Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Nasty Rootkit that won't go! Help


  • Please log in to reply

#16
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hmm ok strange because google analytics is legitimate.
See here > http://www.google.com/analytics/

But if you are still redirected then something more is at play.

Download TDSSKiller and save it to your Desktop.

  • Right click on the file and choose extract all extract the file to your desktop then run it.
  • If prompted to restart the computer type in Y then it will restart.
  • Or if you are prompted with a hidden service warning do go ahead and delete it.
  • Once completed it will create a log in your C:\ drive
  • Please post the contents of that log

  • 0

Advertisements


#17
Katelynn

Katelynn

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
I ran that before and nothing. Hitman pro says nothing. But when searching on google it still says results5.google.co.uk/click.php and then a string of numbers and letters. This is how it started. It opens a pop up window which re-directs or doesn't load at all. Have to click 2X + in order to get to the website. What is still missing?


TDSS rootkit removing tool, Kaspersky Lab, 2010
version 2.3.2.0 May 31 2010 10:39:48

Scanning Services ...

Scanning Drivers ...

Completed

Results:
Registry objects infected / cured / cured on reboot: 0 / 0 / 0
File objects infected / cured / cured on reboot: 0 / 0 / 0

Press any key to continue . . .
  • 0

#18
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Nothing shows in your logs that I can see at this point.
But doesn't mean it isn't there.

Please click here to download Kaspersky Virus Removal Tool.

  • Double click on the file you just downloaded and let it install.
  • It will install to your desktop.
  • After that leave what is selected and put a check next to My Computer.
  • Click on the option that says Threat Detection and change it to Disinfect,delete if disinfection fails.
  • Then click on Start Scan.
  • Before it is done it may prompt for action regardless of the setting so choose delete if prompted.
  • When the scan is done no log will be produced.
  • Click on the bottom where it says Report to open the report.
  • Then highlight of of the items found by using ctrl + a on your keyboard to select all or use your mouse to select all then right click and choose copy.
  • This will copy the items that it found to the clipboard you can then open notepad (go to start then run then type in notepad) and choose paste to paste the contents into Notepad.
  • You can save this on the desktop.
  • Post the contents of the document in your next reply.

Note: This tool will self uninstall when you close it so please save the log before closing it.


  • 0

#19
Katelynn

Katelynn

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Ok thanks I will try it. At least it lets me download virus software now! I did a sophos scan last night and here are the results below. It doesn't recommend removing them, but I don't know which ones some of them are...

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22489_none_6c6c8757cd796d3e\ntkrnlpa.exe
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Windows\winsxs\x86_microsoft-windows-mulanttsvoicecommon_31bf3856ad364e35_6.0.6001.18000_none_e1e971f061eb63bb\MSTTSCommon.dll
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Program Files\Microsoft Works\lnchtour.exe
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Program Files\Install SiteGrinder 3.exe
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Users\Katelynn\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\4BRKP715\rapidresponse;net=ns;u=,ns-53961422_1277371823,1198d0d00b00644,Miscellaneous,;;kw=;tile=1;ord1=795085;sz=72
8x15;ppos=atf;contx=Miscellaneous;btg=;ord=3881857775385146[1]
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Program Files\Common Files\Adobe\Plug-Ins\CS5\File Formats\Camera Raw.8bi
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Program Files\QuickTime\QTSystem(33)\QuickTimeWebHelper.Resources\es.lproj\QuickTimeWebHelperLocalized.qtr
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6000.20904_none_d89ecc7412670658\srv.sys
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\ProgramData\Norton\00000082\00000107\000003cc\cltLMS1.dat
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\ProgramData\Norton\00000082\00000107\000003cc\cltLMS2.dat
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Downloads\21 The Movie [kevin Spacey] Quality Cam XViD AntoNN-ITL2.0 [Eng]\21 The Movie [kevin Spacey] Quality Cam XViD AntoNN-ITL2.0 [Eng].part02.rar.bc!
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21101_none_6ad49de3d019654f\ntoskrnl.exe
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)


Area: Local hard drives
Description: Unknown hidden file
Location: C:\Windows\winsxs\x86_netfx-installutillib_dll_b03f5f7f11d50a3a_6.0.6000.20883_none_a0148339f1d1c316\InstallUtilLib.dll
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)


Area: Local hard drives
Description: Unknown hidden file
Location: C:\Program Files\DiskInternals\Uneraser\Alligator.k52
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Windows\winsxs\x86_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_6.0.6000.16386_en-us_213d6d7e1c277344\imapi.dll.mui
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_none_9d81873e2afd9b5e\NlsData001b.dll
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_none_9d81873e2afd9b5e\NlsData004b.dll
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wuaueng.dll
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Program Files\LimeWire\.NetworkShare\LimeWireWin5.3.6.exe
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)
  • 0

#20
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Ok none of those are malicious.
Go ahead with my previous instructions and see what it comes up with.
  • 0

#21
Katelynn

Katelynn

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
OK! :)
  • 0

#22
Katelynn

Katelynn

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Autoscan: completed 2 minutes ago (events: 39, objects: 632166, time: 03:16:58)
6/24/2010 1:16:23 PM Task started
6/24/2010 1:37:39 PM Detected: Exploit.Java.Agent.f C:\Documents and Settings\Katelynn\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\12670d29-41a52a31/gogol/Familie.class
6/24/2010 1:37:40 PM Deleted: Exploit.Java.Agent.f C:\Documents and Settings\Katelynn\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\12670d29-41a52a31/gogol/Familie.class
6/24/2010 1:56:22 PM Detected: Trojan-PSW.Win32.Dybalom.bkn C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/keygen.exe
6/24/2010 1:56:22 PM Untreated: Trojan-PSW.Win32.Dybalom.bkn C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/keygen.exe Write not supported
6/24/2010 1:56:23 PM Detected: Trojan-PSW.Win32.Dybalom.bkn C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/CORE10k.EXE
6/24/2010 1:56:23 PM Untreated: Trojan-PSW.Win32.Dybalom.bkn C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/CORE10k.EXE Write not supported
6/24/2010 1:58:11 PM Detected: P2P-Worm.Win32.Nugg.w C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\on the road jack kerouac.zip/self_extracting_archive.exe
6/24/2010 1:58:13 PM Deleted: P2P-Worm.Win32.Nugg.w C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\on the road jack kerouac.zip/self_extracting_archive.exe
6/24/2010 2:08:41 PM Detected: Backdoor.Win32.Filth.s C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/svchost.exe
6/24/2010 2:08:41 PM Untreated: Backdoor.Win32.Filth.s C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/svchost.exe Write not supported
6/24/2010 2:08:41 PM Detected: Backdoor.Win32.IRCBot.mrg C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/taskmgr.exe
6/24/2010 2:08:41 PM Untreated: Backdoor.Win32.IRCBot.mrg C:\Documents and Settings\Katelynn\Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/taskmgr.exe Write not supported
6/24/2010 2:09:00 PM Detected: Trojan-PSW.Win32.Dybalom.bkn C:\Documents and Settings\Katelynn\My Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/keygen.exe
6/24/2010 2:09:00 PM Untreated: Trojan-PSW.Win32.Dybalom.bkn C:\Documents and Settings\Katelynn\My Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/keygen.exe Write not supported
6/24/2010 2:09:00 PM Detected: Trojan-PSW.Win32.Dybalom.bkn C:\Documents and Settings\Katelynn\My Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/CORE10k.EXE
6/24/2010 2:09:00 PM Untreated: Trojan-PSW.Win32.Dybalom.bkn C:\Documents and Settings\Katelynn\My Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/CORE10k.EXE Write not supported
6/24/2010 2:24:45 PM Detected: Backdoor.Win32.Filth.s C:\Documents and Settings\Katelynn\My Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/svchost.exe
6/24/2010 2:24:45 PM Untreated: Backdoor.Win32.Filth.s C:\Documents and Settings\Katelynn\My Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/svchost.exe Write not supported
6/24/2010 2:24:45 PM Detected: Backdoor.Win32.IRCBot.mrg C:\Documents and Settings\Katelynn\My Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/taskmgr.exe
6/24/2010 2:24:45 PM Untreated: Backdoor.Win32.IRCBot.mrg C:\Documents and Settings\Katelynn\My Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/taskmgr.exe Write not supported
6/24/2010 2:34:50 PM Detected: HEUR:Trojan.Win32.Generic C:\Program Files\EarthLink TotalAccess\WENGINE\NTErr10.dll
6/24/2010 3:09:55 PM Detected: Trojan-PSW.Win32.Dybalom.bkn C:\Users\Katelynn\Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/keygen.exe
6/24/2010 3:09:55 PM Untreated: Trojan-PSW.Win32.Dybalom.bkn C:\Users\Katelynn\Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/keygen.exe Write not supported
6/24/2010 3:09:55 PM Detected: Trojan-PSW.Win32.Dybalom.bkn C:\Users\Katelynn\Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/CORE10k.EXE
6/24/2010 3:09:55 PM Untreated: Trojan-PSW.Win32.Dybalom.bkn C:\Users\Katelynn\Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/CORE10k.EXE Write not supported
6/24/2010 3:17:09 PM Detected: Backdoor.Win32.Filth.s C:\Users\Katelynn\Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/svchost.exe
6/24/2010 3:17:09 PM Untreated: Backdoor.Win32.Filth.s C:\Users\Katelynn\Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/svchost.exe Write not supported
6/24/2010 3:17:09 PM Detected: Backdoor.Win32.IRCBot.mrg C:\Users\Katelynn\Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/taskmgr.exe
6/24/2010 3:17:09 PM Untreated: Backdoor.Win32.IRCBot.mrg C:\Users\Katelynn\Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/taskmgr.exe Write not supported
6/24/2010 3:18:32 PM Detected: Trojan-PSW.Win32.Dybalom.bkn C:\Users\Katelynn\My Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/keygen.exe
6/24/2010 3:18:32 PM Untreated: Trojan-PSW.Win32.Dybalom.bkn C:\Users\Katelynn\My Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/keygen.exe Write not supported
6/24/2010 3:18:32 PM Detected: Trojan-PSW.Win32.Dybalom.bkn C:\Users\Katelynn\My Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/CORE10k.EXE
6/24/2010 3:18:32 PM Untreated: Trojan-PSW.Win32.Dybalom.bkn C:\Users\Katelynn\My Documents\LimeWire\Saved\Adobe Master Collection CS5 Keygen & Patch Only CORE.rar/CORE10k.EXE Write not supported
6/24/2010 3:32:36 PM Detected: Backdoor.Win32.Filth.s C:\Users\Katelynn\My Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/svchost.exe
6/24/2010 3:32:36 PM Untreated: Backdoor.Win32.Filth.s C:\Users\Katelynn\My Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/svchost.exe Write not supported
6/24/2010 3:32:36 PM Detected: Backdoor.Win32.IRCBot.mrg C:\Users\Katelynn\My Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/taskmgr.exe
6/24/2010 3:32:36 PM Untreated: Backdoor.Win32.IRCBot.mrg C:\Users\Katelynn\My Documents\LimeWire\Saved\Adobe Photoshop CS4 Extended + Activator & Serial.rar/Adobe Photoshop CS4/ACTIVATE Adobe Photoshop/Photoshop CS4 Activation Blocker.exe/data0000.cab/taskhost.exe/data0000.cab/taskmgr.exe Write not supported
6/24/2010 4:33:22 PM Task completed
  • 0

