Ask Experts Questions for FREE Help!
Answer   ||    Advanced Search

Ask your question or search...
International Sites: Nederlandse experts vragen
User Name 
Password 
Join   Forgot password? 

Home > Computers & Technology > Security > Spyware, Viruses, etc.   »   So, I have this malware.

Question
 
 
#1  
Old Apr 22, 2009, 11:29 AM
Capuchin's Avatar
Capuchin
Science Expert
Capuchin is offline
 
Join Date: Oct 2006
Location: UK
Posts: 5,237
Capuchin See this member's comment history on his/her Profile page.Capuchin See this member's comment history on his/her Profile page.Capuchin See this member's comment history on his/her Profile page.Capuchin See this member's comment history on his/her Profile page.Capuchin See this member's comment history on his/her Profile page.Capuchin See this member's comment history on his/her Profile page.
Send a message via MSN to Capuchin Call Capuchin via Skype™
So, I have this malware.

Hello fellows!

I have a piece of malware on my pc! This doesn't make me happy!
I need your help in getting rid of it!

What it's doing is hijacking my google results and taking me to some ad page so they can make money. It doesnt seem to be doing anything more malicious than that, but i want to be able to use google. It also blocks any attempt to download updates for anti-malware clients, so i'll need your help to make mirrors of any definitions updates if you recommend any new software to try.

I have detected the infection using ad-aware 2008, my pc works fine for about an hour and then the same problem returns, so it's obviously hiding away somewhere. I'm just running a scan now to see what it's called.

Ad-aware doesn't give a name, but this is what appears in the logs:

Quote:
Family Id: 538 Name: Possible Browser Hijack attempt Category: Malware TAI:3

Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet001\Services\Tcpip\Parameters Value: NameServer Data: 85.255.112.158,85.255.112.86

Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet001\Services\Tcpip\Parameters\Int erfaces\{61E730B8-B842-49D3-8C53-3F4AE052CF84} Value: NameServer Data: 85.255.112.158,85.255.112.86

Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet002\Services\Tcpip\Parameters Value: NameServer Data: 85.255.112.158,85.255.112.86

Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet002\Services\Tcpip\Parameters\Int erfaces\{61E730B8-B842-49D3-8C53-3F4AE052CF84} Value: NameServer Data: 85.255.112.158,85.255.112.86
I hope you know what that means better than I do!

Hope you guys can help, i'm totally drowned under with work I don't have the time to look much deeper than I already have right now.

Reply With Quote
 
     

Answers
 
 
Old Apr 22, 2009, 11:32 AM   #2  
Administrator
Curlyben is offline
 
Curlyben's Avatar
 
Join Date: Mar 2005
Location: Behind You !!
Posts: 8,886
Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.
Pay to call Curlyben for advice ($1/min)
Call Curlyben via Skype™
Spybot S&D.
You can download and apply the updates manually
http://www.safer-networking.org/en/download/index.html

Actually you could simply hack those values out of the registry with good old regedit, BUT be careful. The registry isn't somewhere to go playing about.
  Reply With Quote
 
     

Your Answer
Email me when someone replies to my answer
Join Login



Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Ask your question or search...



Similar Threads
Removal of malware
(2 replies)
Removal of Malware
(22 replies)
Malware Found
(1 replies)
I have malware? a trojan? something
(4 replies)
PC spyware, malware.
(5 replies)

Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Search this Thread

Advanced Search

Bookmarks





Copyright ©2003 - 2009, Ask Me Help Desk.
All times are GMT -8. The time now is 09:21 AM.