Member Panel


Sponsors and Ads

Live Tag Cloud

[Fixed] Hijackthis! Logs - browser hijacked? posted in the Security & Safety forums; You may want to print these out. please close all other applications, start hjt again, click 'perform system scan only', place a tick next to the following and click 'fix ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #19  
Old 01-14-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,585
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: browser hijacked?

You may want to print these out. please close all other applications, start hjt again, click 'perform system scan only', place a tick next to the following and click 'fix checked'

O4 - HKLM\..\Run: [AOL Plaxo Support] PlaxoSoftware.exe
O4 - HKLM\..\RunServices: [AOL Plaxo Support] PlaxoSoftware.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab


reboot, and post a new hjt and sdfix log.

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #20  
Old 01-15-2008
keller130's Avatar
Bronze Member
 
Join Date: Jan 2008
Posts: 42
PC Experience: Some Experience
keller130 - See this Members User comments on their Profile page
Default Re: browser hijacked?

As requested. Behavior unchanged.

thanks
norm
Attached Files
File Type: log hijackthis.log (9.8 KB, 2 views)
File Type: txt SDFix report.txt (2.4 KB, 2 views)


  #21  
Old 01-15-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,585
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: browser hijacked?

okay, sdfix and hjt are showing that the trojan is clean. What is the aberrant behaviour you are still experiencing? Is it redirections, or other issues? Let's dump the cache and go from there as well.

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #22  
Old 01-16-2008
keller130's Avatar
Bronze Member
 
Join Date: Jan 2008
Posts: 42
PC Experience: Some Experience
keller130 - See this Members User comments on their Profile page
Default Re: browser hijacked?

Valis,

I used ATF cleaner as you suggested and the behavior is still there. This is what is happening - first of all, I cannot get to AntiVirus, Anti-Spyware, Endpoint Security, Backup, Storage, and Compliance Solutions - Symantec Corp. - IE says site can't be displayed - makes it hard to download virus updates for my Norton Antivirus. Also, Microsoft Corporation just sits there and hangs. Some websites that we have gone to in the past such as Wilderness Survival: Free info covering all aspects of survival. which my daughter likes to look at comes up with a gay porn site. If I try to search the registry for, say, wilderness, to see if there is some entry that is causing the vectoring, regedit sits there for a few seconds searching and then the system spontaneously reboots.

While we have certainly cleared out some trojans that were on the system, there must be something else that is causing these problems.

I appreciate all your help and hope we can get to the bottom of this.

thanks
norm


  #23  
Old 01-16-2008
keller130's Avatar
Bronze Member
 
Join Date: Jan 2008
Posts: 42
PC Experience: Some Experience
keller130 - See this Members User comments on their Profile page
Default Re: browser hijacked?

addendum -

I just downloaded firefox and find that I can access symantec, microsoft and wilderness-survival with no problems. Of course, this doesn't fix the problem with searching the registry. Just wanted to give you the additional info.

norm


  #24  
Old 01-16-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,585
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: browser hijacked?

could you post a new hjt log and sdfix log please?

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Default Browser Issues Mullet_Fish General Software 1 01-29-2007 11:42 AM
Auto Reboot (again) bagofcrap24 All other Hardware 3 10-17-2006 09:25 AM
Wuaueng.dll Errors in Applications Logs Debutante Windows XP/2000 9 06-25-2006 01:51 AM
Enigma Browser PraiseJah General Software 1 03-14-2006 09:41 PM
[Pending] HJT log - hijacked IE browser jmarkey71 [Fixed] Hijackthis! Logs 1 05-31-2005 02:29 PM


All times are GMT +1. The time now is 12:17 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top