Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Sep 2 2008, 07:01 AM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 2-September 08 Member No.: 81,331 Operating System: Windows XP |
Like alot of others here I got the AntivirusXP 2008 bug. I was able to restore my display tabs and change my desktop. Thought I had deleted the bug as it stopped sending pop ups and such. However my IE7 browser has been affected. Any searches in Yahoo, Google, etc, are all redirected to ad sites. Half the pages refuse to load at all. They all appear to go through an IP owned by "Conepuppy". Also after 20 or so minute the browser stops working all together and the only way to use it again is to reboot the system. All system restore points are gone. Ran AVG, McAfee, AdWare and a few others but nothing is being detected. Tried downloading a few other spyware programs but none will download properly or operate. Receive a message stating that are not valid SYSTEM32 files. Right now nothing else on my system seems to be affected except the browser. Can someone please tell me what I'm missing? I can run a hijack this scan if wanted.
|
|
|
|
Sep 3 2008, 11:54 AM
Post
#2
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 2-September 08 Member No.: 81,331 Operating System: Windows XP |
Not sure what I did wrong here. I'm just trying to get some help solving this.
|
|
|
|
Sep 4 2008, 03:08 AM
Post
#3
|
|
![]() SuperMember Group: Malware Team Posts: 2,036 Joined: 28-April 07 From: UK Member No.: 69,799 Operating System: Windows XP Media Center/Ubuntu Linux |
Hi, and Welcome to WhatTheTech
My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer. Please download HijackThis version 2.0.2 and save the file to your desktop. Double click the Hijackthis icon on your desktop and hit Do a System Scan and Save a Logfile and then copy and paste the log into a new reply, using the Add Reply button. Thanks, jpshortstuff |
|
|
|
Sep 4 2008, 12:18 PM
Post
#4
|
|
|
New Member ![]() Group: New Member Posts: 4 Joined: 2-September 08 Member No.: 81,331 Operating System: Windows XP |
I thank you for your help. I resolved it last night. Actually the AntivirusXP was removed, however that wasn't what was causing the problems. Found a trojan called TDSSServ.sys. It was embedded in the System32 folder. Couldn't delete in safe mode. Had to download a program and force a delete of it. Again, thank you for your response.
|
|
|
|
Sep 5 2008, 12:58 AM
Post
#5
|
|
![]() SuperMember Group: Malware Team Posts: 2,036 Joined: 28-April 07 From: UK Member No.: 69,799 Operating System: Windows XP Media Center/Ubuntu Linux |
Hi there.
I notice you named a file that was bad, and I recognized this file as a Rootkit. Read about it here: http://www.bleepingcomputer.com/startups/t....sys-23624.html This is quite a nasty infection. If you want me to check your computer for any more signs of malware, then I would be more than happy to do so. If you are happy that your computer is back to it's usual performance then please let me know and we can close this thread. Thanks. |
|
|
|
Sep 10 2008, 05:46 AM
Post
#6
|
|
![]() Forum God Group: Root Admin Posts: 39,364 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Due to inactivity this topic will be closed.
If you need help please start a new thread and post a new HJT log |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
15 | Parth | 99 | Today, 10:29 AM Last post by: Rorschach112 |
|||
![]() |
6 | Pepito00 | 74 | Today, 09:00 AM Last post by: BHowett |
|||
![]() |
8 | fragolla | 314 | Today, 08:59 AM Last post by: BHowett |
|||
![]() |
12 | Megamuffin | 131 | Today, 06:24 AM Last post by: ken545 |
|||
|
Time is now: 1st December 2008 - 11:54 AM |