Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Browser Redirect

[Fixed] Hijackthis! Logs - [Fixed] Browser Redirect posted in the Security & Safety forums; Hey guys merry new year I have a issue were some sites i visit i will be redirected to 85.255.115.163 i have done a full spy ware and virus scan ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-02-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 3
madnz - See this Members User comments on their Profile page
Default [Fixed] Browser Redirect

Hey guys merry new year

I have a issue were some sites i visit i will be redirected to 85.255.115.163
i have done a full spy ware and virus scan and nothing.
Attached Files
File Type: log hijackthis.log (8.0 KB, 3 views)



Last edited by madnz; 01-02-2006 at 01:07 AM.
  #2  
Old 01-02-2006
Silver Member
 
Join Date: Jun 2005
Location: Canada
Posts: 218
Nathan - See this Members User comments on their Profile page Nathan - See this Members User comments on their Profile page
Default

Hi madnz, welcome to PCHF! I'm not fully qualified to read hijack this logs, but someone who is will be around shortly to help you out.


__________________

  #3  
Old 01-02-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 3
madnz - See this Members User comments on their Profile page
Default

Cool thanks, ill just await and try not to smash my pc


  #4  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Madnz , lets see what we can do.



Before fixing things with HijackThis Please Do the Following:


Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.
Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Please download CCleaner

You might have a LOP infection that often comes together with Messenger Plus. To remove it we will try the simple way first.


1. Go to Add/Remove programs. Double click on "Messenger Plus!" (or click on Remove) (see quote below!)

2. The "Messenger Plus! - Setup" is now displayed. Click on the Uninstall button. Note: options displayed on the first screen are not related to the sponsor program.

3. The sponsor screen is now displayed (if you don't see it, search for it in your Task Bar). To prove that someone is currently reading the screen, you have to type the code that is displayed. Once you enter the code, press Uninstall.

4. If you entered the code properly, the program will ask you to confirm that you want to uninstall. You must answer "Yes" to this question, else, you won't have another chance of uninstalling.

5. To complete the uninstallation, follow the instructions that are displayed (the first one is to close all your Internet Explorer windows, that's very important). When everything is complete, restart your computer and, hopefully one nasty infection is gone.



When removing Lop.com from the Add/Remove screen it may not show up as Messenger Plus instead also look for these and remove them:

Window Search
Window Searching
Lop.com
LOP SEARCH
Browser Enhancer
Ultimate Browser Enhancer
L.O P. Un insta11
L O.P. Un instal1
Live 0n line Portal
Live.0nli ne Porta1
Window Active

Finally there is a step in the removal process of Messneger Plus where the sponsor asks if you want to uninstall that aswell, You have to click YES to this part of the removal process

If you dont do this corretly then you will have no other choice but to reinstall Messenger Plus and then go through the whole removal process again from the start.


Then boot in safemode (hit f8 when boting up) and fix these with hjt:


O4 - HKLM\..\Run: [dmuzb.exe] C:\WINDOWS\system32\dmuzb.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC0F5417-9811-4661-8D15-E94F251F2C96}: NameServer = 85.255.113.123,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC245462-9A3F-4CE8-9967-DB85A75C2BB6}: NameServer = 85.255.113.123,85.255.112.76
Then run ccleaner , and delete the file in bold.

Then post a new hjt log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 01-02-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 3
madnz - See this Members User comments on their Profile page
Default

hey joe5 here is the updated hjt:
Attached Files
File Type: txt hijackthis2.txt (6.4 KB, 2 views)


  #6  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looks clean to me , only i would disable the windows messenger service:

Please download Shoot The Messenger

Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state ? running or disabled ? that you desire.

If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.

Do you still have any problems?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Resolved] Browser keeps pageing back Grayel Peripherals 4 01-04-2007 07:21 AM
[Tech News] Opera Quietly Ships Mini Browser Newsie IT News 0 12-20-2005 08:30 PM
[Tech News] Nokia Launches Open-Source Browser Newsie IT News 0 11-03-2005 01:30 AM
[Tech News] Flock Founder Hopes New Browser Will Fly Newsie IT News 0 10-24-2005 05:30 PM
Thinking about switching to an alternative web browser? What's Out There? merlin Web, Internet and Network Tutorials 0 08-01-2005 06:11 AM

All times are GMT +1. The time now is 05:49 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top