Browser Hijacker - Can't Run or Update Anti-Virus Software

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MattComp, Dec 13, 2008.

  1. MattComp

    MattComp Private E-2

    Hi,

    I have a virus on my home PC which takes me to random websites when I click links in Google (in both FireFox and IE) and won't allow me to run or update anti-virus software. I am unable to update AVG, AdAware, or install Spybot, HijackThis, ComboFix, or any of the other suggested programs. I have followed all of the steps listed in the tutorial that I have been able to, but am unable to post the logs because the website with the anti-spyware programs won't load because of the virus or won't install if downloaded. I've run AVG and AdAware with the updates I had before I got the virus and they don't pick up anything. Any insight on the virus I have or how to remove it would be greatly appreciated as it seems to be made to prevent me from attempting to remove it. I am also unable to access this website from the PC so I am writing from my laptop, so even if I were able to generate the necessary logs, I wouldn't be able to post them.

    Thank you,

    Matthew
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. MattComp

    MattComp Private E-2

    Hi,

    Thanks for responding. I have tried all of the steps in the READ AND RUN ME guide in safe mode and was only able to do the CCleaner and MGTools steps. For SAS, when I try to run it, it says that the program has encountered a problem and needs to close. For Malware Bytes, I click the file and the computer thinks for a second and then nothing happens. (I have tried changing the filenames as suggested in the guide, but the problems persist.) For Spybot, I get to the point where it tries to download additional files, but it says that there is no internet connection (this happens whenever I try to update or download antivirus software or updates on the infected computer). For MGTools, I got it to run, but the virus blocks me from accessing forums.majorgeeks.com on the infected computer, so I don't have a way to post the MGlog.zip file (unless there is a safe way to move the log to another computer). I don't know what the log looks like, but would it be possible for me to transcribe it here using my laptop instead of linking to it?

    Thanks,

    Matthew
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

    * Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    * Then search for TDSSserv.sys
    * Let me know if you find this or not.
    * If you do find it, right click on it, and select Disable. Do not try to uninstall it.
    * Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.

    And yes you can trasfer via CD the MGLogs.zip and attach it from a different computer.
     
  5. MattComp

    MattComp Private E-2

    Hi,

    I found the "TDSSserv.sys" file and disabled it. Super Anti-Spyware is working now. I'll run this and any of the other programs that will work and post the logs as soon as they're done.

    Matthew
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know...I'll be here when you get the logs attached. :)
     
  7. MattComp

    MattComp Private E-2

    Here are the 3 of the logs. Due to the earlier problems, the programs were run in the order: MGTools, SuperAntiSpyware, Spybot, Malware Bytes, ComboFix.
     

    Attached Files:

  8. MattComp

    MattComp Private E-2

    Here is the fourth log.

    Matthew
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good....thought I see some leftovers from Norton. Please re-boot into normal mode and then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  10. MattComp

    MattComp Private E-2

    Hi,

    I've attached the new zip file. The Norton files are likely the Norton AntiVirus 2003 that came with the computer. Someone installed it awhile ago and it never gets used, so I'll just uninstall it.

    Matthew
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can use this to uninstall it: Norton Removal Tool.

    Also Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    and finally you may like to have this:
    ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    If you are not having any other malware issues, then:

     
  12. MattComp

    MattComp Private E-2

    I went through all of the procedures and the computer seems to be running fine now.

    Thank you,

    Matthew
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds