browser hijacked???

Discussion in 'Malware Help (A Specialist Will Reply)' started by Aloevera, Sep 10, 2006.

  1. Aloevera

    Aloevera Private E-2

    For some weeks now I have been unable to directly access web sites from Google by clicking on page titles. I am instead redirected to redundant, mock search engines with names such as "topten.com", "Rpicamps.com", "wordsea.com", and perhaps most intriguingly of all "camouflageclothingonline.net".
    I am still able to access the desired web sites by cutting their URLs from the Google Search Results page then pasting it into the IE address box.

    I have done the following steps, but it still not fix the problem ><

    1. scan with BitFinder and Panda
    2. run Spybot Search & distroy
    3. run Ad-Aware
    4. run Ewido
    5. run hijackthis

    i have attached the log files here. please help me get rid of this annoying spyware and i am not sure if it's harmful to any of information in this computer???

    thanks alot in advance
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Best option is to follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis

    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Aloevera

    Aloevera Private E-2

    sorry about before.

    i have now followed the mentioned steps but still not fixed the problem :confused:

    please see attached logs

    thanks alot for your time and help :)
     

    Attached Files:

  4. Aloevera

    Aloevera Private E-2

    more logs...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First I have a few questions:

    1) Is this your normal start page? www.google.co.th

    2) Is Ewido a free trial or paid version?

    3) Is CounterSpy a free trial or paid version (from the READ ME?). Where is the log?

    4) Did you download an updated copy of wininet.dll on Sept 11, 2006?


    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_04

    You now need to run this: WareOut Removal and attach the requested log.

    Now make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O1 - Hosts: localhost 127.0.0.1
    O2 - BHO: (no name) - {0AD43354-A526-4608-BE2E-17B950400732} - C:\WINDOWS\system32\hmba.dll (file missing)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{68E33BDE-C2D5-4377-A8AD-3F8BB020ADDA}: NameServer = 85.255.113.92,85.255.112.195
    O21 - SSODL: Internet Explorer - {F28A40D7-AD0E-034A-C651-5F0ED76232E6} - C:\WINDOWS\system32\Lalpjdfj.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete(if found):
    C:\WINDOWS\system32\hmba.dll
    C:\WINDOWS\system32\Lalpjdfj.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode!

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now attach a new HJT log and the log from FixWareOut

    Make sure you tell me how things are working now.
     
    Last edited: Sep 12, 2006
  6. Aloevera

    Aloevera Private E-2

    1.yes it is. it's just google page in thailand :)
    2. it's a free trial version
    3. free trial from READ ME section. hmmm...sorry but i can't find the log :( i will run it again if needed
    when i first run it seems to detect about 5-6 spyware i did quanrantine and removed them afterward.

    with Spybot search & destroy when run it always show that it detect some sort of spyware called "Pipa.A" and I did take recommended action by removed it but it will always come back everytime i scan using Spybot????

    thanks
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just edited my last message to add more steps! Please refresh and re-read.

    No don't rerun CounterSpy now!
     
  8. Aloevera

    Aloevera Private E-2

    please see the logs.

    after all suggested steps, it seems the browser is working fine now I am able to view the desire page from the search without having to copy and paste the link into address bar. :)

    thank you very much :) :) :)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look for and delete the below files if found:
    C:\WINDOWS\SYSTEM32\CSGKP.EXE
    C:\WINDOWS\SYSTEM32\CSQRB.EXE
    C:\WINDOWS\SYSTEM32\DMROH.EXE

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds