desktop hijack Take Two

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Coaster, Dec 4, 2004.

  1. Coaster

    Coaster Private E-2

    Re: desktop hijack

    Hello, I am adding to this thread because I have the same problem and I can not get rid of it. Whenever I have active desktop running my chosen image seems to be covered over with a black screen that has a warning in the middle that reads "WARNING! YOU ARE IN DANGER! All you do with computer is stored in your hard disk forever..."

    It goes on for a paragraph and has a 'link' that reads 'removal instructions'.

    On top of that I have reoccuring popups and I know there are tasks running that I can not seem to get ride of.

    I have followed the instructions listed in another thread on this topic and now have Ad-Aware (with vx2 plugin), Spybot Search & Destroy, CCleaner, SpywareBlaster and a few others (including HiJackThis).

    I have run each of them multiple times, both in normal mode as well as Safe Mode and nothing seems to prevent the popups from reoccuring nor does it restore my active desktop.

    My HiJack this log is currently...


    Most of those O15's were removed by me but have returned. What the Heck Is that thing that has ussurped my active desktop?!
     

    Attached Files:

    Last edited by a moderator: Dec 5, 2004
  2. PhilliePhan

    PhilliePhan Guest

    Hi Coaster,

    I gave you your own thread. Somebody will take a look at your log when they get a chance.

    ALSO: Is that your COMPLETE HJT Log?


    PP :)
     
  3. Coaster

    Coaster Private E-2

    I believe it is...I have just rebooted my machine and ran HiJackThis again. Here is the log cut and pasted...


    Just an fyi but I have gone and performed the steps in the FAQ I found. I have and now run Ad-Aware (with vx2 plugin), SpybotSearchAndDestroy, CCleaner, Spyware Blaster and the others.

    EDIT by chaslang: Inline log changed to an attachment

    I even found the file that holds the image that is overlaying my desktop (its in the Windows folder in a file called Desktop.html. I deleted it and there is no warning message but now my desktop is white and occasionally flashes grey.

    My comp works fine, just my desktop is gone.

    I believe the 'desktop.html' file is/was being used to overlay my existing desktop. When I boot up I get to see my desktop as it should be for a moment before it goes all white.

    What I figure is that something somewhere is still trying to 'overlay' my desktop but since I have deleted the file it needs, it is still 'overlaying' but with white since it does not have the file it needs.
     

    Attached Files:

    • hjt.txt
      File size:
      2.1 KB
      Views:
      0
    Last edited by a moderator: Dec 7, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HJT logs must be attachments!!! The last log you posted is smaller than the first. What happend to the O16 lines showing the Symantec and Trendmicro online scans?

    You must remember to exit browsers like IE before running HJT. You had this running:
    C:\Program Files\Internet Explorer\iexplore.exe
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bettersearch.biz
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    O15 - Trusted Zone: *.awmdabest.com
    O15 - Trusted Zone: *.c4tdownload.com
    O15 - Trusted Zone: *.finefind.net
    O15 - Trusted Zone: *.iframe.biz
    O15 - Trusted Zone: *.megapornix.com
    O15 - Trusted Zone: *.newiframe.biz
    O15 - Trusted Zone: *.overpro.com
    O15 - Trusted Zone: *.sp2admin.biz
    O15 - Trusted Zone: *.sp2****ed.biz
    O15 - Trusted Zone: *.windupdates.com

    Exit HJT.

    Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. moonman78

    moonman78 Private E-2

    hey regarding that desktop hijack, is it a black kinda screen dat covers ur desktop? and redirects u to some software site? if it is then the same guys offer u some removal stuff (after apologising for the hijack!!) ive attached the file (dont remember the site whr i downloaded it from..was sum techsupport site i think) try it n hope it works for ya
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And you expect anyone to trust that they should run that EXE file. I don't think so! From unknown sources with no supporting data!!!!!
     
  8. moonman78

    moonman78 Private E-2

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. moonman78

    moonman78 Private E-2

    Hahahhahhahaha
     
  11. goldtoes

    goldtoes Private E-2

    heh well i trust the site, because that removal tool fixed the problem with my desktop, and didn't add anything else. thanks man.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure? Have you run a few of the scanners? Like Ad-Aware SE, Spybot...etc.

    Take a look at your HijackThis log too just to double check.

    I'm not saying they added anything, but there home page is full of malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds