Virus/Trojan/? - Internet traffic being redirected

brownkc

Gawd
Joined
Nov 18, 2005
Messages
702
Do I still have malware on my computer or did it alter a setting affecting internet requests?

Last night I downloaded a file that apparently had some sort of malware in it. I believe it was a rar or zip file and when I tried to decompress it, I knew something was wrong and tried to shut it down. Something is now opening blank Internet Explorer windows and an advertisement plays over my speakers but no browsers appear to be running. I find multiple instances of ml#.exe (# is a single digit number; each instance has the next number available) in my processes. Attempts to open Firefox, result in the page being redirected. My desktop widgets are failing to run properly (Network Traffic, MSN Weather and a Game Server Monitor).

I did a quick scan with MSE and nothing was found. I downloaded Spybot Search & Destroy on another computer and installed via USB. I ran the search twice (the second time in Adminstrator mode) but it didn't seem to check all files. While it was running, I decided to download Malwarebytes. Prior to restarting in Safe Mode, MSE warned of a problem (vobfus.gen!D) and I told it to repair/fix the issue. Internet traffic was still being redirected.

After entering safe mode, I attempted to run Search & Destroy. It appeared to start but no window opened (The taskbar indicated it was open but repeated attempts to open it wouldn't present a window). I installed and updated Malwarebytes and ran a full scan overnight. I checked this morning and it found 17 issues. I had it fix them. I attempted S&D again with no luck and couldn't find a way to open MSE in safe mode (not listed in menus and not in the systray).

I restarted my computer in normal mode. S&D said there was a change in the registry by Malwarebytes and I allowed this. The widgets on my desktop are still not loading there information. I started MSE on a full scan before heading to work.

Does the redirect of internet traffic/widget issue mean that the virus/trojan/? is still active or could it have changed a setting that I need to manually revert back? Any suggestions on what my next step should be if I am still having problems when I get home today?
 
I'm guessing the latter.

Do your browsers open now?
Can you nslookup google.com?
Can you ping google.com?
Do you have any proxies in your Internet Options?
Maybe 'Automatically detect settings' under LAN settings (in the same place) is checked?
Can you either list or provide a screenshot of all Non-Plug and Play Drivers in the device manager? You'll need to check Show hidden device in the View menu.
 
It's called Hijacking. Spybot S&D or HijackThis will likely find whatever is doing it.
 
Well, something I did seemed to take care of everything but the desktop widgets. They still appear broken. MSN is a small white box with a blue circle with a white on it in the upper left corner. I can't access the settings/options for it. The game server tracker seems to be MIA. The network monitor box is there but no IP addresses or graphs are visible. There is an image symbol over it in the upper right corner. Any ideas what I need to reset or should I just reinstall?

MSE ran while I was at work and returned zero results. I ran Search & Destroy when I got home and it just picked up a few ad trackers. Both browsers (Firefox and IE) appear to be running properly now. The pointer is no longer flickering over to a wait state (glowing ring) indicating something is trying to start.
 
Have you scanned with antivirus software, or only anti malware?
 
Microsoft Security Essentials, Malwarebytes and Spybot Search & Destroy. I thought MSE was antivirus. It was recommended as an alternative to AVG.
 
MSE is an anti-virus program, but like all the others it's not going to catch everything. It's a never ending race between virus writers and AV companies.
 
Update: Back up and running.

Looks like MSE caught it at the beginning. It just took a bit to do it. By the time it quarantined the problem changes had already been made in some important places. I did run a scan with Search & Destroy and Malwarebytes. Both found some questionable programs but it looked like they were more of ad trackers.

The changes ended up preventing my desktop gadgets (sidebar style gadgets) from connecting to the network. They also knocked out Windows Media Player.


I spent several hours trying to figure out what files I needed to repair/replace and none of the suggestions I found worked. I tried using a pre-infection Win7 restore point but it said there was a registry issue and wouldn't complete the task. Luckily, I have a Windows Home Server on my network that backs up all of my computers every night. I was able to use it to restore my desktop. Everything is back up and running normally.

Thanks for the help.
 
Back
Top