desperatly seeking to remove hop.clickbank.net

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by txgri, Oct 23, 2004.

  1. txgri

    txgri Private E-2

    Desperate in Texas. I can't get rid of "hop.clickbank.net" from opening as my homepage whenever my computer gets restarted.

    I've tried CWshredder, housecalls, adaware(I can't run this because it causes my computer to crash), McAfee virus scan, bitdefenders, ca virus scan, symantec, used the registry mechanic, spybot, spyhunter, & avast. I've also cleaned out my temporary folders, cookies, and deleted the offline content files.

    Please let me know what else I can do, I'm at my wits end. Thanks.

    Kat
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have followed all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    It appears that you have run some of the above, but I cannot tell from your message whether you did all of them and did them as we indicate (in safe mode and with system restore disable etc).

    After doing all that, if you still have a problem, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or from a sub-folder of C:\Documents and Settings, or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. txgri

    txgri Private E-2

    here is my hijackthis log file
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow all the steps in the READ ME FIRST. You are using an old version of HJT. Please get the correct version (1.98.2) and post a new log.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I still would prefer to see a log from HJT 1.98.2 because the olde version does not show certain problems and has problems fixing some things too. But let's do the following anyway:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - - (no file)
    O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-D6F5-F66EA787AD2D} - (no file)
    O4 - HKCU\..\Run: [avicap321070v.exe] "C:\WINDOWS\system32\avicap321070v.exe"
    O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} (Installer Class) -
    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) -
    O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) -
    O16 - DPF: {99410CDE-6F16-42CE-9D49-3807F78F0287} -

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Questions for you:
    Do you know the reason for these two diagnostic lines to be running at startup?
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    Did you add MusicMatch to your trusted zone? This is not causing your current problem but I would not add anyone to my trusted zone unless it was absolutely necessary and then I would ask the company why I need to do that to get their software to work.
    O15 - Trusted Zone: *.musicmatch.com
     
  6. txgri

    txgri Private E-2

    Thank you, it worked. Here is my new HJT log.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must remember to shutdown ALL browsers before running HijackThis. You had this running:
    C:\Program Files\Internet Explorer\iexplore.exe

    Now below you will see a bunch of lines to fix that your old version of HJT did not pick up.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra button: (no name) - {3A37C1A1-D260-4C34-B996-F60E03B458BC} - (no file) (HKCU)
    O9 - Extra button: (no name) - {4F5C8404-F44C-462D-8D69-70B461F3E68C} - (no file) (HKCU)
    O9 - Extra button: (no name) - {646C6A67-A5C4-4B0C-A9B6-C48A62508F12} - (no file) (HKCU)
    O9 - Extra button: (no name) - {7D12E1A4-A4A0-4A96-8D77-F345D47D2E5A} - (no file) (HKCU)
    O9 - Extra button: (no name) - {D26F10D2-4EA4-4447-BD1C-872250D8B97C} - (no file) (HKCU)
    O20 - AppInit_DLLs: C:\WINDOWS\system32\aamd532681t.dll

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\aamd532681t.dll

    Now reboot in normal mode and post a new HJT log. And tell me how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds