Browser hijacker

Discussion in 'Malware Help (A Specialist Will Reply)' started by mac77mac, May 12, 2006.

  1. mac77mac

    mac77mac Private E-2

    Hello,

    I have a problem with a browser hijacker which redirects me to:
    http://search.msn.co.uk/results.asp?FORM=AS35&srch=5&q=??รถ
    which I think is a bogus website.

    I run Windows 2K SP4, Pentium 3, 128Mb RAM, 80Gb hard disk with a firewall and security package from my ISP (blueyonder), normally I use Firefox as my browser.
    The antivirus real time protection in the package is disabled and I run AVG free.

    I have followed all the steps in "read me and run first".
    2 problems with this, I could not enable browser helper in Spybot S&D and could not run Windows defender, used CounterSpy instead.

    I had other problems which the procedure removed, however the above problem remains..I am not using the computer for any secure actions.

    Your advice would be much appreciated.

    mac
     

    Attached Files:

  2. mac77mac

    mac77mac Private E-2

    Additional info: the hijacker only hijacks IE not Firefox. SD helper was the feature on S&D that I couldn't enable.
    mac
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    CounterSpy removed part of your problem with a SpywareQuake infection, but I'm not sure it got all of it. Please run the below procedure and attach the smitfiles.txt log:

    SpywareQuake & SpyFalcon Removal Procedure


    Then attach a new HJT log and also tell me how things are working.
     
  4. mac77mac

    mac77mac Private E-2

    Thanks for the reply.
    Ran the steps as you detailed, had to do it twice as the screen froze the first time while searching system32 files in safe mode, found none of the files or folders in the lists. Some files were very close in name to those on the list, did not touch them. Found twain_32.dll in C:/WINNT/System32/dllcache so renamed and deleted on reboot, worked fine.
    Unfortunately the browser is still being redirected.

    Maybe I should point out that some of the files on your lists had been removed previously (hp????.dll and ld????.dll files) but have not reappeared.

    Thanx again
    mac
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are running two antivirus programs (Authentium and AVG7). You must pick the one you prefer and uninstall the other as instructed in step 3 of the READ ME.

    Please explain what the below is:
    O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\blueyonder\PCguard\fws.exe

    Is it also an antivirus? Is shows as a security service. What exactly is it doing?


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    (if it exists):
    c:\winnt\system32\ldE4FD.tmp

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: May 14, 2006
  6. mac77mac

    mac77mac Private E-2

    Hello,
    I had no idea Iwas running 2 virus programs. I'm assuming that Authentium is the one provided by my ISP, which I thought I'd disabled. I've now enabled this and uninstalled AVG7.
    I have no idea what fws.exe is. Firewall perhaps? (part of "PC guard" package)
    I also don't know what dvpapi.exe is either. I don't recall ever installing anything from Command Software.
    Anyway ran all the steps you recommended, couldn't find ldE4FD.tmp
    Browser still being redirected, this time to a bogus MS update website.

    Thanx
    mac
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would have been better off keeping AVG then Authentium.

    Probably also from your ISP. You need to find out exactly what its purpose is from your ISP. See this: http://www.radialpoint.com/home.php and also http://www.radialpoint.com/solutions-security.php

    Personally I would not want it on my PC but that's your choice. I do not want my ISP to ever automatically download anything to my PC. That's too much like AOL as far as I'm concerned. I just want a broadband connection to my house and then let me choose what I install/run on my PC.

    Again this is from your ISP. When you install software from an ISP you need to know what it is that your are installing. dbpapi.exe is part of Authentium.

    Some of the items I asked you to fix are not fixed. This could be due to the stuff you are running from your ISP. You need to shutdown/exit all this protection software that is getting in your way and then do the below fixes. Also shutdown CounterSpy and WinPatrol. If you cannot shut it down or disable all of these programs, then uninstall them (at least until we get your problems fixed) .


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://auto.search.msn.com/response.asp?MT=%3F%3F%C3%B6&srch=3&prov=&utf8
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings (make sure you set your home page to www.majorgeeks.com for now until we get you fixed. I need you do this so I can tell that the fixes are working.):
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
    Last edited: May 16, 2006
  8. mac77mac

    mac77mac Private E-2

    Hello again,

    Ran steps as you said, attaching HJT log.
    Opened IE got "www.majorgeeks.com" not redirected:)
    The Radialpoint link was most enlightening, thanks
    I shall take your advice and organise my own security in future!

    Many thanx
    mac
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds