Browser Hijack

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SirWilliam13, Jun 12, 2005.

  1. SirWilliam13

    SirWilliam13 Private E-2

    My start page is constantly hijacked to "about:blank". I followed the directions (4 steps) here http://forums.majorgeeks.com/showthread.php?t=35407. I also get lots of pop-ups. In Hijack This, I've deleted some R1 entries with variable .dll files along with an R3, but they come back. There is a suspicious BHO, and when I remove it, another takes its place. I've been trying to figure this out for many hours now, and would appreciate help.
    Thanks
    -Will
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    [​IMG] Download HijackThis 1.99.1

    [​IMG] Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    [​IMG] Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    [​IMG]Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    [​IMG]Run HijackThis and save your log file.

    [​IMG] Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    [​IMG]Need help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. SirWilliam13

    SirWilliam13 Private E-2

    Here it is, thank you!
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\zehci.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zehci.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\zehci.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\zehci.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\zehci.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\zehci.dll/sp.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\zehci.dll/sp.html#37049

    R3 - Default URLSearchHook is missing

    O2 - BHO: Class - {4CC69C86-A66C-150A-8AF4-0FE86BFA7342} - C:\WINDOWS\system32\msmd32.dll

    O4 - HKLM\..\Run: [pfsvgae] C:\Program Files\pfsvgae.exe
    O4 - HKLM\..\Run: [netpt32.exe] C:\WINDOWS\netpt32.exe
    O4 - HKLM\..\Run: [applk.exe] C:\WINDOWS\system32\applk.exe

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Navigate to and DELETE the following if they should remain:

    C:\Program Files\pfsvgae.exe

    C:\WINDOWS\system32\netcu32.exe

    C:\WINDOWS\system32\zehci.dll

    C:\WINDOWS\system32\msmd32.dll

    C:\WINDOWS\system32\applk.exe

    C:\WINDOWS\netpt32.exe

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     
  5. SirWilliam13

    SirWilliam13 Private E-2

    Here is the new one. I don't know if it makes any difference, but I'm sure this is the "Only the Best" hijack. Thanks.
     
  6. SirWilliam13

    SirWilliam13 Private E-2

    Oops... Heres the att.
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is now clean!

    Now we must address you AV issue. I notice you are running Norton AntiVirus and AVG AntiVirus, you must pick ONE and uninstall the other. Running 2 antivirus programs will cause conflicts on your computer.

    Are you having any further problems?
     
  8. SirWilliam13

    SirWilliam13 Private E-2

    So far, its good. No pop-ups, and my browser settings are staying the same. I was having problems on startup (desktop background, but nothing else at all), but after I removed Norton AV, it seems to have stopped. I'll attach one current HT scan, and if you could give it a quick glance I'd be even more thankful than I am now.
    Thanks sooo much, never would have figured it out on my own.
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds