Friend of mine’s XP Pro machine has gotten something really nasty. Any hyperlink that is clicked on takes you somewhere other than the link’s address. This happens in both Internet Explorer and Firefox. PC has ZoneAlarm Security Suite installed. Doing a full virus/malware scan with it finds nothing. Malwarebytes’ Anti-Malware found a couple pieces of adware and a single trojan, killed them all. Ad-Aware found two pieces of adware, killed them. Not seeing anything strange in the IE or FF add-ons. Can’t run an online scan with something like Trend Micro’s Housecall, because clicking on a link to it takes me somewhere else 🙁 Any suggestions?
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Links HIjacked
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Links HIjacked
- This topic has 17 replies, 10 voices, and was last updated 15 years, 2 months ago.
Viewing 7 reply threadsAuthorReplies-
WSunkamunka
AskWoody Lounger -
Jonesy47
AskWoody PlusFebruary 5, 2010 at 1:00 pm #1208195What happens when Internet addresses are manually typed into the address bar of a browser?
I get to the right site that way. Almost ready for the “nuke it” solution: Hosts file is OK, HIjackThis didn’t find anything, and HouseCall didn’t either. If I can find a way to recover the XP Pro product key, I’ll just save his files to an external hard drive and wipe and reinstall XP.
-
joep517
AskWoody MVPFebruary 5, 2010 at 2:50 pm #1208215I get to the right site that way. Almost ready for the “nuke it” solution: Hosts file is OK, HIjackThis didn’t find anything, and HouseCall didn’t either. If I can find a way to recover the XP Pro product key, I’ll just save his files to an external hard drive and wipe and reinstall XP.
Have you used something like Autoruns for Windows to see what is getting started when you boot the system?
Have you checked the file association for the type .url?
Joe
--Joe
-
-
WSHeyJude
AskWoody LoungerFebruary 4, 2010 at 8:53 am #1207945Have you tried going into Safe Mode and running Trend Micro from there? Safe Mode is usually reached by tapping the F8 key continuously before the Windows screen comes up after rebooting. Once you get the screen, choose Safe Mode With Networking and you will be able to access the internet and try running TM from there.
Hey Jude
WSDoc Brown
AskWoody LoungerFebruary 4, 2010 at 10:43 am #1207972Take a look at the HOSTS file. Located at C:WINDOWSsystem32driversetc. The file has no extension but is only a text file and can be opened with Notepad. After all the lines that start with #, there generally should only be one entry:
127.0.0.1 localhost
If there’s more, then probably some malware or trojan added its own lines to this file to redirect traffic to malicious servers.
WSSpiritWind
AskWoody LoungerFebruary 4, 2010 at 11:54 am #1207991I highly recommend your friend seek the assistance of the experienced,
CERTIFIED, Volunteer “Malware Removal Specialists” on the Geeks To
Go Forums at http://www.geekstogo.com/forum/forums.html ,
SPECIFICALLY in their “Virus, Spyware and Trojan Removal” forum .
They have a “Malware Cleaning Guide” and I recommend your friend
starts by posting Logs of the “GMER Rootkit Scanner” and “OTL”
as mentioned in the “Guide” .-
satrow
AskWoody MVPFebruary 4, 2010 at 12:27 pm #1207998I highly recommend your friend seek the assistance of the experienced,
CERTIFIED, Volunteer “Malware Removal Specialists” on the Geeks To
Go Forums at http://www.geekstogo.com/forum/forums.html ,
SPECIFICALLY in their “Virus, Spyware and Trojan Removal” forum .
They have a “Malware Cleaning Guide” and I recommend your friend
starts by posting Logs of the “GMER Rootkit Scanner” and “OTL”
as mentioned in the “Guide” .Agree with Robin on this; it reads like a possible TDSS infection but my choice of help forum would be Majorgeeks. Malware cleaning guide, read it carefully, write down any errors encountered and good luck 🙂
WSCLiNT
AskWoody Lounger-
satrow
AskWoody MVPFebruary 4, 2010 at 5:06 pm #1208079Before running through hoops trying to manually fix something like this, I would consider your
friends system as compromised. The only 100% way to be sure is a clean instal.If there’s an MBR infection, even that may not be enough and perhaps render the drive completely inaccessible; I prefer to find the problem then decide how to deal with it.
WSCLiNT
AskWoody Lounger-
satrow
AskWoody MVPFebruary 4, 2010 at 7:28 pm #1208100I miss something?
A complete format will wipe everything, including MBR.You may think so, yes – but if the MBR infection has moved the actual boot data and linked to it instead, breaking that link by replacing the MBR with a normal MBR can lead to inacessable data or a write-protected drive. If an infected MBR uses encryption, similar result. MBR virusses have been rare since W85/98; Vista/7 use different boot techniques leading to new infection explorations.
Best to diagnose correctly before writing the prescription.
-
WSCLiNT
AskWoody LoungerFebruary 5, 2010 at 5:11 pm #1208245You may think so, yes – but if the MBR infection has moved the actual boot data and linked to it instead, breaking that link by replacing the MBR with a normal MBR can lead to inacessable data or a write-protected drive. If an infected MBR uses encryption, similar result. MBR virusses have been rare since W85/98; Vista/7 use different boot techniques leading to new infection explorations.
Best to diagnose correctly before writing the prescription.
This is way out there, extremely rare, a little too sophisticated for your average rootkit. Like grasping at straws, not to mention a waste of time.
If you have to time and zeal to look into, fine. Otherwise nuke it and be done with it. Consider the system compromised.
-
satrow
AskWoody MVPFebruary 5, 2010 at 3:34 pm #1208223-
Anonymous
InactiveFebruary 12, 2010 at 8:59 pm #1209190I fixed your link, which was broken. The Magical Jelly Bean Keyfinder is used to recover the XP Pro product key.
-
Jonesy47
AskWoody PlusFebruary 13, 2010 at 8:51 am #1209225I fixed your link, which was broken. The Magical Jelly Bean Keyfinder is used to recover the XP Pro product key.
I used that program to recover the XP Pro product key, and have the new hard drive installed, Windows Update churning away, and getting ready to put the old hard drive in an external enclosure and transfer the data files to the new setup. When I fired up the PC to do the product key recovery, the onboard VGA port decided to stop working, so I had to dig up an AGP video card, too 🙁
-
rc primak
AskWoody_MVPFebruary 15, 2010 at 10:47 am #1209423When I fired up the PC to do the product key recovery, the onboard VGA port decided to stop working, so I had to dig up an AGP video card, too 🙁
A driver update for your VGA might help recover the onboard port. You can go to the manufacturer’s web site once you know which vendor made your VGA or your motherboard. This information can be found by using Belarc Advisor.
-- rc primak
-
-
rc primak
AskWoody_MVPFebruary 6, 2010 at 3:59 am #1208311Doing a full virus/malware scan with it finds nothing. Malwarebytes’ Anti-Malware found a couple pieces of adware and a single trojan, killed them all. Ad-Aware found two pieces of adware, killed them. 🙁 Any suggestions?
Focusing on what has been accomplished, I would say first try the suggestion about emptying your Hosts File. If the redirect goes away, then the removals did their job, but did not restore the Hosts File. That can happen.
But if the problem goes away and then returns, or doesn’t go away at all, the next step is a Safe Mode scan with the two programs you have tried. Before doing this, try to get new updates for Malwarebytes. If this does not succeed (server cannot be reached), then I would go straight to a wipe and reinstall.
The point is, if the malware is still able to block or redirect access to antivirus update servers, you probably have a deeply embedded Trojan which will resist all efforts to remove it. That’s when it is safest to do the wipe/reinstall routine.
Magic Jellybean is a good product key recovery tool for Windows XP. If this was an original manufacturer install of Windows XP, the Product Key should also be printed on a sticker on the side or back (bottom if this is a laptop) of the computer.
If you suspect that MBR information has been messed with, go to a local INDEPENDENT PC service shop (NOT any Big Box Store!), tell them what happened, and ask for “low-level reformatting”. This is the equivalent of running a disk wiping (not just reformatting) program like Darik’s Boot And Nuke, but you will not have to do this difficult and time-consuming operation yourself. It would be well worth the money to leave low-level reformatting to the Pros. The shop can probably also recover your Product Key and reinstall Windows XP and most of your software and updates as part of their service. You could then rest assured that your refreshed Windows XP installation is clean and safe.
If you have an Image Backup for your system, do not use it — that backup could have preserved the infection. Delete all recent backup files, if there are any.
(By “you” I mean of course your friend.)
-- rc primak
Viewing 7 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Where’s the cache today?
by
Up2you2
6 hours, 26 minutes ago -
Ascension says recent data breach affects over 430,000 patients
by
Nibbled To Death By Ducks
13 hours, 32 minutes ago -
Nintendo Switch 2 has a remote killing switch
by
Alex5723
57 minutes ago -
Blocking Search (on task bar) from going to web
by
HenryW
7 hours, 7 minutes ago -
Windows 10: Microsoft 365 Apps will be supported up to Oct. 10 2028
by
Alex5723
23 hours, 40 minutes ago -
Add or Remove “Ask Copilot” Context Menu in Windows 11 and 10
by
Alex5723
23 hours, 47 minutes ago -
regarding april update and may update
by
heybengbeng
1 day, 1 hour ago -
MS Passkey
by
pmruzicka
3 hours, 12 minutes ago -
Can’t make Opera my default browser
by
bmeacham
1 day, 8 hours ago -
*Some settings are managed by your organization
by
rlowe44
19 hours, 39 minutes ago -
Formatting of “Forward”ed e-mails
by
Scott Mills
1 day, 7 hours ago -
SmartSwitch PC Updates will only be supported through the MS Store Going Forward
by
PL1
2 days, 3 hours ago -
CISA warns of hackers targeting critical oil infrastructure
by
Nibbled To Death By Ducks
2 days, 12 hours ago -
AI slop
by
Susan Bradley
6 hours, 27 minutes ago -
Chrome : Using AI with Enhanced Protection mode
by
Alex5723
2 days, 13 hours ago -
Two blank icons
by
CR2
1 day, 1 hour ago -
Documents, Pictures, Desktop on OneDrive in Windows 11
by
ThePhoenix
2 minutes ago -
End of 10
by
Alex5723
3 days, 1 hour ago -
Single account cannot access printer’s automatic duplex functionality
by
Bruce
1 day, 23 hours ago -
test post
by
gtd12345
3 days, 7 hours ago -
Privacy and the Real ID
by
Susan Bradley
2 days, 21 hours ago -
MS-DEFCON 2: Deferring that upgrade
by
Susan Bradley
23 hours, 53 minutes ago -
Cant log on to oldergeeks.Com
by
WSJonharnew
3 days, 11 hours ago -
Upgrading from Win 10
by
WSjcgc50
1 day, 23 hours ago -
USB webcam / microphone missing after KB5050009 update
by
WSlloydkuhnle
2 days, 3 hours ago -
TeleMessage, a modified Signal clone used by US government has been hacked
by
Alex5723
4 days, 3 hours ago -
The story of Windows Longhorn
by
Cybertooth
3 days, 15 hours ago -
Red x next to folder on OneDrive iPadOS
by
dmt_3904
4 days, 5 hours ago -
Are manuals extinct?
by
Susan Bradley
1 day, 5 hours ago -
Canonical ditching Sudo for Rust Sudo -rs starting with Ubuntu
by
Alex5723
4 days, 14 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.