Friend of mine’s XP Pro machine has gotten something really nasty. Any hyperlink that is clicked on takes you somewhere other than the link’s address. This happens in both Internet Explorer and Firefox. PC has ZoneAlarm Security Suite installed. Doing a full virus/malware scan with it finds nothing. Malwarebytes’ Anti-Malware found a couple pieces of adware and a single trojan, killed them all. Ad-Aware found two pieces of adware, killed them. Not seeing anything strange in the IE or FF add-ons. Can’t run an online scan with something like Trend Micro’s Housecall, because clicking on a link to it takes me somewhere else 🙁 Any suggestions?
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Links HIjacked
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Links HIjacked
- This topic has 17 replies, 10 voices, and was last updated 15 years, 3 months ago.
Viewing 7 reply threadsAuthorReplies-
WSunkamunka
AskWoody Lounger -
Jonesy47
AskWoody PlusFebruary 5, 2010 at 1:00 pm #1208195What happens when Internet addresses are manually typed into the address bar of a browser?
I get to the right site that way. Almost ready for the “nuke it” solution: Hosts file is OK, HIjackThis didn’t find anything, and HouseCall didn’t either. If I can find a way to recover the XP Pro product key, I’ll just save his files to an external hard drive and wipe and reinstall XP.
-
joep517
AskWoody MVPFebruary 5, 2010 at 2:50 pm #1208215I get to the right site that way. Almost ready for the “nuke it” solution: Hosts file is OK, HIjackThis didn’t find anything, and HouseCall didn’t either. If I can find a way to recover the XP Pro product key, I’ll just save his files to an external hard drive and wipe and reinstall XP.
Have you used something like Autoruns for Windows to see what is getting started when you boot the system?
Have you checked the file association for the type .url?
Joe
--Joe
-
-
WSHeyJude
AskWoody LoungerFebruary 4, 2010 at 8:53 am #1207945Have you tried going into Safe Mode and running Trend Micro from there? Safe Mode is usually reached by tapping the F8 key continuously before the Windows screen comes up after rebooting. Once you get the screen, choose Safe Mode With Networking and you will be able to access the internet and try running TM from there.
Hey Jude
WSDoc Brown
AskWoody LoungerFebruary 4, 2010 at 10:43 am #1207972Take a look at the HOSTS file. Located at C:WINDOWSsystem32driversetc. The file has no extension but is only a text file and can be opened with Notepad. After all the lines that start with #, there generally should only be one entry:
127.0.0.1 localhost
If there’s more, then probably some malware or trojan added its own lines to this file to redirect traffic to malicious servers.
WSSpiritWind
AskWoody LoungerFebruary 4, 2010 at 11:54 am #1207991I highly recommend your friend seek the assistance of the experienced,
CERTIFIED, Volunteer “Malware Removal Specialists” on the Geeks To
Go Forums at http://www.geekstogo.com/forum/forums.html ,
SPECIFICALLY in their “Virus, Spyware and Trojan Removal” forum .
They have a “Malware Cleaning Guide” and I recommend your friend
starts by posting Logs of the “GMER Rootkit Scanner” and “OTL”
as mentioned in the “Guide” .-
satrow
AskWoody MVPFebruary 4, 2010 at 12:27 pm #1207998I highly recommend your friend seek the assistance of the experienced,
CERTIFIED, Volunteer “Malware Removal Specialists” on the Geeks To
Go Forums at http://www.geekstogo.com/forum/forums.html ,
SPECIFICALLY in their “Virus, Spyware and Trojan Removal” forum .
They have a “Malware Cleaning Guide” and I recommend your friend
starts by posting Logs of the “GMER Rootkit Scanner” and “OTL”
as mentioned in the “Guide” .Agree with Robin on this; it reads like a possible TDSS infection but my choice of help forum would be Majorgeeks. Malware cleaning guide, read it carefully, write down any errors encountered and good luck 🙂
WSCLiNT
AskWoody Lounger-
satrow
AskWoody MVPFebruary 4, 2010 at 5:06 pm #1208079Before running through hoops trying to manually fix something like this, I would consider your
friends system as compromised. The only 100% way to be sure is a clean instal.If there’s an MBR infection, even that may not be enough and perhaps render the drive completely inaccessible; I prefer to find the problem then decide how to deal with it.
WSCLiNT
AskWoody Lounger-
satrow
AskWoody MVPFebruary 4, 2010 at 7:28 pm #1208100I miss something?
A complete format will wipe everything, including MBR.You may think so, yes – but if the MBR infection has moved the actual boot data and linked to it instead, breaking that link by replacing the MBR with a normal MBR can lead to inacessable data or a write-protected drive. If an infected MBR uses encryption, similar result. MBR virusses have been rare since W85/98; Vista/7 use different boot techniques leading to new infection explorations.
Best to diagnose correctly before writing the prescription.
-
WSCLiNT
AskWoody LoungerFebruary 5, 2010 at 5:11 pm #1208245You may think so, yes – but if the MBR infection has moved the actual boot data and linked to it instead, breaking that link by replacing the MBR with a normal MBR can lead to inacessable data or a write-protected drive. If an infected MBR uses encryption, similar result. MBR virusses have been rare since W85/98; Vista/7 use different boot techniques leading to new infection explorations.
Best to diagnose correctly before writing the prescription.
This is way out there, extremely rare, a little too sophisticated for your average rootkit. Like grasping at straws, not to mention a waste of time.
If you have to time and zeal to look into, fine. Otherwise nuke it and be done with it. Consider the system compromised.
-
satrow
AskWoody MVPFebruary 5, 2010 at 3:34 pm #1208223-
Anonymous
InactiveFebruary 12, 2010 at 8:59 pm #1209190I fixed your link, which was broken. The Magical Jelly Bean Keyfinder is used to recover the XP Pro product key.
-
Jonesy47
AskWoody PlusFebruary 13, 2010 at 8:51 am #1209225I fixed your link, which was broken. The Magical Jelly Bean Keyfinder is used to recover the XP Pro product key.
I used that program to recover the XP Pro product key, and have the new hard drive installed, Windows Update churning away, and getting ready to put the old hard drive in an external enclosure and transfer the data files to the new setup. When I fired up the PC to do the product key recovery, the onboard VGA port decided to stop working, so I had to dig up an AGP video card, too 🙁
-
rc primak
AskWoody_MVPFebruary 15, 2010 at 10:47 am #1209423When I fired up the PC to do the product key recovery, the onboard VGA port decided to stop working, so I had to dig up an AGP video card, too 🙁
A driver update for your VGA might help recover the onboard port. You can go to the manufacturer’s web site once you know which vendor made your VGA or your motherboard. This information can be found by using Belarc Advisor.
-- rc primak
-
-
rc primak
AskWoody_MVPFebruary 6, 2010 at 3:59 am #1208311Doing a full virus/malware scan with it finds nothing. Malwarebytes’ Anti-Malware found a couple pieces of adware and a single trojan, killed them all. Ad-Aware found two pieces of adware, killed them. 🙁 Any suggestions?
Focusing on what has been accomplished, I would say first try the suggestion about emptying your Hosts File. If the redirect goes away, then the removals did their job, but did not restore the Hosts File. That can happen.
But if the problem goes away and then returns, or doesn’t go away at all, the next step is a Safe Mode scan with the two programs you have tried. Before doing this, try to get new updates for Malwarebytes. If this does not succeed (server cannot be reached), then I would go straight to a wipe and reinstall.
The point is, if the malware is still able to block or redirect access to antivirus update servers, you probably have a deeply embedded Trojan which will resist all efforts to remove it. That’s when it is safest to do the wipe/reinstall routine.
Magic Jellybean is a good product key recovery tool for Windows XP. If this was an original manufacturer install of Windows XP, the Product Key should also be printed on a sticker on the side or back (bottom if this is a laptop) of the computer.
