Member Panel


Sponsors and Ads

Live Tag Cloud

[Fixed] Hijackthis! Logs - browser hijacked? posted in the Security & Safety forums; could you also post a new sdfix report for them to look at? thannks, v...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #31  
Old 01-18-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,585
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: browser hijacked?

could you also post a new sdfix report for them to look at?

thannks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #32  
Old 01-18-2008
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,585
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: browser hijacked?

had one of the other experts (the guys who taught me) take a look, and here is his response below:

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open *notepad* and copy/paste the text in the quotebox below into it:

Killall::

File::
C:\WINDOWS\SYSTEM32\RSVP322.DLL
C:\WINDOWS\system32\oldwn.tmp
C:\WINDOWS\system32\oldws.tmp

Folder::
C:\Program Files\Viewpoint
Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.


Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.

*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*

thanks to pancake for that.

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #33  
Old 01-19-2008
keller130's Avatar
Bronze Member
 
Join Date: Jan 2008
Posts: 42
PC Experience: Some Experience
keller130 - See this Members User comments on their Profile page
Default Re: browser hijacked?

Thanks, Valis and thanks to Pancake. Previous post executed and logs attached. No change to the symptoms. I look forward to any addional thoughts on the matter.

norm
Attached Files
File Type: txt combofix.txt (15.0 KB, 1 views)
File Type: log hijackthis.log (9.3 KB, 2 views)
File Type: txt SDFix report.txt (2.4 KB, 1 views)


  #34  
Old 01-20-2008
dahli's Avatar
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 548
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: browser hijacked?

Hello keller130,

There isn't much showing in those logs but you definitely have a problem. Let's try a couple other things.

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://swandog46.geekstogo.com/Fixwareout.exe

Save it to your desktop and run it.
Click Next, then Install, then make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.

You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.

When your system reboots, follow the prompts.

If your system does not reboot, then reboot it manually.

Please boot into Normal Mode and select the following with HijackThis.
With all windows (including this one!) closed (close browser/explorer windows), please select "fix.”

O4 - HKLM\..\Run: [TkBellExe] \"C:\Program Files\Common Files\Real\Update_OB\realsched.exe\" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] \"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe\"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

Close HijackThis, and click OK to proceed.


* Go to Control Panel. - If you are using Windows XP's Category View, select the Network and Internet Connections category. If you are in Classic View, go to the next step.

Double-click the Network Connections icon
Right-click the Local Area Connection icon and select Properties.
Higlight Internet Protocol (TCP/IP) and click the Properties button.
Be sure Obtain DNS server address automatically is selected.
OK your way out.

* Go to Start > Run and type in cmd
Click OK.
This will open a command prompt.
Type or copy and paste the following line in the command window:

ipconfig /flushdns

Hit Enter.
Exit the command window.


Reboot your computer again.

Please post the contents of the logfile C:\fixwareout\report.txt, along with a new HijackThis log.


Download SilentRunners.vbs
Unzip it to a permanent folder.
Read here how to unzip/extract properly:
Help removing and preventing spyware - Compressed folders XP
Start SilentRunners.vbs
When your antivirus is giving an alert, do not block this. Allow the script.
When the scan is done, notepad will open with a log in it. Please close this again.
I'll need that log later.
Normally that log is saved automatically in your silent runners-folder.
Post the log it created.


__________________
Steve
  #35  
Old 01-20-2008
keller130's Avatar
Bronze Member
 
Join Date: Jan 2008
Posts: 42
PC Experience: Some Experience
keller130 - See this Members User comments on their Profile page
Default Re: browser hijacked?

I have executed your commands as directed, please find the logs attached. FYI there has been no change to the symptoms at this point. Look forward to your continued support.

thanks
norm
Attached Files
File Type: txt fixwareout report.txt (1.4 KB, 2 views)
File Type: log hijackthis.log (9.1 KB, 1 views)
File Type: txt Startup Programs (NK_COMP) 2008-01-20 12.02.09.txt (15.4 KB, 1 views)


  #36  
Old 01-20-2008
dahli's Avatar
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 548
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: browser hijacked?

Sorry, I was just looking through this thread again. Are you still getting the same errors with SDFix?


__________________
Steve

Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Default Browser Issues Mullet_Fish General Software 1 01-29-2007 11:42 AM
Auto Reboot (again) bagofcrap24 All other Hardware 3 10-17-2006 09:25 AM
Wuaueng.dll Errors in Applications Logs Debutante Windows XP/2000 9 06-25-2006 01:51 AM
Enigma Browser PraiseJah General Software 1 03-14-2006 09:41 PM
[Pending] HJT log - hijacked IE browser jmarkey71 [Fixed] Hijackthis! Logs 1 05-31-2005 02:29 PM


All times are GMT +1. The time now is 08:11 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top