Malware Problems
For the past three days I've been scratching my head at some Malware somewhere on my PC. I'm still not entirely sure where it came from but the only thing that made me suspicious was that any Google result would jump me to seemingly random pages. The link would appear OK and so the correct address. I'd click it and search-tracker.net would start loading... then a few seconds later any number of page redirects would happen then I'd end up anywhere. sometimes it was the page I wanted, most times it wasn't. The most amusing one was my search for some info on some iPhone 3.0 changes and I ended up at a blackberry page.
After scanning my entire computer numerous times with Trend Internet Security Pro and AdAware nothing major came back and the problem remained.
Today, I finally cracked it. A forum post discribing something similar had the answer - ComboFix. You can find the program here: http://www.bleepingcomputer.com/combofix/. This program took half the time any other scan took and actually got rid of the problem. I think it was one of these three files at fault:
One note of warning!!! Bleeping Computer recommends not using ComboFix unless one of their experts recommends it for your situation. Also not that ComboFix resets a lot of your customizations. I was getting really annoyed so I ignored both these warnings but you may not be so lucky.
One more note of warning. I'm not sure of the payload of this so to be safe I suggest changing all your passwords after you've removed the malware.
After scanning my entire computer numerous times with Trend Internet Security Pro and AdAware nothing major came back and the problem remained.
Today, I finally cracked it. A forum post discribing something similar had the answer - ComboFix. You can find the program here: http://www.bleepingcomputer.com/combofix/. This program took half the time any other scan took and actually got rid of the problem. I think it was one of these three files at fault:
- c:\windows\system32\drivers\MSIVXrepajqitioipqfxtpymewvvqbstksydj.sys
- c:\windows\system32\MSIVXiilttodnmsscucfonbrspgbebixdynsm.dll
- c:\windows\system32\MSIVXrwdiswrsfvujlfcxtpdpopbbqxsfxvpx.dll
One note of warning!!! Bleeping Computer recommends not using ComboFix unless one of their experts recommends it for your situation. Also not that ComboFix resets a lot of your customizations. I was getting really annoyed so I ignored both these warnings but you may not be so lucky.
One more note of warning. I'm not sure of the payload of this so to be safe I suggest changing all your passwords after you've removed the malware.
Comments