If you suspect that MBR information has been messed with, go to a local INDEPENDENT PC service shop (NOT any Big Box Store!), tell them what happened, and ask for “low-level reformatting”. This is the equivalent of running a disk wiping (not just reformatting) program like Darik’s Boot And Nuke, but you will not have to do this difficult and time-consuming operation yourself. It would be well worth the money to leave low-level reformatting to the Pros. The shop can probably also recover your Product Key and reinstall Windows XP and most of your software and updates as part of their service. You could then rest assured that your refreshed Windows XP installation is clean and safe.
If you have an Image Backup for your system, do not use it — that backup could have preserved the infection. Delete all recent backup files, if there are any.
(By “you” I mean of course your friend.)
-- rc primak
Viewing 7 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Giving UniGetUi a test run.
by
RetiredGeek
16 minutes ago -
Windows 11 Insider Preview Build 26100.4188 (24H2) released to Release Preview
by
joep517
7 hours, 54 minutes ago -
Microsoft is now putting quantum encryption in Windows builds
by
Alex5723
5 hours, 52 minutes ago -
Auto Time Zone Adjustment
by
wadeer
12 hours, 23 minutes ago -
To download Win 11 Pro 23H2 ISO.
by
Eddieloh
10 hours, 3 minutes ago -
Manage your browsing experience with Edge
by
Mary Branscombe
3 hours, 50 minutes ago -
Fewer vulnerabilities, larger updates
by
Susan Bradley
1 hour, 34 minutes ago -
Hobbies — There’s free software for that!
by
Deanna McElveen
5 hours, 52 minutes ago -
Apps included with macOS
by
Will Fastie
5 hours, 29 minutes ago -
Xfinity home internet
by
MrJimPhelps
5 hours, 24 minutes ago -
Convert PowerPoint presentation to Impress
by
RetiredGeek
5 hours, 22 minutes ago -
Debian 12.11 released
by
Alex5723
1 day, 9 hours ago -
Microsoft: Troubleshoot problems updating Windows
by
Alex5723
1 day, 13 hours ago -
Woman Files for Divorce After ChatGPT “Reads” Husband’s Coffee Cup
by
Alex5723
16 hours, 39 minutes ago -
Moving fwd, Win 11 Pro,, which is best? Lenovo refurb
by
Deo
9 hours, 3 minutes ago -
DBOS Advanced Network Analysis
by
Kathy Stevens
2 days, 6 hours ago -
Microsoft Edge Launching Automatically?
by
healeyinpa
1 day, 20 hours ago -
Google Chrome to block admin-level browser launches for better security
by
Alex5723
2 days, 8 hours ago -
iPhone SE2 Stolen Device Protection
by
Rick Corbett
2 days, 1 hour ago -
Some advice for managing my wireless internet gateway
by
LHiggins
1 day, 8 hours ago -
NO POWER IN KEYBOARD OR MOUSE
by
HE48AEEXX77WEN4Edbtm
10 hours, 34 minutes ago -
A CVE-MITRE-CISA-CNA Extravaganza
by
Nibbled To Death By Ducks
2 days, 18 hours ago -
Sometimes I wonder about these bots
by
Susan Bradley
6 hours, 24 minutes ago -
Does windows update component store “self heal”?
by
Mike Cross
2 days, 4 hours ago -
Windows 11 Insider Preview build 27858 released to Canary
by
joep517
3 days, 8 hours ago -
Pwn2Own Berlin 2025: Day One Results
by
Alex5723
1 day, 16 hours ago -
Windows 10 might repeatedly display the BitLocker recovery screen at startup
by
Susan Bradley
1 day, 4 hours ago -
Windows 11 Insider Preview Build 22631.5409 (23H2) released to Release Preview
by
joep517
3 days, 10 hours ago -
Windows 10 Build 19045.5912 (22H2) to Release Preview Channel
by
joep517
3 days, 10 hours ago -
Kevin Beaumont on Microsoft Recall
by
Susan Bradley
1 hour, 22 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.