REVscene Automotive Forum

REVscene Automotive Forum (https://www.revscene.net/forums/)
-   Gaming, Computer Tech & Electronics (https://www.revscene.net/forums/gaming-computer-tech-electronics_32/)
-   -   Browser Hijacking Virus/Malware Issue (https://www.revscene.net/forums/662417-browser-hijacking-virus-malware-issue.html)

Cman333 02-14-2012 02:33 PM

Quote:

Originally Posted by asiandude (Post 7796222)
Open Internet Explorer go to TOOLS < Manage ADDONS and check for anything unusual.

Post your C:\Windows\System32\Drivers\etc\hosts file

Any particular reason you using those DNS numbers? 68.105.28.12 68.105.29.12 68.105.28.11

Go to local area connection properties, TCP/IP properties set to obtain DNS automatically.

open CMD and do
ipconfig /release
ipconfig /renew
ipconfig /flushdns

Here's what the host file says

127.0.0.1 localhost


No particular reason why were using those DNS. I'm thinking maybe the computer tech did it when we tried to recover the data.

I looked at the local network connections and both IP and DNS were already set to obtain automatically.

goo3 02-16-2012 01:46 AM

You have a rootkit virus. I don't run windows any more so I'm not familiar with all the ins and outs.

But this is a simple thing to try:

How to remove malware belonging to the family Rootkit.Win32.TDSS (aka Tidserv, TDSServ, Alureon)?

edit: I just noticed someone posted this earlier. Did it work?

Psykopathik 02-16-2012 11:11 AM

Quote:

Originally Posted by Cman333 (Post 7784137)
... My gf somehow has installed some sort of browser hijacking virus onto her comp.

next time don't put a PC in the kitchen.

:lawl:

N.V.M. 02-16-2012 11:24 AM

all this time working on it instead of reinstalling the OS? really?

Psykopathik 02-16-2012 01:13 PM

^^backup favorites and reinstall windows. fastest fix by far. I never store anything on the main drive.

also helps my as my main drive is a paltry 128GB SSD :lawl: no choice but to move everything to E or F drives

rental_metard 02-18-2012 03:26 AM

Are you still encountering this behaviour? I'll chime in

underscore 02-18-2012 12:41 PM

try Panda online virus scanner, that saved my ass the last/only time I've had a virus.

Cman333 02-20-2012 12:12 AM

Quote:

Originally Posted by goo3 (Post 7798458)
You have a rootkit virus. I don't run windows any more so I'm not familiar with all the ins and outs.

But this is a simple thing to try:

How to remove malware belonging to the family Rootkit.Win32.TDSS (aka Tidserv, TDSServ, Alureon)?

edit: I just noticed someone posted this earlier. Did it work?

I havent tried Kaspersky yet. I'll give it a shot. Thanks.

Quote:

Originally Posted by N.V.M. (Post 7798730)
all this time working on it instead of reinstalling the OS? really?

The computer came pre installed with windows. I don't have a copy to reinstall and don't want pirated copy on it.

Quote:

Originally Posted by underscore (Post 7800960)
try Panda online virus scanner, that saved my ass the last/only time I've had a virus.

I'll try that if Kaspersky idea doesn't work. Thanks.

Quote:

Originally Posted by rental_metard (Post 7800696)
Are you still encountering this behaviour? I'll chime in

Unfortunately yes.

mk1freak 02-20-2012 05:48 PM

if you feel you have a good grasp of processes and whats legit, and if you are anal to the point of hunting down the evil manipulator of your girlfriend's goods,

download this:
Process Monitor

run it from USB if you are able to,

once running use browser surf to your favorite pron site (or was it your wife's :p)

*this next part optional but recommended*
open revscene.net, login to account, hit user cp and click "send pm"
in To field put in "mk1freak" and in message body copy and paste all favorite pron sites links and and requisite user/pw combos. tyvm

*end of optional*

find bad process and process threads (research process for what can be safely deleted) and eradicate with cmd prompt

mind you, if your not comfortable booting into and running ms-dos cmd prompts (for deletion of derrty files) you might want to remove drive and connect it to a another computer.

this is a little time consuming and theres a chance you may remove something your not supposed to so be very careful on how you proceed!

and oh yea have fun reading! funtimes ahead for you.

whitev70r 02-20-2012 06:03 PM

Can you find out name of program that she downloaded and go to Control Panel and remove program?

N.V.M. 02-20-2012 06:06 PM

Quote:

Originally Posted by Cman333 (Post 7802891)



The computer came pre installed with windows. I don't have a copy to reinstall and don't want pirated copy on it.



you're sure there's not a partitioned back up of the OS on the HDD?

is there a legit sticker on the machine with a valid key # ? then any OEM disk will do.

iwantaskyline 02-20-2012 11:31 PM

use hitmanpro

http://www.surfright.nl/en/downloads

90 percent sure this will resolve your issue

Psykopathik 02-21-2012 02:23 PM

Quote:

Originally Posted by N.V.M. (Post 7803501)
you're sure there's not a partitioned back up of the OS on the HDD?

is there a legit sticker on the machine with a valid key # ? then any OEM disk will do.

ooohh...i still have a legit serial sticker and a dead PC. the OEM disc was for a gateway. wonder if i can get another OEM disk and use my serial? whatever.. XP is soo old anyways lol!


All times are GMT -8. The time now is 09:10 AM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
SEO by vBSEO ©2011, Crawlability, Inc.
Revscene.net cannot be held accountable for the actions of its members nor does the opinions of the members represent that of Revscene.net