Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » Browser hijacked - continuous redirects

[Fixed] Hijackthis! Logs - Browser hijacked - continuous redirects posted in the Security & Safety forums; Thanks for the help. Ran HJT and checked the lines you noted. Attached is a new log. Brad...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 03-03-2008
Bronze Member
 
Join Date: Feb 2008
Posts: 8
PC Experience: Some Experience
winchester - See this Members User comments on their Profile page
Default Re: Browser hijacked - continuous redirects

Thanks for the help. Ran HJT and checked the lines you noted. Attached is a new log.

Brad
Attached Files
File Type: txt hijackthis03.03.08.txt (8.7 KB, 1 views)


  #9  
Old 03-04-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 545
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: Browser hijacked - continuous redirects

Disable TeaTimer

Reboot in SAFE MODE (Tap F8 during startup)

Run HijackThis and check the following:

O4 - HKLM\..\Run: [dmfne.exe] C:\Windows\system32\dmfne.exe

O4 - HKCU\..\Run: [dmsia.tmp] C:\Windows\system32\dmsia.tmp
O4 - HKCU\..\Run: [dmclg.tmp] C:\Windows\system32\dmclg.tmp
O4 - HKCU\..\Run: [dmuak.tmp] C:\Windows\system32\dmuak.tmp
O4 - HKCU\..\Run: [dmqgw.tmp] C:\Windows\system32\dmqgw.tmp
O4 - HKCU\..\Run: [dmnwo.tmp] C:\Windows\system32\dmnwo.tmp
O4 - HKCU\..\Run: [dmiks.tmp] C:\Windows\system32\dmiks.tmp
O4 - HKCU\..\Run: [dmwaj.tmp] C:\Windows\system32\dmwaj.tmp

Click FIX CHECKED

Reboot

Post a new HijackThis log.


__________________
Steve
  #10  
Old 03-05-2008
Bronze Member
 
Join Date: Feb 2008
Posts: 8
PC Experience: Some Experience
winchester - See this Members User comments on their Profile page
Default Re: Browser hijacked - continuous redirects

Thanks for the help.

- disabled tea timer
- followed the rest of your instructions
- have attached a new HJT log and also a screenshot of an HJT error message I got when opening the program; something about a Hosts file

Appreciate the assistance,
Brad
Attached Images
File Type: jpg HJT error prompt 04Mar2008.jpg (179.7 KB, 3 views)
Attached Files
File Type: txt hijackthis04.03.08.txt (8.1 KB, 1 views)


  #11  
Old 03-06-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 545
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: Browser hijacked - continuous redirects

Please do an online scan with Kaspersky WebScanner
Note: This Scanner is for Internet Explorer Only!

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading the latest definition files:
Once the files have been downloaded click on NEXT

Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)
Scan Options:Scan Archives
Scan Mail Bases

Click OK

Now under select a target to scan:Select My Computer
This will program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Then post the results from the Kapersky scan.


__________________
Steve
  #12  
Old 03-08-2008
Bronze Member
 
Join Date: Feb 2008
Posts: 8
PC Experience: Some Experience
winchester - See this Members User comments on their Profile page
Default Re: Browser hijacked - continuous redirects

Hi - thanks for the continued support.

Ran the Kaspersky scan -- completed 100% but had a b*tch of a time saving it. I continually tried to save it as a text file to my desktop, but it seemed to override saying it saved to my Temporary Internet Folders. However, never was able to find the file where they said it would be. Frustrating!

Either way, I took a screen shot of the final completed scan and have attached it. Also did another quick HJT scan and am posting that as well.

Any comment on the error about 'hosts' files I seem to get at the outset of running an HJT scan? Reattached a screenshot of that error as well.

Thanks in advance,
Brad
Attached Images
File Type: jpg Kaspersky scan march08.jpg (127.4 KB, 1 views)
File Type: jpg HJT error prompt 04Mar2008.jpg (179.7 KB, 1 views)
Attached Files
File Type: txt hijackthis08.Mar.2008.txt (8.1 KB, 1 views)


  #13  
Old 03-09-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 545
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: Browser hijacked - continuous redirects

Go to this site and submit the following files and post the results:

C:\Windows\system32\dmfne.exe

Run HijackThis and check the following:

O4 - HKCU\..\Run: [dmehc.tmp] C:\Windows\system32\dmehc.tmp
O17 - HKLM\System\CCS\Services\Tcpip\..\{0642EFCB-8E53-40C6-82BB-3788A1190ACD}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{FDC2A44D-81CB-45BC-8E16-D7D689378DD8}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{0642EFCB-8E53-40C6-82BB-3788A1190ACD}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\..\{0642EFCB-8E53-40C6-82BB-3788A1190ACD}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

Click FIX CHECKED

Post a new HijackThis log along with the result from virustotal.


__________________
Steve
  #14  
Old 03-09-2008
Bronze Member
 
Join Date: Feb 2008
Posts: 8
PC Experience: Some Experience
winchester - See this Members User comments on their Profile page
Default Re: Browser hijacked - continuous redirects

Thanks Steve. Virustotal result and new HJT log attached. Fixed all the files you told me to, but some showed up again after rebooting...

Let me know what's next. Thanks again.
Brad
Attached Files
File Type: txt Virustotal result March09.txt (1.5 KB, 2 views)
File Type: txt hijackthis09.March.08.txt (8.1 KB, 2 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 04:06 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top