Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

 
Closed TopicStart new topic
> [Closed] Another AntivirusXP Victim/Browser Hijacked, Browser affected by malware
mrfronty
post Sep 2 2008, 07:01 AM
Post #1


New Member
*

Group: New Member
Posts: 4
Joined: 2-September 08
Member No.: 81,331
Operating System: Windows XP



Like alot of others here I got the AntivirusXP 2008 bug. I was able to restore my display tabs and change my desktop. Thought I had deleted the bug as it stopped sending pop ups and such. However my IE7 browser has been affected. Any searches in Yahoo, Google, etc, are all redirected to ad sites. Half the pages refuse to load at all. They all appear to go through an IP owned by "Conepuppy". Also after 20 or so minute the browser stops working all together and the only way to use it again is to reboot the system. All system restore points are gone. Ran AVG, McAfee, AdWare and a few others but nothing is being detected. Tried downloading a few other spyware programs but none will download properly or operate. Receive a message stating that are not valid SYSTEM32 files. Right now nothing else on my system seems to be affected except the browser. Can someone please tell me what I'm missing? I can run a hijack this scan if wanted.
Go to the top of the page
 
+Quote Post
mrfronty
post Sep 3 2008, 11:54 AM
Post #2


New Member
*

Group: New Member
Posts: 4
Joined: 2-September 08
Member No.: 81,331
Operating System: Windows XP



Not sure what I did wrong here. I'm just trying to get some help solving this.
Go to the top of the page
 
+Quote Post
jpshortstuff
post Sep 4 2008, 03:08 AM
Post #3


SuperMember
Group Icon

Group: Malware Team
Posts: 2,209
Joined: 28-April 07
From: UK
Member No.: 69,799
Operating System: Windows XP Media Center/Ubuntu Linux



Hi, and Welcome to WhatTheTech smile.gif

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.

Please download HijackThis version 2.0.2 and save the file to your desktop. Double click the Hijackthis icon on your desktop and hit Do a System Scan and Save a Logfile and then copy and paste the log into a new reply, using the Add Reply button.

Thanks,

jpshortstuff
Go to the top of the page
 
+Quote Post
mrfronty
post Sep 4 2008, 12:18 PM
Post #4


New Member
*

Group: New Member
Posts: 4
Joined: 2-September 08
Member No.: 81,331
Operating System: Windows XP



I thank you for your help. I resolved it last night. Actually the AntivirusXP was removed, however that wasn't what was causing the problems. Found a trojan called TDSSServ.sys. It was embedded in the System32 folder. Couldn't delete in safe mode. Had to download a program and force a delete of it. Again, thank you for your response.
Go to the top of the page
 
+Quote Post
jpshortstuff
post Sep 5 2008, 12:58 AM
Post #5


SuperMember
Group Icon

Group: Malware Team
Posts: 2,209
Joined: 28-April 07
From: UK
Member No.: 69,799
Operating System: Windows XP Media Center/Ubuntu Linux



Hi there.

I notice you named a file that was bad, and I recognized this file as a Rootkit. Read about it here:
http://www.bleepingcomputer.com/startups/t....sys-23624.html

This is quite a nasty infection. If you want me to check your computer for any more signs of malware, then I would be more than happy to do so. If you are happy that your computer is back to it's usual performance then please let me know and we can close this thread.

Thanks.
Go to the top of the page
 
+Quote Post
LDTate
post Sep 10 2008, 05:46 AM
Post #6


Forum God
Group Icon

Group: Root Admin
Posts: 40,566
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




Due to inactivity this topic will be closed.
If you need help please start a new thread and post a new HJT log
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 7th January 2009 - 02:35 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy