amazing malware


Recommended Posts

A buddy of mine has been calling me almost everyday for about a week about is browser being hijacked. He's being redirected to downloadalot.com.

I've run Adaware and Spybot and even the free version of Spy Sweeper (can't download updates) and a lot of stuff gets flagged and removed. Everything things find except something is eating up his resources and hijacking IE AND Firefox! Well it doesn't really hijack FF. When you load FF it tries to go to something like wnefkjwdanfkjasndfjkn.com but says it can't find it. The start page gets reset.

I thought about running HijackThis but a lot of sites don't allow you to post logs. And I've posted at one almost a week ago and got nothing. Any good sites that I can get quick results from?

Link to comment
Share on other sites

What's eating up the resources? You didn't really give any information on the problem.

the firefox issue is interesting--can you copy and paste the address string here?

Edited by bsarmir
Link to comment
Share on other sites

Try SpyWareBlaster, It supports IE & Mozilla. Best of all it doesnt need to be running in the background to have protection enabled & you can update it's protection files from it's server as well.

Link to comment
Share on other sites

He says he's already got Spyware Blaster installed and checks for updates quite often. He had older version of Adaware installed.

CWShredder just remove CoolWeb stuff. It didn't find anything. Spybot pretty much took care of a lot of CW stuff.

Downloaded and ran HijackThis. Looks like it the scan gets about 90% of the way and then just stops. If I hit CTRL/ALT/DEL it says it's not responding and I have to end the task.

I even tried running it in safe mode.

Well gonna try running Norton AV. It takes forever, because it's an old slow 350MHz sys with 288MB of RAM running 98 and he's got the whole systems works installed so it really uses up resources.

Sorry but I can't post the address string. Already changed it in FF back to normal when I thought everything was running ok. What I can read from HijackThis it's all random garbage. It's a search assistant and there another search item below it about a BHO that's missing a file. Looks like the Send2Noun\Dog up.exe he deleted because it wasn't there and didn't look familiar.

Edited by goofy_monk
Link to comment
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.