embryonic geek can't download 'hijack this' software

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by guytrepka, Dec 13, 2003.

  1. guytrepka

    guytrepka Private E-2

    Hi , I'm trying to get rid of a highjacked homepage and 'highjack this' software was recommended. But my computer will not download the free download. It just sits on 'downloading' for hours (I've tried leaving it for 6) I have tried several different times.
    If you can help please do !
    Guy
     
  2. Draith

    Draith Private E-2

    And if ad-aware doesn't get it, Spybot S&D will definitely zap it. Sometimes i like to run both of these programs - as someone on this board pointed out a while back that one zaps the spyware the other doesn't find.
     
  3. Marjorie

    Marjorie Private E-2

    Hijackthis just recently changed it's site. Is that an issue??

    Current Hijackthis Homepage:

    http://www.merijn.org/
     
  4. Wisewiz

    Wisewiz Apprentice's Sorcerer

    Good catch, Marjorie! I hadn't noticed that. It only happened a few days ago.

    This one is still live and good for HJT and info, though:
    HJThis!
     
  5. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Just tried all 3 links on the main page all OK and the homepage link is aimed at the same one you posted Marjorie or his spywareinfo url so all seems ok.

    yes xflat that is always a downside to giving advice out sometime you just never know what or whos advice fixed a particular problem, so the next time it comes around we all start from the beginning again until someone says YES that fixed my problem.

    our geeky friend guytrepka is in china at present and his/her online time will be different to ours.


    If you dont manage to download this program let me know and I will either email it to you or put it on an FTP for you to download.
     
  6. guytrepka

    guytrepka Private E-2

    reply to my heroic friends

    thanks for your advice. I'm still working through all your suggestions. I now have Ad-aware and spybot loaded . So far they both find two 'somethings' and I delete them but on restarting my
    computer, my internet explorer page is still hijacked - I'm embarrased to say - with a pornography website.
    I am using windows '98.
    I'll keep working through and keep you posted thanks for your help.
    The bright side is my geek-ability is improving.
    Guy.
     
  7. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    Hey guytrepka, you really have to get HiJack This, Get it off a friend or something. and run it. Some programs are neutering the standard adawares,S&D , Norton etc
     
  8. Marjorie

    Marjorie Private E-2

    You may also want to download and install CWShredder.It can clean and repair some things that Spybot and Ad-aware don't get. CWShredder can be downloaded from the same site I posted earlier for Hijackthis.
     
  9. Marjorie

    Marjorie Private E-2

    Guy,

    This won't help your problem of downloading Hijackthis but could stop you getting the pornography site coming up when you restart your computer.

    It sounds like the spyware that got loaded into your computer that takes you to a pornography site has got into your Startup. If you know how to check which programs are in your Startup list, check them over for any programs that shouldn't be there.

    If you don't know how to find which programs are in your Startup list do the following: click on Start button, then click on Run and when the box comes up type in msconfig. After typing in msconfig, click OK. After the OK has been clicked, a screen will come up that's called System Configuration Utility. Across the top of the System Configuration Utility screen, you will see a number of tabs. Click on Startup. After you have clicked on Startup, a screen will come up showing you all the programs that are starting up when you restart your computer. Beside each program you will see a box with a check mark in it.

    I suspect the spyware that is causing the pornography site to load on your computer is in that list. Go over the list in the Startup and if you can identify the spyware program which is causing the pornography problem, uncheck the box beside that program. After unchecking the box, click Apply, then click OK. Your computer will need to be restarted for the changes to take effect. After you have restarted your computer a box will probably come up saying something like "you are starting up in selective start up mode". Just click the OK button.

    If you are unsure which program in the Startup list should be unchecked, post the programs that are in your startup list, here., and I'm sure somebody will help you.

    This isn't a solution to the problem but only a suggested fix until you get Hijackthis downloaded and installed and a proper repair can be made.
     
  10. guytrepka

    guytrepka Private E-2

    my ongoing headache

    thanks to all for your help. I still cannot load hijack - have tried from all suggested avenues.
    Marjorie, I could not see how to save and post my start up list other than writing it all down. I also could not see any obvious 'virus' . I've got to go to work now - teaching oral English to aspiring teachers.
    GUY
     
  11. Wisewiz

    Wisewiz Apprentice's Sorcerer

    Yo, Guy,

    Use the PM button to give me your e-mail address by Private Message, and I'll send you Hijack This! as a zipped attachment.

    (I'll have to zip it. I can't send an exe file as an attachment.)

    Where are you in China? I have lived and taught in both Lanzhou (at Lanzhou U) and Beijing (at Beijing U and the Beijing Linguistics Institute).
     
  12. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    You have a PM message Guy with a link to my FTP with the file in a self extracting archive ( no need for an external zipping uitility to be installed as I dont think win98 has one afaik ) so just download and double click and pick a folder to save it in and then you just run the HiJackThis .exe inside the folder.
     
  13. Wisewiz

    Wisewiz Apprentice's Sorcerer

    OK, here's Guy's HJT log, just in from China. I haven't actually had time to examine it yet. I'm sure he'll be monitoring the forum, so replies can be posted here, not sent to me. Now that he HAS HJT, if we need to get an update, we can ask him to post it directly to the forum.
    ***********
    Logfile of HijackThis v1.97.7
    Scan saved at 4:07:34 PM, on 12/18/03
    Platform: Windows 98 Gold (Win9x 4.10.1998)
    MSIE: Internet Explorer v5.00 (5.00.2314.1000)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\SISTRAY.EXE
    C:\WINDOWS\SYSTEM\KHOOKER.EXE
    C:\PROGRAM FILES\IVASION\WINPOET\WINPPPOVERETHERNET.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
    C:\WINDOWS\SYSTEM\HPZTSB07.EXE
    C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\RNATHCHK.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    A:\HIJACKTHIS.EXE
    A:\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://au.rd.yahoo.com/slv/ycheck/as/*http://
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://au.rd.yahoo.com/slv/ycheck/as/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com.au/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://au.rd.yahoo.com/slv/ycheck/as/*http://search.yahoo.com/search?p=%s
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YCOMP.DLL
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YCOMP.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\SYSTEM\SISTRAY.EXE
    O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\SYSTEM\khooker.exe
    O4 - HKLM\..\Run: [WinPoET] C:\Program Files\iVasion\WinPoET\WinPPPoverEthernet.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [LoadFont2] C:\WINDOWS\FONTS\Verdana.vbs
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb07.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O14 - IERESET.INF: SEARCH_PAGE_URL=http://home.microsoft.com/access/allinone.asp
    O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: Yahoo! Chat 1.3 - http://cs5.chat.sc5.yahoo.com/c174/chat.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
     
  14. Wisewiz

    Wisewiz Apprentice's Sorcerer

    Only things that hit me in that are the

    SISTRAY.EXE and KHOOKER.EXE entries,

    and I don't think I've seen the 014 entry before, but it looks harmless, and I'd slap the hell out of that all that REAL player garbage and tell it to sit down and shaddup, but that can't be the problem of course, and otherwise, ...

    Somebody wanta get in here, please? The man's been hijacked, and we want to help him out.
     
  15. Wisewiz

    Wisewiz Apprentice's Sorcerer

    Ummm, Guy's having trouble with the PM System (PMS, yeah!) just now. I have asked AbbySue to check into it. Meanwhile, he has my e-mail addy, so I'll forward the copy to you when I get it.

    Guy, send me a copy of that file as an attachment, pls. It'll stick out in the Fonts folder, cuz it Should be the only VBS file in there.

    Anybody else in here on this HJT file? Please? Some fresh eyes might see sthg robo and I have missed.
     
  16. Wisewiz

    Wisewiz Apprentice's Sorcerer

    No problem. I'm in touch with him by e-mail, anyway.

    Now all I need to do is get somebody else to help robo and me with the checking of Guy's HJT log.

    Heeeeelp, people.
     
  17. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    KHOOKER.EXE

    is a SIS G/FX app which is not really needed similar to the Nvidia Driver Helper so delete it as it shouldnt interfear with normal PC use.



    SISTRAY

    could be either a SIS driver helper again or part of this nasty http://securityresponse.symantec.com/avcenter/venc/data/trojan.prova.html

    I would look at the registry keys at the page above to see if similar is evident.



    other than that only the real player stuff stands out and you can get Real Alternative which uses WMP to play Real Media and is less intrusive imo!

    Link to Real Alternative Via Philipp @ NT compat



    Wisewiz cheers for sorting GUY out with HJT :)
     
  18. Wisewiz

    Wisewiz Apprentice's Sorcerer

    OK, then, with thanks to robo and Halo, I guess we'll put this one to bed for now.

    I've sent Guy a tiny startup manager that'll let him temporarily kill the sistray, khooker, and verdana.vbs operators, and if that helps with his problem, we'll get him to use HJT to kill those things one by one.

    Thanks to all who read this all and DIDN'T have any ideas. When a lot of people have come up blank, you can feel good about making a decision on the basis of just a few eddikated gesses.
     
  19. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Do you know what I forgot to ask? what was the name of the homepage that Hijacked you?


    I know this thread started out as a I cannot download HJT but strangely I forgot to ask the simple question above!
     
  20. Wisewiz

    Wisewiz Apprentice's Sorcerer

    He said it was a porn site ... somewhere up there. I didn't find anything that was OBVIOUSLY a porn site in the HJT data, so I went hunting for other stuff.
     
  21. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Ah yes... just noticed that on re-read


    Some of those sites tend to leave either dialers or exe's in the windows folder.... hopefully Ad-Aware, Spybot and HJT have removed the offending hijack if not please let us know Guy?
     
  22. guytrepka

    guytrepka Private E-2

    EMBRONIC GEEK - but moving on from larvae stage

    Thanks for all your help. By unchecking the suggested start-ups I no longer have hijacked homepage ...whoopeeee
    I will now try to find them and delete them using hjk.
    Thank you all for your time.
    GUY
     
  23. Jabman

    Jabman Private First Class

    Well....... I'm a bit late on this, but your problem was the hijacker freexxplace.

    Regards,
    Jade.
     
    Last edited: Dec 19, 2003
  24. Wisewiz

    Wisewiz Apprentice's Sorcerer

    It's a done deed

    Nice catch and nice link, Jab. Wish you'd been here earlier, but robo spotted the culprit anyway, and I gave the lad the tools he needed to get rid of the curse.

    Kinda fun working with the crew here to solve a problem halfway 'round the world, in Northwest China.

    Merry whatever you celebrate! Christmas doesn't actually HAPPEN in China. The Chinese sure know about the Western celebration, though, and darn near EVERY Chinese knows one English-language song by heart (even if he/she doesn't know another WORD of English):

    JINGLE BELLS
     
  25. Jabman

    Jabman Private First Class

    Merry x-mas to you too Wise-a-wokky :p :D.

    Best regards,
    Jade.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds