• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 18:50
CET 00:50
KST 08:50
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
TL.net Map Contest #21: Winners11Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13TL.net Map Contest #21: Voting12[ASL20] Ro4 Preview: Descent11
Community News
Weekly Cups (Nov 3-9): Clem Conquers in Canada0SC: Evo Complete - Ranked Ladder OPEN ALPHA2StarCraft, SC2, HotS, WC3, Returning to Blizzcon!45$5,000+ WardiTV 2025 Championship7[BSL21] RO32 Group Stage4
StarCraft 2
General
SC: Evo Complete - Ranked Ladder OPEN ALPHA Mech is the composition that needs teleportation t Weekly Cups (Nov 3-9): Clem Conquers in Canada RotterdaM "Serral is the GOAT, and it's not close" TL.net Map Contest #21: Winners
Tourneys
Tenacious Turtle Tussle Constellation Cup - Main Event - Stellar Fest Sparkling Tuna Cup - Weekly Open Tournament $5,000+ WardiTV 2025 Championship Merivale 8 Open - LAN - Stellar Fest
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 499 Chilling Adaptation Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened Mutation # 496 Endless Infection
Brood War
General
FlaSh on: Biggest Problem With SnOw's Playstyle BW General Discussion BGH Auto Balance -> http://bghmmr.eu/ [ASL20] Ask the mapmakers — Drop your questions Where's CardinalAllin/Jukado the mapmaker?
Tourneys
[Megathread] Daily Proleagues [ASL20] Grand Finals [BSL21] RO32 Group A - Saturday 21:00 CET [BSL21] RO32 Group B - Sunday 21:00 CET
Strategy
PvZ map balance Current Meta How to stay on top of macro? Soma's 9 hatch build from ASL Game 2
Other Games
General Games
Nintendo Switch Thread Stormgate/Frost Giant Megathread Should offensive tower rushing be viable in RTS games? Path of Exile Dawn of War IV
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine US Politics Mega-thread Canadian Politics Mega-thread The Games Industry And ATVI
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
[Manga] One Piece Anime Discussion Thread Movie Discussion! Korean Music Discussion Series you have seen recently...
Sports
2024 - 2026 Football Thread Formula 1 Discussion NBA General Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Learning my new SC2 hotkey…
Hildegard
Coffee x Performance in Espo…
TrAiDoS
Saturation point
Uldridge
DnB/metal remix FFO Mick Go…
ImbaTosS
Reality "theory" prov…
perfectspheres
Our Last Hope in th…
KrillinFromwales
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1470 users

Trojan removal HELP!

Blogs > imBLIND
Post a Reply
imBLIND
Profile Blog Joined December 2006
United States2626 Posts
Last Edited: 2010-01-24 20:00:11
January 24 2010 19:39 GMT
#1
I have an Alureon trojan that keeps creating a registry key that rewrites my DNS servers and hijacks my processes so that every time i input new dns servers, it just hijacks those new ones instead.

From Hijackthis:

O17 - HKLM\System\CCS\Services\Tcpip\..\{843E7ADF-E671-4CE3-B51A-7D90A04EDE28}: NameServer = 68.238.64.12,68.238.96.12

I found the registry key and deleted it, but in doing so i had to input my dns servers again, which created the the registry key above again.

What really bugs me is that all these parameters are all legit parameters and recreate themselves because they're pretty important to the internet...there's something manipulating these keys or renaming them but i can't find it.

also tried setting it to '0', but then a .sys file tries to fix it(avira keeps catching it) and says it's from C:System Volume Information. Another one from a mysterious C file contains an exploit which i think is the executable or the updater. Neither of them stops trying, even if i delete it.

Hijack this doesn't work because it has the same effect as manually deleting. Virus scan has worked to some degree, but the DNS thing is still happening. Avira hasn't found the trojan. CCCleaner had no effect. I have no idea how to use combofix.

Please help i have no idea what else i can do..

*
im deaf
R1CH
Profile Blog Joined May 2007
Netherlands10341 Posts
January 24 2010 19:43 GMT
#2
Are you able to get to online scanners such as http://www.eset.com/onlinescan/ and http://quickscan.bitdefender.com/ ?
AdministratorTwitter: @R1CH_TL
TL+ Member
imBLIND
Profile Blog Joined December 2006
United States2626 Posts
Last Edited: 2010-01-24 20:13:43
January 24 2010 19:46 GMT
#3
yes ima post them in a bit h/o

edit:
Bitdefender didn't find anything and esat is taking a lot longer

Eset is still going, but it found an Olmarik.SV trojan. I kinda doubt this one rewrites rewrites DNS servers though...

Oh i forgot to mention: whenever i input my DNS servers and click okay, a msg pops up and says there's another adapter with the same IP Address as mine, and i click "no i don't want to change it," and then the comp works for about 3 seconds and then the TCP/IP screen disappears. Whatever i have, it recognizes that process after i click something and recreates the registry key.

The msg that says theres another comp w/ the same IP address doesn't surprise me cause i sometimes unplug/replug my adapter into a new USB port (i have a static IP address too), but that msg itself is new which makes me suspicious of it..
im deaf
Manit0u
Profile Blog Joined August 2004
Poland17425 Posts
January 24 2010 19:58 GMT
#4
Some things you could try out:

1. Turn off system restore (and keep it that way for the rest of your life).
2. Perform a full system scan with Avira (once I had a really nasty trojan, looking over internet I saw a couple of super-complicated solutions that involved downloading various stuff, restarting in safe mode, launching them in correct order, changing the registry and so on... A simple full scan solved the problem for me without all this bullshit).
Time is precious. Waste it wisely.
Severedevil
Profile Blog Joined April 2009
United States4839 Posts
January 24 2010 19:58 GMT
#5
Either think unsexy thoughts, or just finish. And next time buy lubricated Trojans.
My strategy is to fork people.
ghermination
Profile Blog Joined April 2008
United States2851 Posts
January 24 2010 19:59 GMT
#6
Reformat, after moving all your games and whatnot onto a seperate partition so you don't lose them.
U Gotta Skate.
imBLIND
Profile Blog Joined December 2006
United States2626 Posts
January 24 2010 20:05 GMT
#7
@manit0u : i just did a full system scan and the only trojans it found were from ADVLoader a while back. But why do i need to turn off system restore? i use it as a last ditch effort to fix my computer and sometimes it works...it didn't this time.

@ghermination: i dun have the XP CD, none of my friends have the CD, and i am too poor to go ask the computer guy to use his CD.
im deaf
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
January 24 2010 20:38 GMT
#8
On January 25 2010 05:05 imBLIND wrote:
@ghermination: i dun have the XP CD, none of my friends have the CD, and i am too poor to go ask the computer guy to use his CD.

Although it's not legal, I'd say one word: torrents.
BlissX1
Profile Blog Joined October 2009
United States328 Posts
January 24 2010 20:39 GMT
#9
get some purell if it is a virus and pour it on your hardrive. if its a trojan than get a girl
XtremeOneZ 4 Life Bliss[x.1]
Patriot.dlk
Profile Blog Joined October 2004
Sweden5462 Posts
January 24 2010 20:53 GMT
#10
Malwarebytes and Spybot search and destroy, download those update them and run full scans.

Something keeps writing to your registry? hrmm use http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx to find out all about your running processes

imBLIND
Profile Blog Joined December 2006
United States2626 Posts
Last Edited: 2010-01-24 21:15:53
January 24 2010 21:10 GMT
#11
@slimshady: I've been torrenting for a few years now, and i can say for a fact that torrenting the actual windows 7 or XP is a total waste of time without a really good keygen. Not gonan waste my time dling that and spend a week looking for a keygen that works

@patriot: i don't care about the malware cause thats ez to delete. I'm tryin to get rid of the trojan changin my dns and sendin me the malware. process explorer didnt have any suspicious looking .dlls

I was browsing through my registry and found the "real" Tcpip file. The key i posted above is being remade by the trojan..
im deaf
Athos
Profile Blog Joined February 2008
United States2484 Posts
January 24 2010 21:15 GMT
#12
I thought this was going to be about condoms.
ghermination
Profile Blog Joined April 2008
United States2851 Posts
January 24 2010 21:18 GMT
#13
On January 25 2010 06:15 Athos wrote:
I thought this was going to be about condoms.

