About a month ago I started having this problem. Almost every time I click a link from a google search it redirects me to a different page instead of the page I clicked on. I have been getting around this by just copying the link directly into the url bar. I usually use chrome but it happens when I use internet explorer also. I don't know what could have caused the problem; I don't think I visited any creepy sites or ran anything blatantly bad.

I ran a full scan of malwarebytes and nothing came up. Then I tried kaspersky rescue disk 2010 and nothing came up at all. Again with Spybot nothing unusual came up. And with TDSSkiller nothing came up.

When it redirects me it usually goes to scour.com or different fake anti-virus sites.

I have windows 7 32 bit.

Thanks for your help


Hello and welcome to Safer Networking.

I am currently assessing your situation and will be back with a fix for your problem as soon as possible.

Please be patient with me during this time.

Meanwhile, please make a reply to this topic to acknowledge that you have read this and is still with me to tackle the problem until the end.

Thanks for helping with this problem.

I subscribed to the thread so I should be able to respond quickly when given advise.

Hello alsbot :),

Welcome to Safer Networking. I am Jack&Jill, and I will be helping you out.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.

Lets start with uninstalling Spybot Search & Destroy because its real time protection will interfere with the fixes.

You have Malwarebytes' Anti-Malware (MBAM) on your machine. I wish to take a look at the most recent log file. Open MBAM and click on the Logs tab. Open the file at the bottom of the list and post the contents back here. If there is no log or you have yet to run MBAM, please let me know.

Please post the TDSSKiller log as well. It will be named TDSSKiller.Version_Date_Time_log.txt at C:\, for example, C:\TDSSKiller.


I see signs of Combofix on your computer.

While you may see ComboFix being used quite often and without incident, the tool should not be run unsupervised (as stated in the Disclaimer that is first displayed by ComboFix when you run the tool).

Going forward, I highly recommend you heed such instructions.

As stated by the author of ComboFix:

ComboFix is a very powerful tool which when improperly used may render your machine to a doorstop.

We first need to verify if there are any rootkits present and how they could affect our tools. Thus, we use preliminary scans like DDS and GMER and their logs to map our strategy for attack.

With these logs, we can determine the infections present and decide whether to deploy ComboFix.

That said, the log it produced contains valuable information. Kindly post the ComboFix log, C:\ComboFix.txt.


Please download aswMBR and save it to your desktop. Click here. (http://public.avast.com/~gmerek/aswMBR.exe)

Double click the aswMBR.exe file to run it.
Click on the Scan button to start. The program will launch a scan.
When done, you will see Scan finished successfully. Please click on Save log and save the file to your desktop.
Please post the contents of the log in your next reply.


Please post back:
1. previous MBAM report
2. TDSSKiller log
3. ComboFix log
4. aswMBR result

I removed Spybot.


Malwarebytes' Anti-Malware

Database version: 6912

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

6/21/2011 4:55:30 PM
mbam-log-2011-06-21 (16-55-30).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 265005
Time elapsed: 55 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


aswMBR version Copyright(c) 2011 AVAST Software
Run date: 2011-06-22 18:42:25
18:42:25.931 OS Version: Windows 6.1.7601 Service Pack 1
18:42:25.933 Number of processors: 4 586 0x1C0A
18:42:25.937 ComputerName: BENDER UserName: Alyssa
18:42:26.613 Initialize success
18:42:35.065 AVAST engine defs: 11062201
18:42:49.170 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
18:42:49.176 Disk 0 Vendor: ST925031 0003 Size: 238475MB BusType: 3
18:42:49.182 Disk 0 MBR read error 0
18:42:49.191 Disk 0 MBR scan
18:42:49.202 Disk 0 unknown MBR code
18:42:49.211 MBR BIOS signature not found 0
18:42:49.223 Disk 0 scanning sectors +488397168
18:42:49.235 Disk 0 scanning C:\windows\system32\drivers
18:43:07.833 Service scanning
18:43:08.951 Disk 0 trace - called modules:
18:43:09.031 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys spgo.sys >>UNKNOWN [0x8523f938]<<
18:43:09.043 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86a811c0]
18:43:09.066 3 CLASSPNP.SYS[895b459e] -> nt!IofCallDriver -> [0x86015360]
18:43:09.083 5 ACPI.sys[88fb53d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8528c028]
18:43:09.980 AVAST engine scan C:\windows
18:53:24.424 AVAST engine scan C:\Users\Alyssa
18:53:24.490 AVAST engine scan C:\ProgramData
18:53:24.492 Scan finished successfully
18:54:09.289 Disk 0 MBR has been saved successfully to "C:\Users\Alyssa\Desktop\MBR.dat"
18:54:09.312 The log file has been saved successfully to "C:\Users\Alyssa\Desktop\aswMBR.txt"

Okay I think that's everything: Thanks!

Hello alsbot :),

Disable CD Emulation drivers

Please download DeFogger© by jpshortstuff and save it to your desktop. Click here. (http://www.jpshortstuff.247fixes.com/Defogger.exe)
Double click on DeFogger.exe to run the tool.
The application window will appear.
Click the Disable button to disable your CD Emulation drivers.
Click Yes to continue.
A Finished! message will appear, then click OK.
DeFogger will now ask to reboot the machine, click OK.
DO NOT re-enable these drivers until otherwise instructed.

If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.


Delete the TDSSKiller copy that you have. Get the latest one and run it as below.

Please download TDSSKiller© from Kaspersky and save it to your desktop. Click here. (http://support.kaspersky.com/downloads/utils/tdsskiller.exe)

Alternatively, you may get the zip version (http://support.kaspersky.com/downloads/utils/tdsskiller.zip) and extract the file to the desktop.
Double click on TDSSKiller.exe to execute it.
Press Start scan to begin.
If anything is found, please change all the actions to Skip only. <-- Important, please select Skip only, DO NOT Cure yet.
Then click on Continue at the lower right corner.
You may be prompted to reboot your computer, please consent.
Once complete, a log will be produced at C:\. It will be named TDSSKiller.Version_Date_Time_log.txt, for example, C:\TDSSKiller.
Please post the contents of this log.


Repeat the aswMBR scan and post back the new log.


Please download MiniToolBox© by farbar and save it to your desktop. Click here. (http://download.bleepingcomputer.com/farbar/MiniToolBox.exe)

Double click on MiniToolBox.exe to run it.
Please check (tick) the following options:
Flush DNS
Report IE Proxy Settings
List content of Hosts
List IP configuration
List last 10 Event Viewer Errors
List Users, Partitions and Memory size.
Click on the GO button. A log will open.
Please post this log as attachment. It can also be found on the desktop as Result.txt.

On the Reply to Thread page, you will see the Additional Options section below the text box that you use for replying. Click Manage Attachment and a new window will open. Browse... and look for the file, then double click on it. Next, click on Upload. You may close the window when done. Please do not post any other logs as attachment unless I request.


Please post back:
1. new TDSSKiller result
2. fresh aswMBR log
3. MiniToolBox result as attachment

Hello alsbot :),

I usually close the topic after 3 days without any reply, and it has already been 3 days since my last post. Do you still need help? Any problems following my instructions? Need more time?

If I do not get any response within the next 24 hours, this topic will be closed.

Due to lack of response, this topic is now closed.

