Browser highjack

Discussion in 'Malware Help (A Specialist Will Reply)' started by matt1, Jan 23, 2006.

  1. matt1

    matt1 Private E-2

    I have followed the steps in Read and Run and am now at the highjack this step. I ran highjack this and saved the log file; I can attach it per the instructions in Read and Run if you require.
    I am still experiencing unusual activity when using my computer online. Every 10 minutes or so it sounds like something is continuously writing to the hard drive for approximately 40 seconds. Also, I notice what appears to be an attempt at redirecting my browser to a bad URL entitled "ad doubleclick" (I hear the audible double click at the same time that I see this URL listed in the address bar). My browser does not go to another website though; it stays on the one I am viewing. I ran a file search in my c: drive for "ad double click" and obtained the USER.DAT file as a result.
    Advice on where to go from here will be appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hi Matt! It took awhile to complete!

    You need to attach the two logs from step 6 and also the HJT log.
     
  3. matt1

    matt1 Private E-2

    Chas, the logs are enclosed. I was unable to save the log for Bitdefender; however, I ran it twice and it showed no problems both times.
    Graphics and text are now becoming altered when I am online. I have zone alarm set to show alerts, but it is not. Thanks.
    I tried to enclose the logs, but had an error message. I don't know what went wrong.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs do not indicate the presence of any malware. You can have HJT fix the two below lines which are related to Alexa and come installed as defaults when Windows is installed.
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    I see no signs of any browser hijacks. Are you really being hijacked? When? How often?

    Disk activity you speak of may be typical of Windows Me.

    It also looks to me like you have both Norton/Symantec's Firewall installed and also ZoneAlarm. Is this a correct observation? Does your Symantec application include a firewall or does it just monitor any firewall. You must use only one firewall.
     
  5. matt1

    matt1 Private E-2

    Chas, I have Norton 2005; I don't believe it includes a firewall. Do I need to configure Norton to work with zone alarm? I don't know if it is a browser highjack. Intermittant problems may be due to Windows ME, low memory (128MB). Low system resources certainly may be causing corruption. When I run scandisk with selective startup and only explorer running, it has to repeatedly restart because something is writing to the harddrive. Why would this be? It leads ne to believe there is still spyware that is undetectable.
    On another topic, I have thought of using one computer for internet use, and a second computer that is not connected to the internet to prevent malware. Is this a good idea? What are your thoughts on this?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any application that you want to have Internet access or local network access will have to be allowed access thru any firewall you setup.

    You better double check whether your Norton application has a firewall or not. I see this:
    O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    It is called some kind of firewall monitor or something like that, but no one seems to have any idea what the heck it is. Is it a firewall? Or is it something to monitor a firewall? And whose firewall does it monitor? You cannot even find any info about what it is exactly for on Symantec's website.

    If you have anything running that can write to the hard disk it will keep causing restarts of scandisk. This typically occurs due to virusscan, antispyware, and maybe even your firewall running.

    See: http://support.microsoft.com/kb/q222469/

    Note: Windows ME is notorious for having lots of disk activity even when not doing anything. It is (IMHO) a crappy OS that was full of major problems.
     
    Last edited: Jan 31, 2006
  7. matt1

    matt1 Private E-2

    Chas, is this norton firewall something that comes on everybody's norton antivirus 2005 or are you only seeing it on mine?
    I did an FDISK and OS reinstall recently. Today I had a blue screen error and could only get into safe mode. I had to uninstall zone alarm and reinstall the video driver to solve this problem. I reinstalled zone alarm from the same file download I originally used and I received the same error code and the OS froze again. I cannot use zone alarm. Is windows ME causing this? How do I get zone alarm running again?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see that Firewall Monitor on many systems. I have no idea what it is other than it is something that Symantec installs. Personally I would not use any of the Symantec AV packages. They are way to bloated and slow most systems down. And in reality, they don't do a vey good job at fixing problems.

    Are you saying you did the FDISK & reinstall just now or do you mean before you came here?

    Perhaps you need driver updates and maybe some Windows updates on your system. What version of ZoneAlarm are you using (version number)? And is it the free or Pro version? I have used an older version on WinME without problem but I did not have Symantec installed. Try using ZoneAlarm without Symantec software being installed and see if that helps.

    You really should discuss these kind of problems in the Software Forum. They are not really malware issues.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds