Ever got infected with the nasty DNS-Relocator virus?

United States
October 2, 2008 11:10pm CST
I recently got hit with the rogue virus, XP Antivirus 2008. When I cleaned up what I thought was all of it, I discovered something that left my jaw open. I was clean, according to several AV's, like Avira, Kaspersky, AVG, and ClamWin. Much to my surprise, every time I loaded up FireFox/IE, I would experience extremely slow internet. Now seeing as how I have DSL, that was something out of the ordinary. Then I discovered that every Google search brought up fake links, and when they were clicked on, they brought me to pages similar to those of a Parked Domain. Then it hit me; I was experiencing Round 2 of the virus. I discovered 2 things about this virus: #1 - it changes certain Registry Keys, thus disabling you to change you desktop/screensaver. #2 - it places a group of hidden files in the System32 folder. You are unable, under any circumstances, to remove them. They are of a certain group, with the leader known as "TDSSADW.dll". If you find a similar error, download a great tool called SDFIX. SDFIX enables you acces to those TDSSADW dll's, and allows you to delete them. You don't need to format or reinstall Windows. Just simply run the app, and shout for joy!(2nd step is optional). I know myLot isn't really a blog board, but I hope that this will help someone. I would like to hear your success story of when you had a virus. How did you remove it? What did you use? I believe that by sharing our experiences we can help others. Hopefully this has helped someone!
1 response
@rsa101 (37969)
• Philippines
3 Oct 08
I also had a malware attack the past couple of weeks. I was infected by these virtumonde malware. My AV Kaspersky failed to identify it as well. What I did was join this forum www.geekstogo.com. They were the ones that have identified the problem with the use of Hijackthis software. All I need to do was send them the logfile of the Hijackthis where they gather information about your registry and they advise you to do something in your computer. so far they have solved my problem. It has never bothered me again and the internet was again fast. although it took me about three days before I was able to clean my PC of the Dlls and some registry entries that block cleaning them.
• United States
3 Oct 08
Yep, virtumonde is pretty bad. Did you use Vundo-fix? or even one called fix-vundo? I repaired a computer a few weeks ago that was filled with Vundo. More like voodoo... The computer was fixed, and I used the standard tools: An AV, an Anti-Spyware, the two tools above, and SFDIX. When I repair a computer, I 95% of the time use at least 2 scanners, and then leave one installed for the customer. That way I know if something slips by one, it will be caught by the other. HijackThis is fantastic software, and provides some of the best logs available. Keep it safe and keep it clean!