I've got Copy-Book malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by christurphy, Nov 19, 2008.

  1. christurphy

    christurphy Private E-2

    Hello,
    Google started playing up for me a few days ago. When I turn on my Firefox I get the message "The page isn't redirecting properly" instead of the Google home page and when I use the search box it directs me to the wrong places. I've done all the steps on the Read and Run me thread apart from ComboFix which won't install because it thinks I've got Win32 (I have 2000 sp4). Spybot found 2entries of a Zlob.DNSchanger and erased them and Malwarebytes found 2 Trojan.DNSchanger and erased them too. This seemed to work yesterday but today the same thing's happening. I erased the viruses again but this time it didn't work. I'm attaching the logs I managed to get and would be very grateful for help. Thanks. Chris
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The infection you have is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    After doing the above, tell us how things are working.

    Note: ComboFix runs just fine on Windows 2000 SP4! The only thing you can not do is install the Recovery Console using the instructions that were given since they are for Windows XP.
     
  3. christurphy

    christurphy Private E-2

    Ok, I've reset the router and it doesn't seem to have had any effect other than now my housemate's got the same thing I think (seems to happen less on his computer and he won't let me touch it to get a better look). I still cant get combofix to work. when I click on the downloaded folder I get "error - Win32 only" message saying "Incompatible OS. ComboFix only works for Windows 2000 and XP". I have windows 2000!
    Also, I did the scans again this morning with the internet unplugged. Super Anti-spyware picked up a tracking cookie (attached log), but the other scans showed nothing. When I plugged the internet back in Spybot found the same Zlob as yesterday. Does this mean the virus is on the router? How dangerous is it, can I still check my bank statements and other password protected stuff?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If either PC still has the infection, it will keep reinfecting your router. Both/all PCs need to be cleaned and then the router needs to be reset.

    Please try deleting the version of ComboFix that you have and download from the below link to your Desktop

    combofix.exe

    Now after saving the above to your Desktop, double click on it to see if it will run.


    Cookies are not problems. I suggest that you make sure you have the current database for SAS installed and run a new scan. Attach the new log.

    You also need to update Malwarebytes to the current database and run a new scan. Attach the new log.

    Yes it means you were reinfected and that your router is probably still infected or other PCs are respreading the infection. It is more annoying than dangerous. It will cause all kinds of redirections and make it difficult to get to many websites.

    You need to clean ALL PCs on your network and then reset the router.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds