There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
audio avg avg 8 backup bios boot browser bsod computer cpu crash css dell desktop driver drivers dvd email error excel explorer firefox firefox 3 freeze game graphics hard drive hardware help please hijackthis hjt install internet internet explorer itunes javascript keyboard lan laptop malware missing monitor network networking openoffice outlook outlook 2003 outlook express php popups problem router screen seo slow sound sp3 spyware trojan usb video virus vista vundo windows windows vista windows xp winxp wireless word
Windows Vista
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Operating Systems > Windows Vista >
Help me solve this damn malware


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
Event3horizon's Avatar
Computer Specs
Account Disabled with 22 posts.
 
Join Date: Mar 2008
Location: Tampa, FL
Experience: Advanced
11-Mar-2008, 11:12 PM #1
Question Help me solve this damn malware
I'm trying to help my friend running Vista and an HP PC.

He caught a virus/worm from limewire and i can't remember the exact name but it was from a file named mp3[1].exe and soon after he downloaded it his trend micro antivirus popped up saying that it detected a virus but when he tried to quarantine it, the program simply says its unable to do that. We then ran a full scan with trend micro and it didn't detect anything!

We then decided to do a file search for the name of the file he downloaded and the executable with the virus and found it and deleted it. We thought the issue was gone.

Now, after a week, the trojan has seemed to manifest itself in the form of corrupting my internet access. Its amazing. IE 7 nor Firefox connect to a site and simply say "connecting to ... " and never connects. Whats most weird is, the ONLY website i can connect to is google.com in both browsers and everything google. Here is what t/s we have done:

1) ran full trend micro and spysweeper scans and nogo
2) safe mode w/networking nogo
3) was able to ping www.yahoo.com in command prompt with no problem
4) inputting for example yahoo's IP address directly into the browser and still nogo (not DNS) issue
5) Unable to receive POP mail from POP mail server through windows mail
6) ran sfc /scannow and no issues detected
7) reset ie 7 web settings nogo
8) checked hosts file for any suspicious information and nothing found

So I am simply stumped here. Our goal of course is not to do an OSRI, which will probably work. So i know its not my internet connection based on the troubleshooting we have done. We have to start thinking like hackers to solve this i dont have that knowledge. What files/things does one have to change internally in Vista in order to kill the web access??

I appreciate all relies in advance. Any ideas, thank you.
Event3horizon's Avatar
Computer Specs
Account Disabled with 22 posts.
 
Join Date: Mar 2008
Location: Tampa, FL
Experience: Advanced
12-Mar-2008, 07:10 PM #2
i guess yall are stumped too eh?
managed's Avatar
Computer Specs
Senior Member with 1,066 posts.
 
Join Date: May 2003
Location: Liverpool, UK
Experience: Difficult to avoid, easy to forget.
12-Mar-2008, 07:21 PM #3
I would post a HijackThis log in the Malware section here :- http://forums.techguy.org/54-malware...jackthis-logs/
Event3horizon's Avatar
Computer Specs
Account Disabled with 22 posts.
 
Join Date: Mar 2008
Location: Tampa, FL
Experience: Advanced
12-Mar-2008, 10:18 PM #4
Quote:
Originally Posted by managed View Post
I would post a HijackThis log in the Malware section here :- http://forums.techguy.org/54-malware...jackthis-logs/
Ok i was thinking about hijackthis but theres no way to directly get it on the computer, obviously the browsers are shot.

I can try FTP through the command prompt or i can tell my friend to try to transfer it from another computer. Thanks for the info.
managed's Avatar
Computer Specs
Senior Member with 1,066 posts.
 
Join Date: May 2003
Location: Liverpool, UK
Experience: Difficult to avoid, easy to forget.
12-Mar-2008, 10:38 PM #5
You could burn the HijackThis EXE download onto a CD and install from that.
Rich-M's Avatar
Computer Specs
Distinguished Member with 15,527 posts.
 
Join Date: May 2006
Location: Eastern Pa
Experience: Advanced
13-Mar-2008, 09:03 PM #6
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 08:01 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.