Friend of mine’s XP Pro machine has gotten something really nasty. Any hyperlink that is clicked on takes you somewhere other than the link’s address. This happens in both Internet Explorer and Firefox. PC has ZoneAlarm Security Suite installed. Doing a full virus/malware scan with it finds nothing. Malwarebytes’ Anti-Malware found a couple pieces of adware and a single trojan, killed them all. Ad-Aware found two pieces of adware, killed them. Not seeing anything strange in the IE or FF add-ons. Can’t run an online scan with something like Trend Micro’s Housecall, because clicking on a link to it takes me somewhere else 🙁 Any suggestions?
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Links HIjacked
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Links HIjacked
- This topic has 17 replies, 10 voices, and was last updated 15 years, 3 months ago.
Viewing 7 reply threadsAuthorReplies-
WSunkamunka
AskWoody Lounger -
Jonesy47
AskWoody PlusFebruary 5, 2010 at 1:00 pm #1208195What happens when Internet addresses are manually typed into the address bar of a browser?
I get to the right site that way. Almost ready for the “nuke it” solution: Hosts file is OK, HIjackThis didn’t find anything, and HouseCall didn’t either. If I can find a way to recover the XP Pro product key, I’ll just save his files to an external hard drive and wipe and reinstall XP.
-
joep517
AskWoody MVPFebruary 5, 2010 at 2:50 pm #1208215I get to the right site that way. Almost ready for the “nuke it” solution: Hosts file is OK, HIjackThis didn’t find anything, and HouseCall didn’t either. If I can find a way to recover the XP Pro product key, I’ll just save his files to an external hard drive and wipe and reinstall XP.
Have you used something like Autoruns for Windows to see what is getting started when you boot the system?
Have you checked the file association for the type .url?
Joe
--Joe
-
-
WSHeyJude
AskWoody LoungerFebruary 4, 2010 at 8:53 am #1207945Have you tried going into Safe Mode and running Trend Micro from there? Safe Mode is usually reached by tapping the F8 key continuously before the Windows screen comes up after rebooting. Once you get the screen, choose Safe Mode With Networking and you will be able to access the internet and try running TM from there.
Hey Jude
WSDoc Brown
AskWoody LoungerFebruary 4, 2010 at 10:43 am #1207972Take a look at the HOSTS file. Located at C:WINDOWSsystem32driversetc. The file has no extension but is only a text file and can be opened with Notepad. After all the lines that start with #, there generally should only be one entry:
127.0.0.1 localhost
If there’s more, then probably some malware or trojan added its own lines to this file to redirect traffic to malicious servers.
WSSpiritWind
AskWoody LoungerFebruary 4, 2010 at 11:54 am #1207991I highly recommend your friend seek the assistance of the experienced,
CERTIFIED, Volunteer “Malware Removal Specialists” on the Geeks To
Go Forums at http://www.geekstogo.com/forum/forums.html ,
SPECIFICALLY in their “Virus, Spyware and Trojan Removal” forum .
They have a “Malware Cleaning Guide” and I recommend your friend
starts by posting Logs of the “GMER Rootkit Scanner” and “OTL”
as mentioned in the “Guide” .-
satrow
AskWoody MVPFebruary 4, 2010 at 12:27 pm #1207998I highly recommend your friend seek the assistance of the experienced,
CERTIFIED, Volunteer “Malware Removal Specialists” on the Geeks To
Go Forums at http://www.geekstogo.com/forum/forums.html ,
SPECIFICALLY in their “Virus, Spyware and Trojan Removal” forum .
They have a “Malware Cleaning Guide” and I recommend your friend
starts by posting Logs of the “GMER Rootkit Scanner” and “OTL”
as mentioned in the “Guide” .Agree with Robin on this; it reads like a possible TDSS infection but my choice of help forum would be Majorgeeks. Malware cleaning guide, read it carefully, write down any errors encountered and good luck 🙂
WSCLiNT
AskWoody Lounger-
satrow
AskWoody MVPFebruary 4, 2010 at 5:06 pm #1208079Before running through hoops trying to manually fix something like this, I would consider your
friends system as compromised. The only 100% way to be sure is a clean instal.If there’s an MBR infection, even that may not be enough and perhaps render the drive completely inaccessible; I prefer to find the problem then decide how to deal with it.
WSCLiNT
AskWoody Lounger-
satrow
AskWoody MVPFebruary 4, 2010 at 7:28 pm #1208100I miss something?
A complete format will wipe everything, including MBR.You may think so, yes – but if the MBR infection has moved the actual boot data and linked to it instead, breaking that link by replacing the MBR with a normal MBR can lead to inacessable data or a write-protected drive. If an infected MBR uses encryption, similar result. MBR virusses have been rare since W85/98; Vista/7 use different boot techniques leading to new infection explorations.
Best to diagnose correctly before writing the prescription.
-
WSCLiNT
AskWoody LoungerFebruary 5, 2010 at 5:11 pm #1208245You may think so, yes – but if the MBR infection has moved the actual boot data and linked to it instead, breaking that link by replacing the MBR with a normal MBR can lead to inacessable data or a write-protected drive. If an infected MBR uses encryption, similar result. MBR virusses have been rare since W85/98; Vista/7 use different boot techniques leading to new infection explorations.
Best to diagnose correctly before writing the prescription.
This is way out there, extremely rare, a little too sophisticated for your average rootkit. Like grasping at straws, not to mention a waste of time.
If you have to time and zeal to look into, fine. Otherwise nuke it and be done with it. Consider the system compromised.
-
satrow
AskWoody MVPFebruary 5, 2010 at 3:34 pm #1208223-
Anonymous
InactiveFebruary 12, 2010 at 8:59 pm #1209190I fixed your link, which was broken. The Magical Jelly Bean Keyfinder is used to recover the XP Pro product key.
-
Jonesy47
AskWoody PlusFebruary 13, 2010 at 8:51 am #1209225I fixed your link, which was broken. The Magical Jelly Bean Keyfinder is used to recover the XP Pro product key.
I used that program to recover the XP Pro product key, and have the new hard drive installed, Windows Update churning away, and getting ready to put the old hard drive in an external enclosure and transfer the data files to the new setup. When I fired up the PC to do the product key recovery, the onboard VGA port decided to stop working, so I had to dig up an AGP video card, too 🙁
-
rc primak
AskWoody_MVPFebruary 15, 2010 at 10:47 am #1209423When I fired up the PC to do the product key recovery, the onboard VGA port decided to stop working, so I had to dig up an AGP video card, too 🙁
A driver update for your VGA might help recover the onboard port. You can go to the manufacturer’s web site once you know which vendor made your VGA or your motherboard. This information can be found by using Belarc Advisor.
-- rc primak
-
-
rc primak
AskWoody_MVPFebruary 6, 2010 at 3:59 am #1208311Doing a full virus/malware scan with it finds nothing. Malwarebytes’ Anti-Malware found a couple pieces of adware and a single trojan, killed them all. Ad-Aware found two pieces of adware, killed them. 🙁 Any suggestions?
Focusing on what has been accomplished, I would say first try the suggestion about emptying your Hosts File. If the redirect goes away, then the removals did their job, but did not restore the Hosts File. That can happen.
But if the problem goes away and then returns, or doesn’t go away at all, the next step is a Safe Mode scan with the two programs you have tried. Before doing this, try to get new updates for Malwarebytes. If this does not succeed (server cannot be reached), then I would go straight to a wipe and reinstall.
The point is, if the malware is still able to block or redirect access to antivirus update servers, you probably have a deeply embedded Trojan which will resist all efforts to remove it. That’s when it is safest to do the wipe/reinstall routine.
Magic Jellybean is a good product key recovery tool for Windows XP. If this was an original manufacturer install of Windows XP, the Product Key should also be printed on a sticker on the side or back (bottom if this is a laptop) of the computer.
If you suspect that MBR information has been messed with, go to a local INDEPENDENT PC service shop (NOT any Big Box Store!), tell them what happened, and ask for “low-level reformatting”. This is the equivalent of running a disk wiping (not just reformatting) program like Darik’s Boot And Nuke, but you will not have to do this difficult and time-consuming operation yourself. It would be well worth the money to leave low-level reformatting to the Pros. The shop can probably also recover your Product Key and reinstall Windows XP and most of your software and updates as part of their service. You could then rest assured that your refreshed Windows XP installation is clean and safe.
If you have an Image Backup for your system, do not use it — that backup could have preserved the infection. Delete all recent backup files, if there are any.
(By “you” I mean of course your friend.)
-- rc primak
Viewing 7 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Identify a dynamic range to then be used in another formula (Awaiting moderation)
by
BigDaddy07
28 minutes ago -
InfoStealer Malware Data Breach Exposed 184 Million Logins and Passwords
by
Alex5723
9 hours, 17 minutes ago -
How well does your browser block trackers?
by
n0ads
4 hours, 6 minutes ago -
You can’t handle me
by
Susan Bradley
18 seconds ago -
Chrome Can Now Change Your Weak Passwords for You
by
Alex5723
4 hours, 57 minutes ago -
Microsoft: Over 394,000 Windows PCs infected by Lumma malware, affects Chrome..
by
Alex5723
20 hours, 40 minutes ago -
Signal vs Microsoft’s Recall ; By Default, Signal Doesn’t Recall
by
Alex5723
10 minutes ago -
Internet Archive : This is where all of The Internet is stored
by
Alex5723
21 hours, 4 minutes ago -
iPhone 7 Plus and the iPhone 8 on Vantage list
by
Alex5723
21 hours, 9 minutes ago -
Lumma malware takedown
by
EyesOnWindows
9 hours, 24 minutes ago -
“kill switches” found in Chinese made power inverters
by
Alex5723
1 day, 5 hours ago -
Windows 11 – InControl vs pausing Windows updates
by
Kathy Stevens
1 day, 5 hours ago -
Meet Gemini in Chrome
by
Alex5723
1 day, 9 hours ago -
DuckDuckGo’s Duck.ai added GPT-4o mini
by
Alex5723
1 day, 10 hours ago -
Trump signs Take It Down Act
by
Alex5723
1 day, 18 hours ago -
Do you have a maintenance window?
by
Susan Bradley
2 hours, 2 minutes ago -
Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms
by
Nibbled To Death By Ducks
20 hours, 16 minutes ago -
Cox Communications and Charter Communications to merge
by
not so anon
1 day, 21 hours ago -
Help with WD usb driver on Windows 11
by
Tex265
5 hours, 45 minutes ago -
hibernate activation
by
e_belmont
2 days, 6 hours ago -
Red Hat Enterprise Linux 10 with AI assistant
by
Alex5723
2 days, 10 hours ago -
Windows 11 Insider Preview build 26200.5603 released to DEV
by
joep517
2 days, 13 hours ago -
Windows 11 Insider Preview build 26120.4151 (24H2) released to BETA
by
joep517
2 days, 13 hours ago -
Fixing Windows 24H2 failed KB5058411 install
by
Alex5723
1 day, 9 hours ago -
Out of band for Windows 10
by
Susan Bradley
2 days, 17 hours ago -
Giving UniGetUi a test run.
by
RetiredGeek
3 days ago -
Windows 11 Insider Preview Build 26100.4188 (24H2) released to Release Preview
by
joep517
3 days, 8 hours ago -
Microsoft is now putting quantum encryption in Windows builds
by
Alex5723
1 day, 4 hours ago -
Auto Time Zone Adjustment
by
wadeer
3 days, 12 hours ago -
To download Win 11 Pro 23H2 ISO.
by
Eddieloh
3 days, 10 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.