Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

server.pac virus


  • This topic is locked This topic is locked
2 replies to this topic

#1 doppiamunnezza

doppiamunnezza

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:10 AM

Posted 09 March 2015 - 01:33 PM

Hi all, this is Fabiano fron Italy.
I'm having exactly the same problem described in http://www.bleepingcomputer.com/forums/t/568272/google-search-redirected-to-fake-site/

but i'm not allowed to replay to that topic so i started a new one, sorry if i'm doing wrong.

 

Every now and then some process tries to downlad a proxy autoconfig script named "server.pac"

The problem appears with random frequency, sometime for three or four days it does not show up, then suddenly three times in the same day.

My antivirus (ESET) catches the event and stops the connection that tries to download the server.pac file from 93.190.137.240

and in the antivirus log the process associated with the event changes (sometimes it's "C:\Windows\System32\svchost.exe",

sometimes it's "C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE") so my guess is that somehow malicious

code is injected in legitimate processes.

The strange thing is that googling about this pulls out very few results, maybe this infection is new or has made few victims

or it's just that the majority of antiviruses don't catch it ..

My system is a windows 7 ultimate x64 fully patched, i have malwarebytes antimalware installed besides eset antivirus.

I can reinstall my pc but i would prefer to try to really understand what's going on and get rid of this pest.

So please tell me what can i do to help understanding this thing and, please, excuse my english ....

Thanks
 



BC AdBot (Login to Remove)

 


#2 Black_Bird

Black_Bird

  • Malware Response Team
  • 228 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:02:10 PM

Posted 13 March 2015 - 08:51 AM

Hi Fabiano,

Welcome to the BleepingComputer support forums! I am BlackBird and I'll be helping you during the malware removal process.

I understand you have got some malware related problems, especially redirecting problems with your browser and a malware related download that keeps popping up. Before I can help you with those problems, I need some logfiles from you though.

I'd like to ask you to read this topic and follow it's instructions:
Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help

Once done, please post the FRST logfiles into your next reply.

Good luck, and don't hesitate to ask me if you're running into problems while running the instructions above. :)
Kind regards,
Black_Bird
 

What to do when your computer is infected? Read here!

The Bleeping Computer Board Rules - The Moderating Team


If I am directly helping you on a topic and I've not replied within 24 hours please send me a Private Message with a link to your topic.


#3 Black_Bird

Black_Bird

  • Malware Response Team
  • 228 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:02:10 PM

Posted 20 March 2015 - 11:56 AM

Due to lack of feedback I'm now closing this topic. If you still need assistance regarding this issue and want this topic re-opened, please feel free to send me or any other Moderator a private message with the request to do so.


Kind regards,
Black_Bird
 

What to do when your computer is infected? Read here!

The Bleeping Computer Board Rules - The Moderating Team


If I am directly helping you on a topic and I've not replied within 24 hours please send me a Private Message with a link to your topic.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users