#23
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Still redirecting?

Also I noticed you have and adobe keygen this type of software is illegal and is a major cause of infections.
You may have not been infected by using this crack but it is still illegal to crack and use the software.
I recommend removing it. (Adobe) and this folder > Adobe Photoshop CS4 Extended + Activator & Serial.rar
  • 0

#24
Katelynn

Katelynn

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Yes still re-directing. I removed the adobe files today but I know that they aren't it beacuse it is still re-directing. This was my partner's laptop before he gave it to me, and I didn't know the software was on there. I caught that and delated it. But still re-directing, any suggestions why?
  • 0

#25
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Let's see if something else is present.

Download the following GMER Rootkit Scanner from Here

  • Download the randomly named EXE file to your Desktop. Remember what its name is since it is randomly named.
  • Double click on the new random named exe file you downloaded and run it. If prompted about the Security Warning and Unknown Publisher go ahead and click on Run
  • It may take a minute to load and become available.
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED

  • IAT/EAT
  • Drives/Partition other than Systemdrive (typically only C:\ should be checked)
  • Show All (don't miss this one)

  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop
  • **Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
  • Click OK and quit the GMER program.
  • Note: On Firefox you need to go to Tools/Options/Main then under the Downloads section, click on Always ask me where to save files so that you can choose the name and where to save to, in this case your Desktop.
  • Post that log in your next reply.

  • 0

Advertisements


#26
Katelynn

Katelynn

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
I tried to GMER last night and during the scan it crashed. The computer went blue with white writing and said it was shutting down to save my computer. The other laptop in the house is also infected with this re-direct virus and nothing works. Neither of us has downloaded the same thing, nor do we visit the same websites. When the other laptop had GMER run on it a few days ago, he said it crashed and went to blue screen too. I am afraid to try it again.
  • 0

#27
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please try it with everything in the right hand side unchecked except for sections and run it like this.
See if you can get me a log.
  • 0

#28
Katelynn

Katelynn

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
I tried to do that but it stops working and windows looks for a solution. Then it just goes to a black screen on GMER and Clt+Alt+Dlt doesn't work and I have to shut my computer down via button...what ever this virus is, I really really hate it! Argh! LOL
  • 0

#29
Katelynn

Katelynn

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
I have been reading about some other people who have the virus and suggestions are that it infects the router and dns? Is that true? Can that be fixed?
  • 0

#30
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hi please try gmer in Safe Mode.
The Dns infection usually is visible and is not he case in this situation.
If Gmer will not work in Safe Mode then we will move on to something else.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP