• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 17:10
CEST 23:10
KST 06:10
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Team TLMC #5: Vote to Decide Ladder Maps!0[ASL20] Ro8 Preview Pt1: Mile High15Team TLMC #5 - Finalists & Open Tournaments2[ASL20] Ro16 Preview Pt2: Turbulence10Classic Games #3: Rogue vs Serral at BlizzCon10
Community News
Artosis vs Ret Showmatch15Classic wins RSL Revival Season 22Weekly Cups (Sept 15-21): herO Goes For Four2SC2 5.0.15 PTR Patch Notes + Sept 22nd update275BSL 2025 Warsaw LAN + Legends Showmatch4
StarCraft 2
General
SC2 5.0.15 PTR Patch Notes + Sept 22nd update Storm change is a essentially a strict buff on PTR Question about resolution & DPI settings SC2 Classic wins RSL Revival Season 2 Code S RO4 & Finals Preview - Cure, Dark, Maru, Creator
Tourneys
Master Swan Open (Global Bronze-Master 2) Sparkling Tuna Cup - Weekly Open Tournament Prome's Evo #1 - Solar vs Classic (SC: Evo) Monday Nights Weeklies RSL: Revival, a new crowdfunded tournament series
Strategy
Custom Maps
External Content
Mutation # 492 Get Out More Mutation # 491 Night Drive Mutation # 490 Masters of Midnight Mutation # 489 Bannable Offense
Brood War
General
BGH Auto Balance -> http://bghmmr.eu/ Artosis vs Ret Showmatch Pros React To: Barracks Gamble vs Mini ASL20 General Discussion Whose hotkey signature is this?
Tourneys
[ASL20] Ro8 Day 2 [ASL20] Ro8 Day 1 [IPSL] ISPL Season 1 Winter Qualis and Info! [Megathread] Daily Proleagues
Strategy
Simple Questions, Simple Answers Muta micro map competition
Other Games
General Games
Beyond All Reason Nintendo Switch Thread Stormgate/Frost Giant Megathread Borderlands 3 Liquipedia App: Now Covering SC2 and Brood War!
Dota 2
Official 'what is Dota anymore' discussion LiquidDota to reintegrate into TL.net
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine The Big Programming Thread UK Politics Mega-thread
Fan Clubs
The Happy Fan Club!
Media & Entertainment
Movie Discussion! [Manga] One Piece Anime Discussion Thread
Sports
2024 - 2026 Football Thread Formula 1 Discussion TeamLiquid Health and Fitness Initiative For 2023 MLB/Baseball 2023
World Cup 2022
Tech Support
Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread High temperatures on bridge(s)
TL Community
BarCraft in Tokyo Japan for ASL Season5 Final The Automated Ban List
Blogs
[AI] JoCo is Eminem for com…
Peanutsc
Try to reverse getting fired …
Garnet
[ASL20] Players bad at pi…
pullarius1
Too Many LANs? Tournament Ov…
TrAiDoS
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1260 users

Virus/Trojan Redirects Internet

Blogs > micronesia
Post a Reply
micronesia
Profile Blog Joined July 2006
United States24701 Posts
February 17 2009 04:54 GMT
#1
So I've been pretty lucky about not letting bad stuff happen to my computer... but one day after running all that defensive software recommended in the thread http://www.teamliquid.net/forum/viewmessage.php?topic_id=87753 I noticed this happening:

1)
  • Type ravenholm into google
  • Click on the first hit (wikipedia article)
  • Get redirected to http://www.manga.com/?ref=AW2396753 or some other dumb site


2)
  • Type fios into google
  • Click on the first hit (verizon website)
  • Get redirected to http://www.mamma.com/Mamma?query=fios or some porn website and end up at the correct website another time...


For a goof I tried another search (smith) and ended up at the smith college website as you might expect...

I brought up my McAfee console for the first time ever (free antivirus crap I got from my university) and manually updated the definitions or whatever the deal is, and am running a scan on my system. It said:

autorun.inf
location: c:\
detected as: Generic!atr
Type: Trojan
Status: No Action Taken (Delete Failed)

So I'm trying to decide how I can aid the software in cleaning it... I tried looking for the file manually, but even after I showed hidden files, there was no autorun.inf there

The timing of this is truly ironic. Maybe adaware is malware!

*****
ModeratorThere are animal crackers for people and there are people crackers for animals.
SpiritoftheTunA
Profile Blog Joined August 2006
United States20903 Posts
February 17 2009 04:58 GMT
#2
try combofix, itslike fucking magic
posting on liquid sites in current year
ssj114
Profile Blog Joined September 2008
Afghanistan461 Posts
February 17 2009 04:59 GMT
#3
http://remove-malware.com/videos/how-to-remove-malware-for-free-video/
Sandboxie + SUA + DEP, Windows Firewall + NAT Router
Binky1842
Profile Blog Joined July 2004
United States2599 Posts
February 17 2009 05:12 GMT
#4
google the name of the detected file, in your case Generic!atr, and follow the help the search hits provide you.
keep your definition up to date >.<

i hope that's what youre asking for anyways. GL
"The zoo could not confirm that Binky was the attacker, but only Binky had blood on his face following the incident"
SpiritoftheTunA
Profile Blog Joined August 2006
United States20903 Posts
February 17 2009 05:15 GMT
#5
On February 17 2009 14:12 Binky1842 wrote:
google the name of the detected file, in your case Generic!atr, and follow the help the search hits provide you.
keep your definition up to date >.<

i hope that's what youre asking for anyways. GL

generic trojans can come in many forms

i suggest http://www.bleepingcomputer.com/combofix/how-to-use-combofix
posting on liquid sites in current year
ulszz
Profile Blog Joined June 2007
Jamaica1787 Posts
Last Edited: 2009-02-17 05:22:45
February 17 2009 05:22 GMT
#6
try hijack this, it works wonders. just google what looks suspicious when hjt shows you the log. i'm sure u can figure it out.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html
everliving, everfaithful, eversure
ShoCkeyy
Profile Blog Joined July 2008
7815 Posts
February 17 2009 06:37 GMT
#7
I've always used trend micro. They're amazing. PC Cillen o.o
Life?
micronesia
Profile Blog Joined July 2006
United States24701 Posts
February 17 2009 07:03 GMT
#8
As I said in the OP, I updated my virus definitions. It took care of the source of the problem when I ran a 2 hour scan lol... I physically removed the autorun.inf since the virus scanner couldn't do it. Hopefully this takes care of it (I tested google out and everything seems to be working now)

I'll keep this blog 'bookmarked' so to speak, for the next time I need help cleaning my computer so ty everyone.
ModeratorThere are animal crackers for people and there are people crackers for animals.
Racenilatr
Profile Blog Joined August 2008
United States2756 Posts
February 17 2009 13:59 GMT
#9
worked for me every time lol. That happens alot to me on internet explorer or something. I would say cut back on the porn though because too much porn=adware+malware
KOFgokuon
Profile Blog Joined August 2004
United States14899 Posts
February 17 2009 14:08 GMT
#10
gl hope it doesn't act up more
dm47
Profile Blog Joined March 2008
82 Posts
February 17 2009 16:31 GMT
#11
sounds like Trojan.vundo. I had this a while ago and it would redirect the first 5-6 pages that show up on google search to other websites. I used Malwarebytes' Anti-malware to fix it and I would definitely recommend that if you have any other problems. Because from what I'm read... Malwarebytes' is one of the few apps/AV's that can actually remove it. I have Nod32 and it didn't do jack squat.
I hate optimists.
SCC-Faust
Profile Blog Joined November 2007
United States3736 Posts
February 17 2009 16:44 GMT
#12
On February 17 2009 14:22 ulszz wrote:
try hijack this, it works wonders. just google what looks suspicious when hjt shows you the log. i'm sure u can figure it out.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html


I'd be super careful with this though.

One time I tried this and it totally bombed my computer, had to system restore.
I want to fuck Soulkey with a Zelderan.
gg_hertzz
Profile Blog Joined January 2004
2152 Posts
February 17 2009 21:21 GMT
#13
this happened to me not too long ago had to reinstall everything.
ulszz
Profile Blog Joined June 2007
Jamaica1787 Posts
February 17 2009 21:48 GMT
#14
On February 18 2009 01:44 SCC-Faust wrote:
Show nested quote +
On February 17 2009 14:22 ulszz wrote:
try hijack this, it works wonders. just google what looks suspicious when hjt shows you the log. i'm sure u can figure it out.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html


I'd be super careful with this though.

One time I tried this and it totally bombed my computer, had to system restore.

ya, just make sure you google the processes before you delete them. sorry bout that though, prolly was a huge pain in the ass.
everliving, everfaithful, eversure
micronesia
Profile Blog Joined July 2006
United States24701 Posts
February 18 2009 04:06 GMT
#15
On February 18 2009 01:31 dm47 wrote:
sounds like Trojan.vundo. I had this a while ago and it would redirect the first 5-6 pages that show up on google search to other websites. I used Malwarebytes' Anti-malware to fix it and I would definitely recommend that if you have any other problems. Because from what I'm read... Malwarebytes' is one of the few apps/AV's that can actually remove it. I have Nod32 and it didn't do jack squat.

Thanks I did this today and it seemed to help (had to transfer the updated definitions from another computer since the trojan was blocking it haha...
ModeratorThere are animal crackers for people and there are people crackers for animals.
Please log in or register to reply.
Live Events Refresh
Next event in 12h 50m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
ZombieGrub196
JuggernautJason103
Nathanias 76
StarCraft: Brood War
Britney 13869
Calm 2170
Shuttle 610
Mini 345
EffOrt 294
Barracks 83
hero 64
Dota 2
Pyrionflax199
monkeys_forever181
capcasts101
Counter-Strike
fl0m1441
taco 543
Stewie2K478
Foxcn265
Heroes of the Storm
Liquid`Hasu457
Other Games
Grubby4154
FrodaN830
mouzStarbuck192
KnowMe180
C9.Mang0123
Trikslyr114
shahzam6
fpsfer 3
Organizations
Other Games
BasetradeTV19
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 20 non-featured ]
StarCraft 2
• StrangeGG 39
• davetesta27
• OhrlRock 1
• Kozan
• Migwel
• sooper7s
• AfreecaTV YouTube
• intothetv
• IndyKCrew
• LaughNgamezSOOP
StarCraft: Brood War
• RayReign 47
• Azhi_Dahaki29
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• masondota21571
League of Legends
• Doublelift3865
• TFBlade756
Other Games
• imaqtpie1812
• Shiphtur195
Upcoming Events
The PondCast
12h 50m
CranKy Ducklings
1d 12h
Maestros of the Game
2 days
Serral vs herO
Clem vs Reynor
[BSL 2025] Weekly
2 days
[BSL 2025] Weekly
2 days
Replay Cast
3 days
BSL Team Wars
3 days
Wardi Open
4 days
Sparkling Tuna Cup
5 days
LiuLi Cup
6 days
Liquipedia Results

Completed

2025 Chongqing Offline CUP
RSL Revival: Season 2
HCC Europe

Ongoing

BSL 20 Team Wars
KCM Race Survival 2025 Season 3
BSL 21 Points
ASL Season 20
CSL 2025 AUTUMN (S18)
Maestros of the Game
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1

Upcoming

IPSL Winter 2025-26
SC4ALL: Brood War
BSL 21 Team A
BSL Season 21
RSL Revival: Season 3
Stellar Fest
SC4ALL: StarCraft II
EC S1
ESL Impact League Season 8
SL Budapest Major 2025
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.