Ask Experts Questions for FREE Help!
 

Free Answers in 3 Easy Steps

Register Now
3 Steps
 


Ask QuestionsprogressAnswer QuestionsprogressBuild ReputationprogressBecome an Expert
 
At Ask Me Help Desk you can ask questions in any topic and have them answered for free by our experts. To ask questions or participate in answering them you must register for a free account. By registering you will be able to:
  • Get free answers from experts in any of our 300+ topics.
  • Accept money for answers that you provide.
  • Communicate privately with other members (PM).
  • See fewer ads.
  Answer this Question    Ask about Spyware, Viruses, etc.    Ask about another Subject  
 

Capuchin
Apr 22, 2009, 11:29 AM
Hello fellows!

I have a piece of malware on my pc! This doesn't make me happy!
I need your help in getting rid of it!

What it's doing is hijacking my google results and taking me to some ad page so they can make money. It doesnt seem to be doing anything more malicious than that, but i want to be able to use google. It also blocks any attempt to download updates for anti-malware clients, so i'll need your help to make mirrors of any definitions updates if you recommend any new software to try.

I have detected the infection using ad-aware 2008, my pc works fine for about an hour and then the same problem returns, so it's obviously hiding away somewhere. I'm just running a scan now to see what it's called.

Ad-aware doesn't give a name, but this is what appears in the logs:

Family Id: 538 Name: Possible Browser Hijack attempt Category: Malware TAI:3

Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet001\Services\Tcpip\Parameters Value: NameServer Data: 85.255.112.158,85.255.112.86

Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{61E730B8-B842-49D3-8C53-3F4AE052CF84} Value: NameServer Data: 85.255.112.158,85.255.112.86

Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet002\Services\Tcpip\Parameters Value: NameServer Data: 85.255.112.158,85.255.112.86

Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{61E730B8-B842-49D3-8C53-3F4AE052CF84} Value: NameServer Data: 85.255.112.158,85.255.112.86

I hope you know what that means better than I do!

Hope you guys can help, i'm totally drowned under with work I don't have the time to look much deeper than I already have right now.

Curlyben
Apr 22, 2009, 11:32 AM
Spybot S&D.
You can download and apply the updates manually ;)
http://www.safer-networking.org/en/download/index.html

Actually you could simply hack those values out of the registry with good old regedit, BUT be careful. The registry isn't somewhere to go playing about.