• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 19:21
CEST 01:21
KST 08:21
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL21] Finals Preview: Two Legacies18Code S Season 2 (2026) - RO12 Preview2herO wins GSL Code S Season 1 (2026)5Code S Season 1 (2026) - RO4 & Finals Preview5[ASL21] Ro4 Preview: On Course12
Community News
Weekly Cups (May 11-17): Classic wins double0Code S Season 1 (2026) - RO8 Results2Weekly Cups (May 4-10): Clem, MaxPax, herO win1Maestros of The Game 2 announcement and schedule !18Weekly Cups (April 27-May 4): Clem takes triple0
StarCraft 2
General
herO wins GSL Code S Season 1 (2026) Code S Season 2 (2026) - RO12 Preview Weekly Cups (May 11-17): Classic wins double Code S Season 1 (2026) - RO4 & Finals Preview Team Liquid Map Contest #22 - The Finalists
Tourneys
Crank Gathers Season 4: BW vs SC2 Team League GSL Code S Season 2 (2026) GSL Code S Season 1 (2026) Sparkling Tuna Cup - Weekly Open Tournament Maestros of The Game 2 announcement and schedule !
Strategy
Custom Maps
[D]RTS in all its shapes and glory <3 [A] Nemrods 1/4 players
External Content
Mutation # 527 Hell Train The PondCast: SC2 News & Results Mutation # 526 Rubber and Glue Mutation # 525 Wheel of Misfortune
Brood War
General
25 Years Since Brood War Patch 1.08 (Spoiler) ASL21 Winner's Interview vespene.gg — BW replays in browser [ASL21] Finals Preview: Two Legacies UA StarCraft: Mawin (T) vs hanniGan (P) Showmatch
Tourneys
[ASL21] Grand Finals Escore Tournament StarCraft Season 2 [Megathread] Daily Proleagues Small VOD Thread 2.0
Strategy
Any training maps people recommend? Muta micro map competition [G] Hydra ZvZ: An Introduction Fighting Spirit mining rates
Other Games
General Games
Stormgate/Frost Giant Megathread Nintendo Switch Thread Dawn of War IV ZeroSpace Megathread Warcraft III: The Frozen Throne
Dota 2
The Story of Wings Gaming
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia Mafia Game Mode Feedback/Ideas TL Mafia Community Thread Five o'clock TL Mafia
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Trading/Investing Thread European Politico-economics QA Mega-thread YouTube Thread
Fan Clubs
The herO Fan Club!
Media & Entertainment
[Manga] One Piece Anime Discussion Thread [Req][Books] Good Fantasy/SciFi books
Sports
2024 - 2026 Football Thread McBoner: A hockey love story TeamLiquid Health and Fitness Initiative For 2023 Formula 1 Discussion
World Cup 2022
Tech Support
streaming software Strange computer issues (software)
TL Community
The Automated Ban List
Blogs
Esports Organizations: Raisi…
TrAiDoS
Why RTS gamers make better f…
gosubay
ramps on octagon
StaticNine
Funny Nicknames
LUCKY_NOOB
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1375 users

Trojan removal HELP!

Blogs > imBLIND
Post a Reply
imBLIND
Profile Blog Joined December 2006
United States2626 Posts
Last Edited: 2010-01-24 20:00:11
January 24 2010 19:39 GMT
#1
I have an Alureon trojan that keeps creating a registry key that rewrites my DNS servers and hijacks my processes so that every time i input new dns servers, it just hijacks those new ones instead.

From Hijackthis:

O17 - HKLM\System\CCS\Services\Tcpip\..\{843E7ADF-E671-4CE3-B51A-7D90A04EDE28}: NameServer = 68.238.64.12,68.238.96.12

I found the registry key and deleted it, but in doing so i had to input my dns servers again, which created the the registry key above again.

What really bugs me is that all these parameters are all legit parameters and recreate themselves because they're pretty important to the internet...there's something manipulating these keys or renaming them but i can't find it.

also tried setting it to '0', but then a .sys file tries to fix it(avira keeps catching it) and says it's from C:System Volume Information. Another one from a mysterious C file contains an exploit which i think is the executable or the updater. Neither of them stops trying, even if i delete it.

Hijack this doesn't work because it has the same effect as manually deleting. Virus scan has worked to some degree, but the DNS thing is still happening. Avira hasn't found the trojan. CCCleaner had no effect. I have no idea how to use combofix.

Please help i have no idea what else i can do..

*
im deaf
R1CH
Profile Blog Joined May 2007
Netherlands10342 Posts
January 24 2010 19:43 GMT
#2
Are you able to get to online scanners such as http://www.eset.com/onlinescan/ and http://quickscan.bitdefender.com/ ?
AdministratorTwitter: @R1CH_TL
TL+ Member
imBLIND
Profile Blog Joined December 2006
United States2626 Posts
Last Edited: 2010-01-24 20:13:43
January 24 2010 19:46 GMT
#3
yes ima post them in a bit h/o

edit:
Bitdefender didn't find anything and esat is taking a lot longer

Eset is still going, but it found an Olmarik.SV trojan. I kinda doubt this one rewrites rewrites DNS servers though...

Oh i forgot to mention: whenever i input my DNS servers and click okay, a msg pops up and says there's another adapter with the same IP Address as mine, and i click "no i don't want to change it," and then the comp works for about 3 seconds and then the TCP/IP screen disappears. Whatever i have, it recognizes that process after i click something and recreates the registry key.

The msg that says theres another comp w/ the same IP address doesn't surprise me cause i sometimes unplug/replug my adapter into a new USB port (i have a static IP address too), but that msg itself is new which makes me suspicious of it..
im deaf
Manit0u
Profile Blog Joined August 2004
Poland17750 Posts
January 24 2010 19:58 GMT
#4
Some things you could try out:

1. Turn off system restore (and keep it that way for the rest of your life).
2. Perform a full system scan with Avira (once I had a really nasty trojan, looking over internet I saw a couple of super-complicated solutions that involved downloading various stuff, restarting in safe mode, launching them in correct order, changing the registry and so on... A simple full scan solved the problem for me without all this bullshit).
Time is precious. Waste it wisely.
Severedevil
Profile Blog Joined April 2009
United States4839 Posts
January 24 2010 19:58 GMT
#5
Either think unsexy thoughts, or just finish. And next time buy lubricated Trojans.
My strategy is to fork people.
ghermination
Profile Blog Joined April 2008
United States2851 Posts
January 24 2010 19:59 GMT
#6
Reformat, after moving all your games and whatnot onto a seperate partition so you don't lose them.
U Gotta Skate.
imBLIND
Profile Blog Joined December 2006
United States2626 Posts
January 24 2010 20:05 GMT
#7
@manit0u : i just did a full system scan and the only trojans it found were from ADVLoader a while back. But why do i need to turn off system restore? i use it as a last ditch effort to fix my computer and sometimes it works...it didn't this time.

@ghermination: i dun have the XP CD, none of my friends have the CD, and i am too poor to go ask the computer guy to use his CD.
im deaf
Shield
Profile Blog Joined August 2009
Bulgaria4824 Posts
January 24 2010 20:38 GMT
#8
On January 25 2010 05:05 imBLIND wrote:
@ghermination: i dun have the XP CD, none of my friends have the CD, and i am too poor to go ask the computer guy to use his CD.

Although it's not legal, I'd say one word: torrents.
BlissX1
Profile Blog Joined October 2009
United States328 Posts
January 24 2010 20:39 GMT
#9
get some purell if it is a virus and pour it on your hardrive. if its a trojan than get a girl
XtremeOneZ 4 Life Bliss[x.1]
Patriot.dlk
Profile Blog Joined October 2004
Sweden5462 Posts
January 24 2010 20:53 GMT
#10
Malwarebytes and Spybot search and destroy, download those update them and run full scans.

Something keeps writing to your registry? hrmm use http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx to find out all about your running processes

imBLIND
Profile Blog Joined December 2006
United States2626 Posts
Last Edited: 2010-01-24 21:15:53
January 24 2010 21:10 GMT
#11
@slimshady: I've been torrenting for a few years now, and i can say for a fact that torrenting the actual windows 7 or XP is a total waste of time without a really good keygen. Not gonan waste my time dling that and spend a week looking for a keygen that works

@patriot: i don't care about the malware cause thats ez to delete. I'm tryin to get rid of the trojan changin my dns and sendin me the malware. process explorer didnt have any suspicious looking .dlls

I was browsing through my registry and found the "real" Tcpip file. The key i posted above is being remade by the trojan..
im deaf
Athos
Profile Blog Joined February 2008
United States2484 Posts
January 24 2010 21:15 GMT
#12
I thought this was going to be about condoms.
ghermination
Profile Blog Joined April 2008
United States2851 Posts
January 24 2010 21:18 GMT
#13
On January 25 2010 06:15 Athos wrote:
I thought this was going to be about condoms.

Actually me too... i thought he had tried to cram himself into a small condom and gotten stuck or something.
U Gotta Skate.
canucks12
Profile Blog Joined June 2009
Canada812 Posts
January 24 2010 21:18 GMT
#14
Try Activescan. It got rid of a trojan that Norton couldn't

It requires a subscription to get it to remove everything, but any malicious or dangerous viruses/spyware will be removed for free.
imBLIND
Profile Blog Joined December 2006
United States2626 Posts
January 24 2010 21:47 GMT
#15
didnt work..
im deaf
yesplz
Profile Blog Joined April 2009
United States295 Posts
January 25 2010 00:08 GMT
#16
http://www.bleepingcomputer.com/forums/forum103.html
Ask here they will be able to help you better
BlissX1
Profile Blog Joined October 2009
United States328 Posts
January 25 2010 07:46 GMT
#17
Purell is the best way to go
XtremeOneZ 4 Life Bliss[x.1]
Please log in or register to reply.
Live Events Refresh
Patches Events
19:30
Patches' Patch Clash #7
RotterdaM564
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
RotterdaM 564
StarCraft: Brood War
Britney 17257
Artosis 677
Zeus 85
NaDa 32
Dota 2
NeuroSwarm150
League of Legends
JimRising 601
Other Games
gofns14982
summit1g13239
tarik_tv11315
FrodaN5073
Liquid`RaSZi2306
shahzam479
KnowMe331
kaitlyn56
RuFF_SC231
Organizations
Other Games
gamesdonequick1259
BasetradeTV77
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
[ Show 18 non-featured ]
StarCraft 2
• Hupsaiya 75
• musti20045 43
• IndyKCrew
• sooper7s
• AfreecaTV YouTube
• Migwel
• intothetv
• Kozan
• LaughNgamezSOOP
StarCraft: Brood War
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• masondota21864
Other Games
• imaqtpie1176
• WagamamaTV353
• Scarra325
• Shiphtur323
• tFFMrPink 10
Upcoming Events
OSC
39m
Universe Titan Cup
11h 39m
Rogue vs Percival
Wardi Open
12h 39m
Monday Night Weeklies
16h 39m
Replay Cast
1d
Kung Fu Cup
1d 11h
GSL
2 days
herO vs Classic
Cure vs Clem
uThermal 2v2 Circuit
2 days
Replay Cast
3 days
GSL
3 days
Maru vs SHIN
Zoun vs Rogue
[ Show More ]
WardiTV Spring Champion…
3 days
SKillous vs Strange
Lambo vs Strange
Ryung vs Strange
Lambo vs Ryung
Ryung vs SKillous
Lambo vs SKillous
Replay Cast
4 days
Maestros of the Game
4 days
Replay Cast
5 days
RSL Revival
5 days
TBD vs SHIN
TBD vs Rogue
IPSL
5 days
ZZZero vs WorsT
Julia vs eOnzErG
Replay Cast
6 days
RSL Revival
6 days
IPSL
6 days
Dragon vs Artosis
dxtr13 vs Hawk
BSL
6 days
Liquipedia Results

Completed

Escore Tournament S2: W8
2026 GSL S1
Heroes Pulsing #1

Ongoing

2026 KK StarCraft Pro League
BSL Season 22
IPSL Spring 2026
KCM Race Survival 2026 Season 2
KK 2v2 League Season 1
YSL S3
Acropolis #4
SCTL 2026 Spring
WardiTV Spring 2026
2026 GSL S2
RSL Revival: Season 5
CS Asia Championships 2026
Asian Champions League 2026
IEM Atlanta 2026
PGL Astana 2026
BLAST Rivals Spring 2026
IEM Rio 2026
PGL Bucharest 2026
Stake Ranked Episode 1
BLAST Open Spring 2026
ESL Pro League S23 Finals

Upcoming

CSCL: Masked Kings S4
Escore Tournament S2: King of Kings
BSL 22 Non-Korean Championship
CSLAN 4
Blizzard Classic Cup 2026
Kung Fu Cup 2026 Grand Finals
HSC XXIX
uThermal 2v2 2026 Main Event
Maestros of the Game 2
Bounty Cup 2026
BLAST Bounty Summer 2026
BLAST Bounty Summer Qual
Stake Ranked Episode 3
XSE Pro League 2026
IEM Cologne Major 2026
Stake Ranked Episode 2
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.