Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Browser Hijacked, please help!

[Fixed] Hijackthis! Logs - [Fixed] Browser Hijacked, please help! posted in the Security & Safety forums; Good evening, I've tried everything on my own and getting rid of this stuff is now beyond me. I'd greatly appreciate any help you could provide. My browser recently got ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-03-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 3
tacojoe77 - See this Members User comments on their Profile page
Default [Fixed] Browser Hijacked, please help!

Good evening,

I've tried everything on my own and getting rid of this stuff is now beyond me. I'd greatly appreciate any help you could provide.

My browser recently got hijacked and it has caused all sorts of system problems. I've run scans/cleans on AVG, McAfee, Adaware, and Ewido (in and out of safe mode). I've been able to clean/delete many files but regardless, my system is still jacked. (pop-ups, browser crashes, system freezes, and this annoying bar at the top of my screen with a scolling text saying "warning your system is infected, click here, etc)

Some of the viruses dectected are:
Startpage-DU.dll
ADClicker-AJ.gen
NewMalware.q

Can anyone please help or offer direction on where to go from here? I greately appreciate your time and efforts on this one.

Best regards,

Joe

Attached is my HiJackthis log (I've run Ewido several times)
Attached Files
File Type: log hijackthis.log (6.3 KB, 0 views)


  #2  
Old 01-03-2006
Silver Member
 
Join Date: Jun 2005
Location: Canada
Posts: 218
Nathan - See this Members User comments on their Profile page Nathan - See this Members User comments on their Profile page
Default

Hi tacojoe77, welcome to PCHF. I'm not fully qualified to read hijackthis logs, however someone that is will be around shortly to help you out.


__________________

  #3  
Old 01-03-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 3
tacojoe77 - See this Members User comments on their Profile page
Default

Thanks for the warm welcome Nathan!

I tried using a few new pieces of software (still having issues) and generated a new hijackthis logfile. Much thanks to anyone that can help out!

Best regards,

Joe
Attached Files
File Type: log hijackthis2.log (6.0 KB, 2 views)


  #4  
Old 01-03-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Joe :smiley: , this is Joe. :azn:



Before fixing things with HijackThis Please Do the Following:


Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.


Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.


Please download CCleaner

Then boot in safemode (hit f8 when booting up)


Click Start>Run and type in: services.msc
Click OK
In the Services window find:

Remote Procedure Call (RPC) Helper

Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open HJT and click config > misc tools > ?delete an NT service?
Copy and past:

11F??#????`I

Click OK.


and then fix these with hjt:

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [ntdi.exe] C:\WINDOWS\system32\ntdi.exe
O4 - HKLM\..\Run: [2CF.tmp] C:\DOCUME~1\Joe\LOCALS~1\Temp\2CF.tmp.exe
O4 - HKLM\..\Run: [2CF.tmp.exe] C:\DOCUME~1\Joe\LOCALS~1\Temp\2CF.tmp.exe
O4 - HKLM\..\Run: [msvs.exe] C:\WINDOWS\msvs.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 11F??#????`I) - Unknown owner - C:\WINDOWS\sdkfr32.exe (file missing)
Then delete the files in bold if present , and run Ccleaner.


I see you seem to have no firewall , to be protected for things like this you really should have one.
Have a look in our download section for some free ones.

Then please post a new hjt log to check.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 01-05-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 3
tacojoe77 - See this Members User comments on their Profile page
Default

Thanks for the help Joe! I followed your steps and havn't had any problems since! You're amazing! I do use the windows xp built in firewall, is that not secure enough these days? Also I sit behind a basic firewall built into our router.

Here is my HJT log


Thanks again!

- Joe
Attached Files
File Type: log hijackthis4.log (5.6 KB, 1 views)



Last edited by tacojoe77; 01-05-2006 at 12:23 AM.
  #6  
Old 01-05-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Always happy to help. :smiley: And youre log is clean.


Only i would check if the windows firewall is really on , and i dont know why i missed it but i see you have 2 AV's installed , that can cause conflicts and performence problems. Its best to disable the realtime protection from one , or uninstall one.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Opera Browser security with Norton change? She Internet Help 1 01-02-2006 09:11 PM
[Tech News] Opera Quietly Ships Mini Browser Newsie IT News 0 12-20-2005 08:30 PM
[Tech News] Nokia Launches Open-Source Browser Newsie IT News 0 11-03-2005 01:30 AM
Thinking about switching to an alternative web browser? What's Out There? merlin Web, Internet and Network Tutorials 0 08-01-2005 06:11 AM
[Pending] HJT log - hijacked IE browser jmarkey71 [Fixed] Hijackthis! Logs 1 05-31-2005 02:29 PM

All times are GMT +1. The time now is 06:07 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top