Free PC Performance Scan

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » Anti-Virus » casinofree2004

Anti-Virus - casinofree2004 posted in the Security & Safety forums; Hello, I have this hidden malware witch I can't seem to nail. As my english isn't good enough to explain, I'll paste a copy of another post in this forum ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 09-14-2008
New Poster
 
Join Date: Sep 2008
Posts: 1
PC Experience: Some Experience
mumera - See this Members User comments on their Profile page
Default casinofree2004

Hello, I have this hidden malware witch I can't seem to nail. As my english isn't good enough to explain, I'll paste a copy of another post in this forum that describes exactly what I'm going through:


" I've run ewido in safemode, I've run Spybot Search and Destroy as well as Adaware (with all the latest updates). And yet I can't seem to nail down this virus that evades my virus scans and everything else. It hijacks any links when I click on Google, yahoo etc and sends me to spam-like sites (all on firefox by the way). I believe it's downloaded things as well, seeing that every once in a while I'll find a shortcut to casinofree2400.com that has appeared on my desktop out of nowhere. I apologize for the frustrated tone of this article, I always felt I was up to snuff on preventing infection and the like (using zonealarm, having Network Associates VirusScan constantly running, and running anti-spyware software once a week). Those darn hackers have gotten the best of me. My HijackThis log is as follows: Thanks for your help"

I have followed the instructions you gave to this guy and this is the report I've got from mbam.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Carpetas Infectadas:
(No se han detectado elementos maliciosos)

Ficheros Infectados:
C:\WINDOWS\system32\ (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\casino1.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\casino2.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\casino3.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdssadw.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssl.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssmain.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdsslog.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\tdssserv.sys (Trojan.Agent) -> Delete on reboot.

Please help me. Thank you.
mumera.




  #2  
Old 09-14-2008
Jelly Bean's Avatar
Moderation Team Leader
My PC
 
Join Date: Feb 2008
Location: Swansea
Posts: 7,431
PC Experience: I Try My Best.
Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page
Send a message via MSN to Jelly Bean Send a message via Yahoo to Jelly Bean Send a message via Skype™ to Jelly Bean
Default Re: casinofree2004

Hello and welcome to PCHelpForum.

Please do not use another members thread they may have other issues to deal with.

Please click this and follow instructions:Prework

If you need any help please ask.


__________________
It is all in the hardware..........................................
Sources:
Microsoft Home Page /Seagate Home Page /Petri Home Page

PCHF Rules / Home Page / Prework /Windows Vista Home Page / XBOX360 / Test your Internet Speed
  #3  
Old 09-16-2008
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,856
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default Re: casinofree2004

Hello mumera, and welcome to PCHF.

Jelly Bean is very correct. Please follow her instructions and let us know how it goes.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Tags
casino , casinofree2004 , firefox problem , hidden , hijack , malware , mbam , new virus , virus

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 09:29 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top