Browser Hijacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by caseyvoigt, Aug 21, 2008.

  1. caseyvoigt

    caseyvoigt Private E-2

    I have a problem with my searches being hijacked. I am using the newest Firefox. I can load my homepage fine. I enter a search topic and I get results just fine. When I try to click on a search result I get redirected to sites like these,



    I also cannot connect to any spyware updating servers or even to websites like this.

    I have tried, Spybot, Norton, AdAware, Trend, and SuperAntiSpy. Each of these programs has removed some threats supposedly but not my browser Hijacker. I don't know what to do.

    Here is my HiJack this report

    Logfile of Trend Micro HijackThis v2.0.2


    Thanks for helping.
     
    Last edited by a moderator: Aug 22, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do not post links to malware!!

    Please uninstall HJT as it will be properly installed when you do the following:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    If something does not run, write down the info to explain to us later but keep on going.

    Do not assume that because one step does not work that they all will not.


    READ & RUN ME FIRST. Malware Removal Guide

    Note:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode

    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. caseyvoigt

    caseyvoigt Private E-2

    Thank you for replying.

    I apologize for breaking some Malware thread rules. I am kind of desparate and posted in a hurry. I will try to follow the steps for self fixing.

    My computer has gotten worse so that now Firefox and Explorer crash instantly when I try to open them. I will try to follow the steps using another PC.
     
  4. caseyvoigt

    caseyvoigt Private E-2

    I have gone through the Run and Read Me steps up to running the first scan with SuperAntiSpyware. The scan is running now. In the SAS page it gave a link for the newest updated definitions and I successfully replaced the old def files.

    For the rest of the malware programs, SpyBot, Malwarebytes, combofix and MG tools, the tutorial says only to update definitions. The Malware I have definitely blocks anti malware programs from updating.

    I found the page to the latest definitions from Malwarebytes and Spybot but it took some searching. I wont post the links but perhaps the cleaning tutorial could be updated with these links so things could go more quickly? This is only a suggestion not a criticism.

    I am waiting for the SAS scan now and I have the rest to go.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the logs when you are ready and I will pass along the suggestion. This is only becoming a problem lately, as the malware is changing and making things much harder to run.
     
  6. caseyvoigt

    caseyvoigt Private E-2

    I believe most of my problems have been corrected. Thank you very much! I can surf the internet and my searches are not being hijacked. I can update my Antispyware programs too.

    I have only two issues now.

    1. My Norton AntiVirus does not work anymore. When I start my computer it says Norton must close. I can't get it to run by clicking in the folder either. I have Norton Corprate edition. Not sure of the year. (I think this may have happened during ComboFix because a Norton prompt window appeared when ComboFix was rebooting my comp after the ComboFix scan)

    2. Firefox immediately crashes sometimes when I start it up. I get the standard "Firefox is experiencing a problem and must close. Would you like to send an error report"
    This doesn't happen every time but it does happen. Also every time I close Firefox by clicking the red X, I get the must close message.

    I will attach the four logs as well.

    Thank you VERY much.
     
  7. caseyvoigt

    caseyvoigt Private E-2

    last file
     

    Attached Files:

  8. caseyvoigt

    caseyvoigt Private E-2

    first three again?
     

    Attached Files:

  9. caseyvoigt

    caseyvoigt Private E-2

    Everything is well except for Firefox is constantly crashing. I have uninstalled Firefox and reinstalled but that did nothing. Explorer works fine but I don't like it as much.

    I cannot uninstall Norton and Norton will not work. I tried installing a newer version of Norton but it says I must uninstall the old version.

    Any suggestions?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still have issues.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    
    Drivers::
    tdssserv
    xryuoikolfv
    
    File::
    C:\WINDOWS\system32\drivers\xryuoikolfv.sys
    C:\WINDOWS\system32\rdssrv.exe 
    C:\WINDOWS\system32\rdshost.dll 
    C:\WINDOWS\system32\hdfkt.dll
    C:\temp.tmp
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\xryuoikolfv.sys]
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    " "=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds