GroovingPict
2008-08-23, 20:36
I need some help.
I was visiting a website, suddenly a pop-up came up, and before I had even time to close it I had been f***ed, and a rootkit and other malware had installed itself.. I managed to remove some of it though, but not all.
One of the effects it has is that many servernames (such as the one for this forum) is looped to 127.0.0.1 (I had to look up the ip address to even get here).
My DNS server settings are ok. My hosts file is ok.
I downloaded RootAlyzer, and it found some files, all having filenames beginning with tdss* hidden in the system32 folder. I tried deleting them with RootAlyzer, but two of them could not be deleted. their filenames are tdssl.dll and tdssadw.dll
I *think* that if I could delete those, then I wouldve rid myself of this problem completely.. but, how do I delete them? I've tried doing it in safe mode too of course, but no luck.
Cheers,
Tor
I was visiting a website, suddenly a pop-up came up, and before I had even time to close it I had been f***ed, and a rootkit and other malware had installed itself.. I managed to remove some of it though, but not all.
One of the effects it has is that many servernames (such as the one for this forum) is looped to 127.0.0.1 (I had to look up the ip address to even get here).
My DNS server settings are ok. My hosts file is ok.
I downloaded RootAlyzer, and it found some files, all having filenames beginning with tdss* hidden in the system32 folder. I tried deleting them with RootAlyzer, but two of them could not be deleted. their filenames are tdssl.dll and tdssadw.dll
I *think* that if I could delete those, then I wouldve rid myself of this problem completely.. but, how do I delete them? I've tried doing it in safe mode too of course, but no luck.
Cheers,
Tor