February 13, 2012, 08:41:06 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: SMF - Just Installed!
 
   Home   Help Search Login Register  

Antivirus XP 2008 redirects internet "go to" addre


AddThis Social Bookmark Button AddThis Feed Button
Pages: [1]
  Print  
Author Topic: Antivirus XP 2008 redirects internet "go to" addre  (Read 4872 times)
Cof1der
Newbie
*
Posts: 1


View Profile
« on: September 19, 2008, 06:28:46 AM »

I'm infected w/ antivirus XP 2008.  I followed the suggested  task manager end process but I still have remnants (or maybe all, what do I know).  I tried going to pctools to download spyware doctor, but was redirected to some other web site.  It seems something is redirecting me to sites different from the one I enter in the "go to address" box, so I can't go to where I can download remedy.  

What do I do?  How is it doing this.  How do I locate the code that changes what I enter in internet explorer/mozilla fox "go to" address box?

P.S. This message from a different computer since I wouldn't be able to get here from my infected PC.

 :?:
Logged

Life, living and the pursuit of happiness
Bobby
Administrator
Newbie
*****
Posts: 290



View Profile
« Reply #1 on: September 21, 2008, 10:43:37 PM »

Hello there,
as you can't download the anti-spyware on the infected computer, you have to download install on another computer, then put the install on cd or usb and run it on the infected machine. i recommend malwarebytes antimalware : http://www.2-spyware.com/review-malwarebytes-anti-malware.html
Logged

I reccomend Spyware Doctor and Malwarebytes’ Anti-malware as ultimate protection.
DanaKate
Newbie
*
Posts: 3


View Profile
« Reply #2 on: December 11, 2008, 06:01:26 PM »

I found that I could get around some of the redirect by going directly to CNet and downloading from there.  I found that my version of AV09 evidently didn't consider CNet to be a threat to it.  But if my browser wasn't being rerouted to a fake AV site, I would get the message that my security software couldn't be updated or that the site I wanted to visit (AVG, Spybot, Lavasoft, whatever) was not found.  So I found a fix today on another site.  I posted in another thread here (maybe where I shouldn't, since I'm new, I dunno), but I can give another overview here in case it helps someone with similar problems.

Go to Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.  Scroll down to "Non-plug and Play Drivers" and click the plus icon to open those drivers.  Search for "TDSSserv.sys", right click on it, select Disable, and reboot your system.  Make sure you don't choose to uninstall it, because it'll just reinstall itself when you reboot.

This doesn't get rid of AV09, but it fixed my redirect problem and allowed my AVG and Spybot to update and run so I could get rid of AV09 with them.  I was also able to download and install trusted software.  I'm running Malwarebytes now to make sure I didn't miss anything, and I still did some manual registry cleanup by following the AV09 removal instructions on this site.  I hope this helps someone in a similar situation.  I was so very happy when I found this.  I couldn't wait to get home from work and try it out, and it worked like a charm for me.  :D
Logged
tamariki
Newbie
*
Posts: 2


View Profile
« Reply #3 on: December 20, 2008, 01:34:51 PM »

Had the same problem. Ran a couple of anti virus programmes, but couldn't get on their sites to download the upgrades. Downloaded spybot, installed it, but it wouldn't run.
One of the programmes I downloaded suggested running check disk. That would n't run.
Non of the previously installed spyware and anti virus programmes would run.
The solution you advised worked. When I rebooted, check disc cut in, and restored corrupted files. Ran for three minutes.
Am now able to run spybot, avast etc.
Thanks for finding a solution. Saved me re-installing Windows again.
PS
Had turned off system restore, so hope the PC in clean.
Logged
visiondash
Newbie
*
Posts: 3


View Profile
« Reply #4 on: December 20, 2008, 02:38:53 PM »

I did what you said but I can't find "TDSSserv.sys". Can it be under a different name?
Logged
tamariki
Newbie
*
Posts: 2


View Profile
« Reply #5 on: December 20, 2008, 10:03:04 PM »

After I disabled TDDS.sys, I found a solution that removed it  by downloading and running SDFix.exe.
Instructions can be obtained from here:-

http://www.computer-juice.com/forums/f49/im-under-assault-smartest-virus-ever-help-19431/
Logged
Pages: [1]
  Print  
 
Jump to:  




Recommended software:
STOPzilla
(90/100)
STOPzilla is a powerful anti-spyware program that detects, blocks, and removes malicious software allowing users to surf the Web not worrying about spyware, Trojan horses,...
Malwarebytes Anti Malware
(88/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t...
Spyware Doctor
(87/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and...
SpyHunter
(86/100)
SpyHunter is a quite simple, but yet highly effective spyware remover with an easy-to-use interface. This program is an excellent choice for users, who are...
XoftSpySE Anti Spyware
(84/100)
XoftSpySE, an anti-spyware program made by ParetoLogic, Inc., is a simple, but effective on-demand scanner with the typical set of functions but very easy to...
Encyclopedia of parasites:

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other