So my computer just became infected, and my spyware pointed to the virtumonde virus. I started working on fixing the problem by reading all different posts, and I thought I had gotten it, but it seems to be back. I think I may have the cool web search virus also because when I go into IE and go to google for example and click on a link, it redirects me to a random pop-up window. Please help me if you have any information.
mvbrant 0 Newbie Poster
Dani AI
Generated
The symptoms described by — Google links redirecting into pop‑ups and a reported Virtumonde/Vundo detection that returns after removal — are classic signs of a persistent browser hijacker. The scan sequence suggested by is a good baseline, but recurrence usually means a persistence mechanism is still present: infected System Restore points, a hidden/rootkit driver, a rogue BHO/startup entry, a modified hosts file or a proxy/DNS change.
A practical cleanup sequence (for technicians reading later) that complements the scans already mentioned:
- Boot into Safe Mode (or use an offline rescue environment) so active malware is less able to block tools.
- Run a process-stopper (to kill malicious processes) prior to full-scans, then run thorough anti‑malware and rootkit scans. Repeat scans after a reboot.
- Inspect startup/BHO entries with an autorun/startup viewer and remove unfamiliar entries. Check the Windows hosts file and Internet Options -> Connections -> LAN settings for rogue proxy/DNS entries.
- Disable and clear System Restore (this deletes infected restore points), clear temp files, then recreate a clean restore point.
- If the infection persists, use an offline rescue CD/USB or consider a clean OS reinstall as the most certain fix.
Additional notes and cautions:
- Back up only personal documents and media (avoid executables and program installers) and scan backups before restoring.
- Check router DNS and admin settings in case redirecting DNS was set at the router level; reset router to defaults and change admin credentials if needed.
- Logs from the scanners and an autoruns/HJT-style log are the most helpful artifacts for further troubleshooting; responders can parse them for persistence traces.
This complements the earlier advice by focusing on persistence mechanisms and recovery options that are often the reason these hijackers reappear.
jholland1964 650 Posting Expert Team Colleague Featured Poster
Hello and welcome to daniweb,
The browser re-directs are not necessarily coolwebsearch but very likely the vundo infections, but we will see.
Do the following:
Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.
* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.
Reboot the computer.
Please Run the ESET Online Scanner and attach the ScanLog with your post for assistance.
* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.
Next download to the desktop.
Run a full system scan with HiJackThis and save the log.
Post back here with the MBA-M log, the ESET log and the HJT log.
Judy
Be a part of the DaniWeb community
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.