• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove msivxserv.sys trojan (Google redirect virus)

Myantispyware team June 24, 2009    

MSIVXserv.sys trojan is a new hidden trojan/rootkit from DNSChanger trojan family. The trojan uses rootkit-specific techniques designed to hide the software presence in the system. Once infected it blocks user access to security websites, blocks Spybot, AdAware, AVG, Superantispyware and Malwarebytes Anti-malware. Search results in Google, Yahoo, MSN and other redirects you to other non related sites.

Also msivxserv.sys trojan changes the DNS server options to the following fixed IPs: 85.255.112.95, 85.255.112.171, 85.255.112.204, 85.255.112.90.

Use the free instructions below to remove msivxserv.sys trojan and any associated malware from your computer.

Symptoms in a HijackThis Log

O17 – HKLM\System\CCS\Services\Tcpip\..\{2AFAF5CA-6B22-40A6-9642-D179DC3ADF8F}: NameServer = 85.255.112.95,85.255.112.171
O17 – HKLM\System\CCS\Services\Tcpip\..\{824A5446-77BF-4995-9F06-5B29F5E80614}: NameServer = 85.255.112.95,85.255.112.171
O17 – HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.204,85.255.112.90
O17 – HKLM\System\CS2\Services\Tcpip\..\{2AFAF5CA-6B22-40A6-9642-D179DC3ADF8F}: NameServer = 85.255.112.204,85.255.112.90
O17 – HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.95,85.255.112.171
O17 – HKLM\System\CS3\Services\Tcpip\..\{2AFAF5CA-6B22-40A6-9642-D179DC3ADF8F}: NameServer = 85.255.112.95,85.255.112.171
O17 – HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.112.95,85.255.112.171
O17 – HKLM\System\CS4\Services\Tcpip\..\{2AFAF5CA-6B22-40A6-9642-D179DC3ADF8F}: NameServer = 85.255.112.95,85.255.112.171
O17 – HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.95,85.255.112.171

Use the following instructions to remove msivxserv.sys trojan

Step 1: Remove msivxserv.sys trojan hidden driver.

Download Avenger from here and unzip to your desktop.

Run Avenger, copy,then paste the following text in Input script Box:

Drivers to delete:
msivxserv.sys

Click on ‘Execute’. You will be asked Are you sure you want to execute the current script?. Click Yes.

You will now be asked First step completed — The Avenger has been successfully set up to run on next boot. Reboot now?. Click Yes.

Your PC will now be rebooted.

Step 2: Remove msivxserv.sys trojan files and any associated malware

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select “Perform Quick Scan”, then click Scan. The scan may take some time to finish,so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

gxvxcservsys-dnschanger-mbam
Malwarebytes Anti-malware, list of infected items

Make sure that everything is checked, and click Remove Selected. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Note: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Trojan Tutorials - HowTo

 Previous Post

How to remove Malware Destructor 2009 (Uninstall instructions)

Next Post 

How to remove Antivirus Protection (Uninstall instructions)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

18 Comments

  1. Pat
    ― July 13, 2009 - 5:35 am  Reply

    Avenger executed MSIVXserv.sys

    and everything work back to normal

    i was able to install and run malwarebytes’ and 16 were detected…

    thnx alot for the instrucions…:)

  2. Scott
    ― July 28, 2009 - 3:27 pm  Reply

    Thank you for posting this. I have been looking for a solution to this for over a week. My next step was to format.

    Worked like a charm!

    Thanks again.

  3. Christin in Austin TX
    ― July 29, 2009 - 7:14 pm  Reply

    I’ve done EVERYTHING on this website and I STILL have the redirect google virus… so frustrated!

  4. Patrik
    ― July 30, 2009 - 8:53 am  Reply

    Christin, then ask for help at our Spyware removal forum.

  5. Sal.sa
    ― August 13, 2009 - 12:41 pm  Reply

    I don’t like google and I want to know how to get out of Total Security Anti-Spyware and PC Anti Spyware and the rest of the fake

  6. Navi
    ― August 23, 2009 - 10:20 pm  Reply

    Hello,

    I followed these instructions after trying many other solutions and it worked!!!

  7. Kevin
    ― September 4, 2009 - 11:16 am  Reply

    Apparent success! I had the Google redirect problem, which my McAfee couldn’t find.

    The avenger didn’t find msivxserv.sys, but I went ahead with the MBAM. That found a number of items and once removed, no more Google redirect!

    Thanks!

  8. Melvin
    ― January 13, 2010 - 5:54 pm  Reply

    IT WORKED! it really did! it was pretty easy too, just took a while (like 30min.)

  9. LarryFromVegas
    ― January 20, 2010 - 11:01 am  Reply

    After hours of hard research work, I came across a different solution because MalWarebytes (MBAM)didn’t work for me. Try HitMan Pro (ver 3.5 is the latest as of this writing) fixed my Google & Yahoo Redirect Virus. The file culprit was named 7n8001.sys and was located in the Drivers sub-directory under C:\Windows\System32.

    It took several hours of research and experimentation before I came upon this solution. I found the software on CNet. Looks like it’s free for 30 days. It’s a cloud computing solution. If you try deleting or renaming the virus yourself, it regenerates itself. It’s nasty and persistent.

    As of today, 1/20/2010, the latest updates for AVG, Malwarebytes, Spybot Search & Destroy, and AdAware could not fix it. XDELBox found it but couldn’t fix it (couldn’t write to the HOSTS file in C:\Windows\System32\Drivers\ETC.)

  10. Graham
    ― January 31, 2010 - 6:46 am  Reply

    Excellent worked a treat, thank you very much!!

    G

  11. Jeni
    ― February 16, 2010 - 12:57 pm  Reply

    Neither of those options worked for me. The first one didn’t remove the virus so I tried the second one – MalwareBytes – and it downloaded to my computer but wouldn’t run and didn’t show any of the screens this website said it should. My computer still has the redirect virus and it’s getting pop-ups now too.

  12. Patrik
    ― February 17, 2010 - 10:01 am  Reply

    Jeni, download TDSSKiller from here and unzip to your desktop.

    Open TDSSKiller folder and double click the TDSSKiller icon. Follow the prompts.

  13. Dave
    ― March 13, 2010 - 12:03 am  Reply

    Thx Larry HitMan Pro fixed me after 4 evenings wasted trying to resolve this redirect virus!

  14. SteveinMA
    ― March 14, 2010 - 3:12 pm  Reply

    The Hitman Pro fixed on the first try. Have been through avenger, unhackme, and malwarebytes along with other anti virus programs. but the hitman worked.

  15. Steve
    ― May 9, 2010 - 2:37 am  Reply

    THANKS DUDE THIS FIXED MY COMP.. THANK YOUuu!!

  16. Daniel
    ― July 17, 2010 - 7:21 pm  Reply

    This didn’t work for me, but Hitman Pro 3 did.

    It saved me a lot of frustration. Thanks. 🙂

  17. jerryman
    ― December 30, 2011 - 3:15 am  Reply

    HITMAN 3 has a lot of haters at cnet. most say to completely avoid this program. will not uninstall
    don’t know why some one try to spam it at this site.
    TDSSkiller, i’ve read some good things about it, i might try it. but will avoid hitman. go to cnet if you want to see all the complaints about hitman.

  18. Cathie
    ― March 8, 2012 - 12:14 pm  Reply

    I am in safe mode and your advenger program will not open in safe and normal. UGH I have been fighting this google bug for a week now, all my scans find it and delete it then somehow it pops right back up.

Leave a Reply to Patrik Cancel reply

New Guides

scam alert
Remove Searchernow.com Redirect: Chrome, Edge, Firefox
Avoid the ExLig.com Bitcoin Scam: Insights on Promo Code Frauds
scam alert
Denwex.com Review: Bitcoin Promo Codes as a Scam
scam alert
CEFOLEX.com Review: A Closer Look at the Bitcoin Promo Code Scam
The Bigexcoin.com Bitcoin Promo Code Scam: How to Stay Safe

Follow Us

Search

Useful Guides

Malwarebytes won’t install, run or update – How to fix it
How to reset Mozilla Firefox (Updated Apr. 2018)
remove chrome extension
How to remove Chrome extensions installed by enterprise policy
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]
browser redirect virus
How to remove Browser redirect virus [Chrome, Firefox, IE, Edge]

Recent Guides

How to remove Malware Destructor 2009 (Uninstall instructions)
How to remove Protection System (Uninstall instructions)
Remove google redirect to IX-Find.com (Remove koobface and podmena.sys trojans)
Malwarebytes won’t install, run or update – How to fix it
How to remove Antivirus System Pro (Uninstall instructions)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.