Help - Redirection virus is on my system

gak1952

Distinguished
Jul 11, 2011
39
0
18,530
I desperately need help getting a redirection virus off my computer (for information on these viruses see, for example, click here and here, for further information about these viruses.

What happens is that in both Firefox and Chrome, every so often, when I attempt to open a new tab, I'm redirected into a tab different than the one I want to go into. I might, for example, be researching backup software. I try and open a tab a new Euease tab in the Euease website when suddenly find I've been catapulted into the Norton website and find myself staring at a window offering 'great deals' on backup software.

According to PC Magazine the redirect viruses, generates web traffic, collects sales leads for other dubious sites, and tries to fool the victim into paying for useless software. If those tricks don't work it can kick up the threat level by downloading additional malicious or misleading programs.

I can see the redirection actions in the bottom left-hand corner of the screen, but not enough to trace anything.

I'm using AVG business edition, but it doesn't find it. From the research I've done, even the specialized root searching malware software don't find these kind of viruses (see the above referenced links). They are extremely difficult to remove. According to PC Magazine they even slip by programs specifically designed to kill them.

The first thing I want to do is track every action that is being performed on my computer and see where the redirection is coming from. I might then be able to delete the rouge software manually.

I've looked in Windows Computer Management on my computer but I can't find any Windows monitoring system that tracks every action. I assume - even vaguely remember finding such a file once - there is such a Windows log/track event file somewhere on my system.

(By the way, I'm running Windows XP Professional).

So I'd be very grateful to anyone who could direct to the Windows file that can provide me with every single event that happens on my system and in my browser. Or failing that any free software that would let me track everything that is happening on my system including my browser.

Naturally, I'd be even more grateful for any advice/help on actually getting rid of this virus.

My heartfelt thanks in advance for your help.
 
load into safemode.

install spybot search and destroy.
install ccleaner... run ccleaner and clear out all your system cache
run spybot search and destroy.
dl malwarebytes, run it
check your program files, uninstall any tool bars you find, and any suspicious programs you find. uninstall anything from java, ask, yahoo (those are the big 3 for adware)
run ccleaner again, this time regestry sweep your system.

restart pc, see if redirect still works.