This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Virus, Redirected in Browser, VERY slow

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I first attempted to run the OTL download, it continued to scan for over 5 hours. I was only able to get it shut down by using the task manager. Upon trying the second download Hijackthis it came up with this, "For some reason your system was denied access to the hosts files. If any hijackthis domains are in this file Hijackthis may not be able to fix this. If that happens you need to fix the file yourself. To do this click Start, Run and type: notepad c:\windows\system32\drivers\etc\hosts press enter. Find the lines hijackthis reports and delete them, save the files as 'host' and reboot." So I ran it and below is what it gave me, I'm not sure where to go from here. Can you help?? Thanks ~Amy Copyright © 1993-2006 Microsoft Corp. # # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. # # This file contains the mappings of IP addresses to host names. Each # entry should be kept on an individual line. The IP address should # be placed in the first column followed by the corresponding host name. # The IP address and the host name should be separated by at least one # space. # # Additionally, comments (such as these) may be inserted on individual # lines or following the machine name denoted by a '#' symbol. # # For example: # # 102.54.94.97 rhino.acme.com # source server # [removed] x.acme.com # x client host # localhost name resolution is handle within DNS itself. # 127.0.0.1 localhost # ::1 localhost
Hi, and welcome to our malware removal forum!

My name is Richard and I'll be happy to help you with your computer problems.

Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.

Please note the following:
  • The cleaning process is not instant as logs can take time to research. Sit tight and please be patient.
  • I will be working on your malware issues. This may or may not solve other issues you may have with your system.
  • While we are fixing your problems, do NOT install/re-install any programs or run any fixes or scanners unless told to do so.
  • Ensure that your anti-virus definitions are up-to-date.
  • I would advise backing up all your important documents, personal data files and photos to a CD or DVD drive.
  • Do not back up any Applications (programs). These should be re-installed from the original source CD(s) or website(s).
  • During the course of our cleanup, please do not do any additional online work or surfing until we have verified that your system is clean.
  • I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier.
  • Be sure to follow the directions and run tools/scans in the order listed.
  • If you do not reply to your topic, it will be closed after 3 days.
I will return as soon as possible with more instructions.



Regards,

Richard :wavey:
:thumbup:

Download DDS to your Desktop.
Disable any script blocker/antivirus software temporarily.
  • Double click DDS.scr to run it and wait for the scan to finish
  • When finished DDS.txt will open
  • At the next prompt, press Yes
  • DDS will continue scanning
  • When done, Attach.txt will open
  • Save both reports to your Desktop.
  • Please post the contents of the logs in your next reply.
Next

Download RogueKiller and save it on your Desktop.
  • Quit all programs.
  • Start RogueKiller.exe. For Vista or Windows 7, right-click on the program, select Run as Administrator to start, then when prompted, press Allow to run.
  • Wait until Pre-scan has finished.
  • Click on Scan.
  • Wait for the scan to complete.
  • When the scan completes, close the program.
  • The report has been created on the Desktop.
  • Please post the contents of the RKreport.txt file located on your Desktop.
In your next reply, please provide the following:
  • DDS.txt
  • attach.txt
  • RogueKiller log.



Regards,

Richard :wavey:
I downloaded DDS (just so you know: the link in your reply didn't work but I went back to the original "get help" page and found it, I only tell you cause I'd want to know). I've attached the two reports DDS came up with. I then ran RogueKiller, during it's pre-scan it asked that I delete the files it suggested. They appeared to be AVG related, which I assumed might conflict so I did as it asked and it continued to complete it's scan. It then opened two browser windows, they appear to take me to their help site. Currently RogueKiller wants to 'restart my computer and make some changes'. There doesn't appear to be anything on my desktop called RKreport.txt, but then at the moment all of my desktop icons have disappeared. It looks as though I may have to let it make the changes and hope that it will reboot okay. I'll attempt to reply again just as soon as possible. Thank you for your time and help. ~Amy
So it rebooted okay and when it did there were 4 icons on my desktop labeled as RKreport.txt I've attached them to this reply. At some point in time it asked that I "zip" the files, but I'm not sure how to do that so they aren't. I think that covers it all. ~Amy P.S. I'm doing my best to reply within the 3 day time frame, but I do work and have a family. Is there a way to extend my response time to 5 days to ensure my thread wont be deleted. I will reply just as soon as possible.
Thanks for providing the logs. ^_^

P.S. I'm doing my best to reply within the 3 day time frame, but I do work and have a family. Is there a way to extend my response time to 5 days to ensure my thread wont be deleted. I will reply just as soon as possible.

No worries. :thumbup:

You're infected with ZeroAccess, a nasty rootkit infection that has backdoor functionality.

This allows hackers to remotely control your computer, steal critical system information and download and execute files. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Please rerun RogueKiller.
  • Quit all programs.
  • Start RogueKiller.exe. For Vista or Windows 7, right-click on the program, select Run as Administrator to start, then when prompted, press Allow to run.
  • Wait until Pre-scan has finished.
  • Click on Scan.
  • Wait for the scan to complete.
  • The report has been created on the Desktop.
  • Next, click on the Fix Proxy button.
  • The report has been created on the Desktop.
  • Please post the contents of the new RKreport.txt files located on your Desktop.
Next

COMBOFIX
—————
Please download ComboFix from one of the following locations:
  • Location #1
  • Location #2
    ***IMPORTANT!!! Save ComboFix.exe to your Desktop.
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on ComboFix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Windows Vista/Windows 7, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see a Congratulations!!! message.

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

WARNING: ComboFix will disconnect your machine from the Internet as soon as it starts.
  • Please do not attempt to re-connect your machine back to the Internet until ComboFix has completely finished.
  • If there is no internet connection after running ComboFix, then restart your computer to restore back your connection.
In your next reply, please provide the following:
  • RogueKiller logs.
  • ComboFix log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Okay so I previously posted the RogueKiller logs. I temporarily disabled AVG, and then ran ComboFix. It automatically started doing it's scan, it didn't come up with anything about the Microsoft Windows Recovery Console, but it did say it was unable scan one program so it gave me the option of retrying, cancelling or ignoring the file. I chose to ignore it to let it continue to scan. Once it finished the window disappeared and I've yet to find any log anywhere. Overall my computer is still running very slow but it doesn't seem to be shutting down or denying me access like it was when I started my posts. Thanks!
Thanks for providing the logs. ^_^

Sorry for the delay it's been a hell of a week.

No problem. B)

Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Windows Vista/Windows 7, ComboFix will continue it's malware removal procedures.

The Microsoft Windows Recovery Console is for Windows XP users. :thumbup:

Please look for ComboFix.txt file in the following locations:
  • C:\ComboFix.txt
  • C:\qoobox\ComboFix.txt
In your next reply, please provide the following:
  • ComboFix log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Hi Richard, Thanks so much for not giving up on me. Getting late Christmas cards out took priority :-) I attempted to search both files listed. I went into the c:\ drive and searched both file names suggested, minus the ' c:\ ' notation (it's not necessary right?) During both searches my computer showed me it's progress, but slowed once it got to about 98% done with the search and then never completed. Overall, my PC is still running very slow and it's still being redirected (Note: I can copy and paste the addresses from a search query into the address box and still access some searched links) I'm sorry this was not very helpful. Have a Happy New Year! Thanks, ~Amy
Thanks for the information. :thumbup:

Thanks so much for not giving up on me. Getting late Christmas cards out took priority :-)

No problem. B)

Have a Happy New Year!

You too! :woot: ^_^

Download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]FRST will let you know when the scan is complete and has written the FRST.txt to file, close out this message, then type the following into the search box:

services.exe
[*]Now press the Search button.

[*]When the search is complete, search.txt will also be written to your USB.

[*]Type exit and reboot the computer normally.

[*]Please copy and paste both logs in your reply.(FRST.txt and Search.txt)

In your next reply, please provide the following:
  • FRST.txt
  • Search.txt
  • Update on how your PC is running.



Regards,

Richard :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI