows you the log. i'm sure u can figure it out.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html
everliving, everfaithful, eversure
ShoCkeyy
Profile Blog Joined July 2008
7815 Posts
February 17 2009 06:37 GMT
#7
I've always used trend micro. They're amazing. PC Cillen o.o
Life?
micronesia
Profile Blog Joined July 2006
United States24666 Posts
February 17 2009 07:03 GMT
#8
As I said in the OP, I updated my virus definitions. It took care of the source of the problem when I ran a 2 hour scan lol... I physically removed the autorun.inf since the virus scanner couldn't do it. Hopefully this takes care of it (I tested google out and everything seems to be working now)

I'll keep this blog 'bookmarked' so to speak, for the next time I need help cleaning my computer so ty everyone.
ModeratorThere are animal crackers for people and there are people crackers for animals.
Racenilatr
Profile Blog Joined August 2008
United States2756 Posts
February 17 2009 13:59 GMT
#9
worked for me every time lol. That happens alot to me on internet explorer or something. I would say cut back on the porn though because too much porn=adware+malware
KOFgokuon
Profile Blog Joined August 2004
United States14893 Posts
February 17 2009 14:08 GMT
#10
gl hope it doesn't act up more
dm47
Profile Blog Joined March 2008
82 Posts
February 17 2009 16:31 GMT
#11
sounds like Trojan.vundo. I had this a while ago and it would redirect the first 5-6 pages that show up on google search to other websites. I used Malwarebytes' Anti-malware to fix it and I would definitely recommend that if you have any other problems. Because from what I'm read... Malwarebytes' is one of the few apps/AV's that can actually remove it. I have Nod32 and it didn't do jack squat.
I hate optimists.
SCC-Faust
Profile Blog Joined November 2007
United States3736 Posts
February 17 2009 16:44 GMT
#12
On February 17 2009 14:22 ulszz wrote:
try hijack this, it works wonders. just google what looks suspicious when hjt shows you the log. i'm sure u can figure it out.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html


I'd be super careful with this though.

One time I tried this and it totally bombed my computer, had to system restore.
I want to fuck Soulkey with a Zelderan.
gg_hertzz
Profile Blog Joined January 2004
2152 Posts
February 17 2009 21:21 GMT
#13
this happened to me not too long ago had to reinstall everything.
ulszz
Profile Blog Joined June 2007
Jamaica1787 Posts
February 17 2009 21:48 GMT
#14
On February 18 2009 01:44 SCC-Faust wrote:
Show nested quote +
On February 17 2009 14:22 ulszz wrote:
try hijack this, it works wonders. just google what looks suspicious when hjt shows you the log. i'm sure u can figure it out.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html


I'd be super careful with this though.

One time I tried this and it totally bombed my computer, had to system restore.

ya, just make sure you google the processes before you delete them. sorry bout that though, prolly was a huge pain in the ass.
everliving, everfaithful, eversure
micronesia
Profile Blog Joined July 2006
United States24666 Posts
February 18 2009 04:06 GMT
#15
On February 18 2009 01:31 dm47 wrote:
sounds like Trojan.vundo. I had this a while ago and it would redirect the first 5-6 pages that show up on google search to other websites. I used Malwarebytes' Anti-malware to fix it and I would definitely recommend that if you have any other problems. Because from what I'm read... Malwarebytes' is one of the few apps/AV's that can actually remove it. I have Nod32 and it didn't do jack squat.

Thanks I did this today and it seemed to help (had to transfer the updated definitions from another computer since the trojan was blocking it haha...
ModeratorThere are animal crackers for people and there are people crackers for animals.
Please log in or register to reply.
Live Events Refresh
Next event in 2h 51m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Nina 317
Livibee 105
RuFF_SC2 4
StarCraft: Brood War
Jaeyun 50
HiyA 35
NaDa 28
Dota 2
420jenkins209
capcasts128
NeuroSwarm76
League of Legends
Grubby2604
JimRising 697
Counter-Strike
taco 1110
Other Games
summit1g9142
tarik_tv4660
fl0m589
ViBE206
PPMD45
Organizations
Other Games
BasetradeTV65
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 16 non-featured ]
StarCraft 2
• Berry_CruncH108
• Hupsaiya 101
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• blackmanpl 24
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• masondota21367
League of Legends
• Doublelift4957
• Jankos1817
Upcoming Events
Korean StarCraft League
2h 51m
CranKy Ducklings
9h 51m
RSL Revival
9h 51m
ByuN vs Cham
herO vs Reynor
FEL
15h 51m
RSL Revival
1d 9h
Clem vs Classic
SHIN vs Cure
FEL
1d 11h
BSL: ProLeague
1d 17h
Dewalt vs Bonyth
Replay Cast
2 days
Sparkling Tuna Cup
3 days
The PondCast
4 days
[ Show More ]
Replay Cast
4 days
RSL Revival
5 days
Replay Cast
5 days
RSL Revival
6 days
Liquipedia Results

Completed

BSL 2v2 Season 3
HSC XXVII
Heroes 10 EU

Ongoing

JPL Season 2
BSL Season 20
Acropolis #3
KCM Race Survival 2025 Season 2
CSL 17: 2025 SUMMER
Copa Latinoamericana 4
Championship of Russia 2025
RSL Revival: Season 1
Murky Cup #2
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
PGL Astana 2025
Asian Champions League '25
BLAST Rivals Spring 2025
MESA Nomadic Masters
CCT Season 2 Global Finals
IEM Melbourne 2025

Upcoming

2025 ACS Season 2: Qualifier
CSLPRO Last Chance 2025
2025 ACS Season 2
CSLPRO Chat StarLAN 3
K-Championship
uThermal 2v2 Main Event
SEL Season 2 Championship
FEL Cracov 2025
Esports World Cup 2025
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.