Actually me too... i thought he had tried to cram himself into a small condom and gotten stuck or something.
U Gotta Skate.
canucks12
Profile Blog Joined June 2009
Canada812 Posts
January 24 2010 21:18 GMT
#14
Try Activescan. It got rid of a trojan that Norton couldn't

It requires a subscription to get it to remove everything, but any malicious or dangerous viruses/spyware will be removed for free.
imBLIND
Profile Blog Joined December 2006
United States2626 Posts
January 24 2010 21:47 GMT
#15
didnt work..
im deaf
yesplz
Profile Blog Joined April 2009
United States295 Posts
January 25 2010 00:08 GMT
#16
http://www.bleepingcomputer.com/forums/forum103.html
Ask here they will be able to help you better
BlissX1
Profile Blog Joined October 2009
United States328 Posts
January 25 2010 07:46 GMT
#17
Purell is the best way to go
XtremeOneZ 4 Life Bliss[x.1]
Please log in or register to reply.
Live Events Refresh
Replay Cast
23:00
Enki Epic Series #6 | LiuLi Cup #47
CranKy Ducklings114
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
CosmosSc2 35
StarCraft: Brood War
Shuttle 733
Artosis 523
Free 146
Dota 2
monkeys_forever219
Super Smash Bros
PPMD44
Other Games
Grubby4541
summit1g2694
shahzam515
Maynarde140
ZombieGrub43
fpsfer 3
Organizations
Other Games
BasetradeTV84
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 16 non-featured ]
StarCraft 2
• davetesta55
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• mYiSmile1105
• Eskiya23 23
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• masondota2809
League of Legends
• imaqtpie2622
Other Games
• Scarra1106
Upcoming Events
WardiTV Korean Royale
12h 10m
OSC
17h 10m
Replay Cast
23h 10m
Replay Cast
1d 9h
Kung Fu Cup
1d 12h
Classic vs Solar
herO vs Cure
Reynor vs GuMiho
ByuN vs ShoWTimE
Tenacious Turtle Tussle
1d 23h
The PondCast
2 days
RSL Revival
2 days
Solar vs Zoun
MaxPax vs Bunny
Kung Fu Cup
2 days
WardiTV Korean Royale
2 days
[ Show More ]
PiGosaur Monday
3 days
RSL Revival
3 days
Classic vs Creator
Cure vs TriGGeR
Kung Fu Cup
3 days
CranKy Ducklings
4 days
RSL Revival
4 days
herO vs Gerald
ByuN vs SHIN
Kung Fu Cup
4 days
BSL 21
4 days
Tarson vs Julia
Doodle vs OldBoy
eOnzErG vs WolFix
StRyKeR vs Aeternum
Sparkling Tuna Cup
5 days
RSL Revival
5 days
Reynor vs sOs
Maru vs Ryung
Kung Fu Cup
5 days
WardiTV Korean Royale
5 days
BSL 21
5 days
JDConan vs Semih
Dragon vs Dienmax
Tech vs NewOcean
TerrOr vs Artosis
Wardi Open
6 days
Monday Night Weeklies
6 days
Liquipedia Results

Completed

Proleague 2025-11-07
Stellar Fest: Constellation Cup
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
BSL Season 21
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual

Upcoming

SLON Tour Season 2
BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
RSL Revival: Season 3
META Madness #9
BLAST Bounty Winter 2026
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
BLAST Rivals Fall 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.