Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 07-06-2009, 06:09 PM   #1 (permalink)
Registered User
 
Join Date: Jul 2009
Posts: 1
OS: Windows Vista


Help with virus removal

Hello,

I am a draftsman, and as a student I used the AutoDesk Student Community download utility to try out AutoCAD 2010. During the installation process, I was alerted that Autodesk is temporarily out of student licenses, and to continue with the install which will work as a trial version until activated in the future by one of the new licenses.

Today the trial expired, and I went to go get a key for the software, and I was alerted with the same message. In frustration I started looking for a keygen. I was perfectly aware of the risks but continued regardless, and as a result my machine is now infected.

Both avast anti-virus and windows defender caught the virus immediately but had no effect. This is a link to the file that caused all the trouble:

http://Click this link only if you u...ntains malware Link REMOVED

The only immediate result of opening the file was an alert by windows defender and avast anti-virus; However, a few minutes after, internet explorer windows began popping up on their own. When this first began happening, I did not have any internet explorer windows open.

The pop ups only go to a handful of sites; Although it queries the site differently each time so that the content is different.

So far I have saved these for reference:

http://allabout.biz/search/index.php?said=af104&q= query+here
http://thecoolerreview.com/srch/search.php?track=sg3&qq= query+here
http://impression.name/search/index.php?said=a09&q= query+here

Immediately after I noticed this problem, I updated SpyBot Search and Destroy, and did a full system scan. The scan revealed a few threats, and I attempted to fix them. Of the 8 or 9 categories of found threats, all but five were permanently removed. The other 5 were removed but only temporarily, and they were listed as "DNSflush.cws". I removed them for the second time, but I am unsure of whether or not they would show up in another scan. The problem currently persists so the spybot entries may not have been the culprits.


I have run a few scans on the computer, and I have pastebined them readability. They are also attached in a compress archive if you would prefer to download them.

Here are the links to the scans:
HijackThis Pastebin
DDS Pastebin
DDS Attach Pastebin
GMER Pastebin


Thank you very much for your help. Let me know if there any important details that I may have left out.
-Kent
Attached Files
File Type: zip Scan Logs.zip (11.3 KB, 3 views)

Last edited by tetonbob; 07-08-2009 at 09:22 AM. Reason: removed malicious link, munged others
musskell is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 07-08-2009, 09:45 AM   #2 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,713
OS: 2000 Pro; XP Pro; XP Home


Re: Help with virus removal

Use of keygens and cracked software is against forum rules.

http://www.techsupportforum.com/rules.php

As such, this thread is closed.

I'd suggest you reinstall your OS.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 09:28 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85