Ask Experts Questions for FREE Help !
Ask
    Capuchin's Avatar
    Capuchin Posts: 5,255, Reputation: 656
    Uber Member
     
    #1

    Apr 22, 2009, 11:29 AM
    So, I have this malware.
    Hello fellows!

    I have a piece of malware on my PC! This doesn't make me happy!
    I need your help in getting rid of it!

    What it's doing is hijacking my Google results and taking me to some ad page so they can make money. It doesn't seem to be doing anything more malicious than that, but I want to be able to use Google. It also blocks any attempt to download updates for anti-malware clients, so I'll need your help to make mirrors of any definitions updates if you recommend any new software to try.

    I have detected the infection using ad-aware 2008, my PC works fine for about an hour and then the same problem returns, so it's obviously hiding away somewhere. I'm just running a scan now to see what it's called.

    Ad-aware doesn't give a name, but this is what appears in the logs:

    Family Id: 538 Name: Possible Browser Hijack attempt Category: Malware TAI:3

    Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet001\Services\Tcpip\Parameters Value: NameServer Data: 85.255.112.158,85.255.112.86

    Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet001\Services\Tcpip\Parameters\Int erfaces\{61E730B8-B842-49D3-8C53-3F4AE052CF84} Value: NameServer Data: 85.255.112.158,85.255.112.86

    Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet002\Services\Tcpip\Parameters Value: NameServer Data: 85.255.112.158,85.255.112.86

    Item Id: 7007 Value: Root: HKLM Path: SYSTEM\ControlSet002\Services\Tcpip\Parameters\Int erfaces\{61E730B8-B842-49D3-8C53-3F4AE052CF84} Value: NameServer Data: 85.255.112.158,85.255.112.86
    I hope you know what that means better than I do!

    Hope you guys can help, I'm totally drowned under with work I don't have the time to look much deeper than I already have right now.
    Curlyben's Avatar
    Curlyben Posts: 18,514, Reputation: 1860
    BossMan
     
    #2

    Apr 22, 2009, 11:32 AM
    Spybot S&D.
    You can download and apply the updates manually ;)
    http://www.safer-networking.org/en/download/index.html

    Actually you could simply hack those values out of the registry with good old regedit, BUT be careful. The registry isn't somewhere to go playing about.

Not your question? Ask your question View similar questions

 

Question Tools Search this Question
Search this Question:

Advanced Search

Add your answer here.


Check out some similar questions!

Removal of malware [ 2 Answers ]

I have a Dell Dimension 2350. Syestem is Microsoft Windows XP Home Edition, Version 2002 with Service Pack 3. I have McAffee Security Center. Symptoms: McAfee "M" square on tray will go black sometimes. Mostly I get "Your computer is not fully protected". And it's either a yellow alert...

Malware Found [ 1 Answers ]

I have just started using Comodo antivirus software and it has detected TrojWare.BAT,DelTree@12190. Just want to know if it is a bad one. What is the risk level and what does it do. I don't know how long it has been in my computer. My Norton, Windows Defender and Spybot have not picked it up.

I have malware? A trojan? Something [ 4 Answers ]

Hello, my computer has gone berserk since last weekend. Popups keep coming out in IE (recently in Mozilla too, which is the browser I always use). At times a window saying that the page I'm offline and I can't access IE (I'm not trying to do so, I don't use IE), then if I click keep...

Removal of Malware [ 21 Answers ]

How do you remove spyware, malware and their cousins?

PC spyware, malware. [ 5 Answers ]

One of my PCs picked up a virus/malware/spyware (the computer is a Dell GX50 all generic parts in it) My mom unkowenly dowloaded some stuff on that PC and now it's all messed up (or FUBAR). There is 3 icons (black monitor icons) one with a sword in the screen of the icon called "Protect your...


View more questions Search