1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active Search-engine Redirects, Certain Blocked Sites/Programs

Discussion in 'Malware and Virus Removal Archive' started by darshie, 2008/12/15.

  1. 2008/12/15
    darshie

    darshie Inactive Thread Starter

    Joined:
    2008/12/15
    Messages:
    2
    Likes Received:
    0
    [Active] Search-engine Redirects, Certain Blocked Sites/Programs

    Well, this is basically the same problem that it seems a lot of people are having, but since my logs differ slightly from theirs, I started a new thread nonetheless.

    The problem in a nutshell: search-engine results are being redirected (have had to go through caches), as well as sites being blocked (specifically, the hosts of RSIT, combofix, etc). The virus also does not let me run certain .exe's until renamed (again, the above). The computers on LAN are all fine, so it's definitely a localized problem.

    I got this virus (I believe) about 1-2 hours ago, when I visited a bogus video-streaming site. Avast popped up with a Trojan alert, and I clicked 'delete,' yet, here I am =\.

    I've already tried to do a bit to no avail (as you'll see in the log below, I used hijackthis to delete one of the .dll's that were foreign to my machine until today.) The other .dll's couldn't be deleted. Being the computer dummy that I am, I don't know if the foreign .dll's are just the least of the problem :p

    The Log From RSIT

    Let me know if you have any questions! Thanks.
     
  2. 2008/12/15
    darshie

    darshie Inactive Thread Starter

    Joined:
    2008/12/15
    Messages:
    2
    Likes Received:
    0
    Sorry in advance for the double post, but I figured this was something that might be missed by others if I just edited in.

    In short---it's fixed. I ran combofix in anticipation of what I'm sure would have been the next step. On step 40 it deleted the 4 foreign DLL's and a .ini. Anyway, cheers!
     

  3. to hide this advert.

  4. 2008/12/16
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Welcome to WindowsBBS darshie :)

    Please post the log from ComboFix located at C:\combofix.txt so we can see if anything else needs done.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.