Home » Questions » Computers [ Ask a new question ]

Removing malware of a particular kind

Removing malware of a particular kind

I need to remove some malware from my computer. It is a trojan, and very annoying. It blocks access to Google and search sites. The trojan, with its name spelled out on each line cause it seems to block sites when i reference it in a url, is

Asked by: Guest | Views: 193
Total answers/comments: 2
Guest [Entry]

"Can you locate the executable? If so, boot into a linux LiveCD and blast it off the face of your filesystem. It may well recreate itself, if it's got hidden agents hiding around, so grab a copy of Autoruns and check what's loading behind your back.

edit: And have you checked your Hosts file?
C:\WINDOWS\SYSTEM32\DRIVERS\ETC
That's where Pre-DNS level filtering happens, worth a look."
Guest [Entry]

"The reason you can't get to Google and the other search sites is because the virus has added all those lines to your hosts file. The line:

127.0.0.1 google.com

will mean that all requests to google.com will be redirected back to your machine, which obviously can't serve them.

As Phoshi says you should remove these lines from the hosts file. However, I would guess that the virus will try to recreate them the next time you boot the PC. By making the file read only it won't be able to update it again and you'll be able to connect to the sites previously blocked."