Posted 14 January 2011 - 09:52 PM
Hello everyone, I just want to say first that I have visited this site many times when fixing my computer or others, so thank you to everyone for this great community. I am a relatively competent computer user, and have never had problems removing malware in the past- until now, which is of course why I am here! I returned from my lunch break at work today to find the shared computer running one of those fake virus scans. I'm sure you've run into them before. I have rkill and hijackthis permanently installed on that computer because, being a shared computer, this kind of thing sadly tends to pop up once a month or so. I ran rkill, killed all the processes, then ran hijackthis and instantly recognized the shady KJHSDJF.exe (or whatever it was) file in a temp directory and removed it. This seemed to fix the problem at first, however, I could not open up any webpages afterwards. This was fixed by removing a proxy server which I assume must be from the malware, which was pointed at 127.0.0.1 with a strange port I didn't recognize (sorry, didn't save which port it was using). I removed this proxy server and all my webpages were loading fine again, however I noticed now that many of my searches were being redirected to SCOUR.COM. I restarted my computer in safe mode, ran HJT again, but did not see anything suspicious, so rebooted once more and then ran malwarebytes. It did find a few minor things, however nothing which I thought would solve the google redirect problem. Upon restarting, the problem seemed to have gotten worse: now I could not directly open ANY webpage, except for google, which is something I've never seen before. Now I am forced to seek help from my home computer. I tried restarting the shared computer at work in safe mode, and even in safe mode I could not even ping common sites such as yahoo.com, cnn.com, etc. But I can still run google searches, pull up current news search results, etc. but when I click one of the links it does not work. I am out of potential solutions as my common methods have failed, and I do not see anything at all when I run HJT. The computer is running windows vista 32 bit. I hope I have given enough information, and thank you in advance for any help in solving this problem!