1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

browser hijack and infoseek problems

Discussion in 'Malware Removal' started by hdebo, May 31, 2007.

  1. hdebo

    hdebo Private E-2

    I have some problems with my home page being changed. Norton seems to find and stop infoseek and whatever is happening it is rolling back my date and time a few years. Please help. I had trouble running counterspy and I deleted all it found and could not find the prompt to save the report. I tried to run everything else in your instructions.

    Attached Files:

  2. hdebo

    hdebo Private E-2

    here is the rest of the reports.

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this the same PC as in the below thread which you never completed?


    It is considered impolite to not complete a thread and even worse, it leaves you susceptable to reinfection.'

    You are using out of date versions of GetRunKey and ShowNew. You must always work from the current on line version of the READ & RUN ME!
  4. hdebo

    hdebo Private E-2

    I am sorry for not responding the last thread. It was running fine and it slipped my mind. Again I apoligize. It is the same pc but with different problems. I will include the new reports. Norton keeps blocking something called infosteal.

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that exactly what it says or does it say something else? Also where is it saying it is found?

    Did you get a popup from Symantec when running GetRunKey! It did not run properly! And neither did ShowNew!
  6. hdebo

    hdebo Private E-2

    I did not get any popub block when i ran those tests. Should I run them in safe mode? I ran them bolth on normal mode. The thing norton blocked was called infostealer.gampass. It said it just block an intrusion of infostealer.gampass. Every time I shut computer down the reboot my homepage is set to some japanese page www.hao123.com.
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Does your registry editor work? Click Start, Run, and enter regedit and click OK! Tell me what happens!

    So then the below is not something you configured?

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/

    Does Symantec give the location or are you saying this is a message from your firewall on an incoming intrusion?
  8. hdebo

    hdebo Private E-2

    Regedit will not work it says ic cant access the file or path or device and i may not have permission to access the item. norton blocks it as an intrusion. I did not configure that line you have there.
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does c:\windows\regedit.exe exist

    What about c:\windows\system32\regedit.exe

    Also look to see if regedit.com exists in either of the above folders.

    You did not answer my question. Please always answer all questions!

  10. hdebo

    hdebo Private E-2

    c:\windows.regedit.exe is there but in the system32 folder it has regedt32.exe

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown Norton and the do the below.

    Click Start, Run, and enter regedit.exe and click OK! What happens?

    Why do you continue to not answer my question?
  12. hdebo

    hdebo Private E-2

    It still wont open with the same response as before. c:\windows\system32\regedit.exe is not there but i see c:\windows\system32\regedt32.exe. I dont see ant regedit.com in either of those folders

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We can continue once you answer my question that you have not answered since message # 7.
  14. hdebo

    hdebo Private E-2

    1. regedit does not work see my last post
    2. I did not configure that line
    3. Symantec does not give a location it only says it blocks an incoming intrusion

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is the only item I was referring to but I also wanted to know if it is from your firewall since you keep saying incoming intrusion. If it is from your firewall then there is nothing wrong, that is what your firewall is supposed to do.

    Does regedt32.exe run?
  16. hdebo

    hdebo Private E-2

    regedt32.exe does not seem to run either.
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you still seem to be missing the concept of answering all questions! In my last message there were to questions. You answered the second but not the first.

    Let me repeat the first!

  18. hdebo

    hdebo Private E-2

    I dont know how to answer that question. I have a firewall on my router but I dont know how to tell if that is where it is coming from. I aploligize if you are having a hard time understanding me but I am not very computer savy and doing the best I can.

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not if it is coming from Norton!

    I understand but you must always try to answer all questions even if the answer is "I don't know". Remember my insight into your problem is only what you tell me since I cannot see anything. The more information (and always be exact) the better. This is the reason I have had to ask all of the questions. I need to zero in on exactly what is going on.

    Please boot into safe mode and log into the user account name Administrator. Then try running regedit.exe. If it does run, then get new logs from GetRunKey and ShowNew. Also do you get warnings from Norton in safe mode while logged in as Administrator.

    Then come back here and attach the logs if they were obtained.
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are the below files from in your root folder?
    112166~1.css  May 29 2007        1725  "1180482443f55.css"
    112461~1.css  May 29 2007         292  "1180482438f36.css"
    112956~1.css  May 29 2007        8443  "1180482443f53.css"
    112c5f~1.css  May 29 2007       16173  "1180482436f34.css"
    112d56~1.css  May 29 2007       16173  "1180482443f54.css"
    112d65~1.css  May 29 2007         388  "1180482442f48.css"
    11315e~1.css  May 29 2007         388  "1180482447f71.css"
    113169~1.css  May 29 2007        1725  "1180482448f75.css"
    113267~1.css  May 29 2007         460  "1180482452f95.css"
    11327b~1.css  May 29 2007        1725  "1180482450f89.css"
    113959~1.css  May 29 2007        8443  "1180482448f73.css"
    113a5b~1.css  May 29 2007         388  "1180482450f83.css"
    113a6b~1.css  May 29 2007       16173  "1180482450f87.css"
    113d59~1.css  May 29 2007       16173  "1180482448f74.css"
    113e67~1.css  May 29 2007         388  "1180482452f98.css"
    113e6b~1.css  May 29 2007        8443  "1180482450f88.css"
    118048~1.css  May 29 2007         388  "1180482426f7.css"
    118048~2.css  May 29 2007         388  "1180482436f32.css"
    118048~3.css  May 29 2007        1725  "1180482436f35.css"
    118048~4.css  May 29 2007        8443  "1180482436f33.css"
    11e9b2~1.css  May 29 2007         388  "1180482461f133.css"
    11eca0~1.css  May 29 2007       16173  "1180482453f103.css"
    11eca4~1.css  May 29 2007        1725  "1180482453f104.css"
    11ecac~1.css  May 29 2007        8443  "1180482453f102.css"
    11fb1b~1.htm  May 29 2007        1439  "1180482440f40.html"
    11fcaf~1.css  May 29 2007        2734  "1180482454f108.css"
    What is the below files for?
    downlo~1.ini  May 29 2007          23  "DownloadStudio.INI"
    Delete the below file.

Share This Page

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds