Let's see, I've been fighting spyware for at least 8 years personally. I am an InfoSec expert of 15 years, I even develop anti-virus and anti-malware engines, but admittedly, InfoSec doesn't even BEGIN to crack the Spyware egg.
I have spent as many as 13 hours cleaning an infected PC (why, I have no idea), and have probably cleaned 100 PCs in my lifetime thus far. I have only given up maybe once or twice. Seriously. I brag to all my friends that "I'm goooood" at this stuff.. Everyone knows me as the guy who can fix anything, hack anything (I've got 13 rooted phones in front of my keyboard right now), etc..
The only tool I ever really use is HijackThis. I also go through the Registry (the various "Run" keys) and the System Services (sometimes line by lines!!) This method has basically never failed me…
… Until now!! I have a new case on my desk here. My sister's laptop… It just got infected yesterday, and now it's showing some search-all-results.com site when I click on hyperlinks. I spent about 2 hours with it last night, and got her DNS to stop using a server in Ukraine (LOL) and disabled and removed the 127.0.0.1:4125 loopback proxy that somehow mysteriously got enabled (LOL!!). I also cleaned up a bunch of mysterious processes and stale files in the process. I thought for sure I had it licked given how easy it was to find some of this stuff.
We can now go to any web page directly, no problem. But if you click on any hyperlinks it eventually does the search engine redirect carp**. So it's like nothing was ever really fixed! I tried both IE and Mozilla (she NEVER uses IE anyways) and it does affect both. I'm inclined to believe DNS or a Proxy or a Service is still interfering (vs. an IE specific bug which shouldn't affect Mozilla). I have cleaned up her HijackThis results severely, including getting rid of oddball mouse drivers (which she didn't need), in hopes that some of those were fake (I myself wrote a virus back in like 1996 and called it "mouse.com" - hey, I was young and dumb!). Anyways, I am still unable to find the source of this.
Against my will, I downloaded Spybot S&D last night. After 2 hours of scanning, it found 20 tracing cookies and 3 stale registry entires, one of which was a tcpip parameter for an old NIC I believe, which also had those Ukraine DNS settings. I cleaned all of this up. Still nothing. I also am in the habit of rebooting by unplugging the power (no battery in the laptop at the time) immediately after I "clean" something, as I know they like to clean themselves. But admittedly, last night I didn't see anything self-repair like I normally do, except her Dell WLAN driver, which I'm guessing is fully legit since I also found it's respective service and my research tells me it's not likely the culprit.
Anyways, I'm at my wit's end here…
Before I go and nuke the HD (SSD BTW, yes, that was my idea last time her HD crashed) and re-install Win7 or whatever.
Any more ideas??
I see OTL and DDS for download - Admittedly, I've never heard of or used them. So maybe I will give it a go today and see if I get any further…
Thanks in advance for any more ideas or insight!!
Kevin
Now maybe you'll realize how the average user feels from people who create this stuff.
Although todays infections want to steal your information or worse. You may even get some feedback from those you infected.
I know no one else would help you from what you posted so I'm not sure why you posted what you did about creating a virus unless it's just to brag about it.
Also if this was your computer, I'd tell you just to reformat and start over, as that's about what you deserve.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.
Vista and Windows 7 users: 1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
You might want to print these instructions out.
Please download ATF Cleaner by Atribune. Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Next:
Please download GooredFix from one of the locations below and save it to your Desktop Download Mirror #1 Download Mirror #2
Ensure all Firefox windows are closed.
To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
When prompted to run the scan, click Yes.
It doesn't take long to run, once it is finished move onto the next step
Next:
Note: if the Cure option is not there, please select 'Skip'.
Only if Malicious objects are found then ensure Cure is selected
Then click Continue > Reboot now
Copy and paste the log in your next reply
A copy of the log will be saved automatically to the root directory, root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
please post the contents of that log TDSSKiller and GooredFix log.
Hi LDTate. Thanks for the welcome, although I'm not sure what you mean by "you deserve". I wrote a virus back in 1995, does that make me a criminal? I didn't launch it against thousands of people or anything, I just wrote it in a programming class. It WAS for bragging rights actually, and got me an A for the project. Naming it mouse.com was deceptive, yes, but that was kind of the point, and anyways I never used it against anyone, it was just a proof of concept for the class.
I have already tried OTL and HijackThis but not yet ATF, GooredFix or TDSSKiller. I will have to give those a shot, thanks!
OK, I tried ATF, it cleared up like 170MB of "stuff" LOL, mostly tempfiles. I also did it for Mozilla. It seems to have had no affect though. After a few clicks, I begin getting the search-results.com type of redirects.