| Note: I am not posting a HijackThis log because I CANNOT RUN HijackThis due to the virus (I assume). I also cannot run ComboFixer, nor download Spybot, etc, because the virus redirects my browser away from most web-security related sites. I've tried many other forums, and this one, for whatever reason, is the only one that loads.
Also note that I cannot run FireFox or Opera, again, I assume because of the virus. I can use MSN Explorer, and I get less redirects on it than with IE, but I will get a Page Cannot Be Found even with MSN if I try to download spybot or go to most security sites. I will try any links you give me, but they are typically unsuccessful. I can't really even screw around on the Microsoft site for any XP-related security updates.
I downloaded BTU/smitfraud fix/roguescannerfix via AIM file sharing. I am attempting to do the same with ComboFixer, but as the virus does not allow me to open many exe files now, I don't know how successful that will be (I open them, nothing happens - I used TaskManager to monitor what happens and the programs close after appearing on it for half a second).
Anyway, to the problem: AVG picked up "malburst" and supposedly dealt with all of the resulting infected files. Apparently it did not, as I started getting webpage redirects and obnoxious popups telling me that I had spyware and to download X fake security software. BTU ended up fixing the popup problem, but not the page-redirect problem. BTU did point me at a registry file called browseui preloader. I also discovered that browseui.dll might have been modified. I attempted to download a replacement dll, and managed to do so after trying a million sites that were redirected. Unfortunately, I cannot replace the current browseui.dll file. I could not delete the old one, though I did manage to move it once. Afterwards, I put the new dll file in my system folder, but next reboot it was gone and I was back to the old one (I know by the file size - they were different by 5k).
Any suggestions? |