Browser Hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by Busteroo, Mar 17, 2006.

  1. Busteroo

    Busteroo Private E-2

    I have done all the steps required and removed numerous dialers and trojans. One problem still persists, its the browser hijack. Whenever I try to go to specific webpages (Symantec, PcCillin) Im being redirected to porn webpages or a google search for sex related topics. I will attach the 3 logs required, maybe that will shed some light into this matter. I tried to manually scan the registry to no avail. Thanks in advance for your time.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions in step 7 of the READ ME and get the proper version of HijackThis installed. Then continue with the below.

    You have a Wareout infection!

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{374C6A90-D4A7-49F5-9847-168B5D4D6EAE}: NameServer = 85.255.113.133 85.255.112.17


    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:
    C:\Program Files\UnSpyPC <--- delete the whole folder if found

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Also attach a new HijackThis log.
     
  3. Busteroo

    Busteroo Private E-2

    here are the logs of hijack and fixware
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All clean! So how are things working now?
     
  5. Busteroo

    Busteroo Private E-2

    O17 - HKLM\System\CCS\Services\Tcpip\..\{374C6A90-D4A7-49F5-9847-168B5D4D6EAE}: NameServer = 85.255.113.133 85.255.112.17


    cant get rid of this entry :( Im still getting the hijacks. Not sure what to do next.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand what you mean. Look at your last HijackThis log you attached. It was not there.

    Attach a new one. Did you follow the steps for running FixWareOut exactly as written? Run it again and attach a new log too.
     
  7. Busteroo

    Busteroo Private E-2

    Yeah I dont understand this either. When I restarted after doing the steps you told me to do it wasnt there. Yet when I went online browsing it was back and hijacking my browsers. Here is anothe log of hijack.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check your firewall settings and make sure incoming and outgoing (from/to) those IP address are blocked. The actually IP range for this bad site and who it belongs to is below:
    You should try to setup your firewall to block that whole range of IP addesses!

    After doing that, continue with below!

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Click Start, Run, and enter ipconfig /flushdns and click OK! This will flush your DNS cache (a command prompt window will just open and quickly close).

    Locate the below files with Windows Explorer and delete them:
    C:\WINDOWS\SYSTEM32\wp.bmp
    C:\WINDOWS\system32\LogFiles\DA7021900.so
    C:\eied_s7.cab
    C:\info6_s.cab
    C:\TEMP\FLEOK <--- the whole folder
    C:\Emailstuff\backup-20040913-082042-180.inf

    If any of these do not delete, try at some point later after a boot into safe mode.

    Then run FixWareOut again and attach the new log. Reboot a couple times afterwards to make sure and then attach a new HJT log and let's see where things stand.

    If still having problems at this point, run the below and attach the Ewido log.

    Running Ewido Anti-Malware

    Also please run the steps in the below link and attach the runkeys.txt log.

    Using GetRunKey
     
    Last edited: Mar 18, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds