Followed Hijack this, still have browser hijack -Help?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by stevo4, Sep 11, 2004.

  1. stevo4

    stevo4 Private E-2

    Used Hijack this, spybot, NIS 2004 and followed the HJT Tutorial and used Pacman and Tony's links for determining bad files.

    When i rescan with Hijack the Try-this-search.biz files re-appear, as well as the home page for the browser.

    Since this just happened today, i haven't played with the system restore feature.

    Looking for any help.

    Thanks,
    steven
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  3. stevo4

    stevo4 Private E-2

    Ok Major Attitude,

    I printed out the Tutorial for the virus removal.

    Downloaded all the anti virus files listed.

    Disabled sys restore.

    Do not have network sec. or workstation services active on my laptop.

    Enabled (already done) hidden files and add extentions.

    Installed software as requested.

    Booted in safe mode.

    Ran all software as described. Deleted the index dat.

    Ran Avert.

    *** Was not able to connect to sym. sec. check or trend since in safe mode, the computer disabled my Wireless/lan connection to the internet.****

    Ran Ad SE with the plugin.

    Ran SPybot and then immunized.

    Ran all the other antivirus software.

    Ran SpywareBlaster.

    Ran Hijack this and removed R1's Try-this-search items (There were 3).

    Ran again and they were gone.

    Rebooted computer, opened IE and Try-this-search.biz was still there!

    Please advise.
    Standing by to post Log if you are ready.

    Thank you.
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    You can, but try an online virus scanner first. Folow Hijack This tutorial please, putting it in its own directory and closing running programs, myself or Chaslang will be along.
     
  5. stevo4

    stevo4 Private E-2

    Ok.

    Ran the online scans at both trend and symantic and found nothing. Followed the Hijack this tutorial.

    Still get the try-this browser and still, obviously shows up in log.

    Following is the latest log:


    Thanks for your help gentlemen!
    Steve
     
    Last edited by a moderator: Sep 12, 2004
  6. stevo4

    stevo4 Private E-2

    Sorry, didn't attach file.

    Here it is the way you prefer...

    I closed all the files in the sys tray except my NIS 2004. If you feel there is still too much running, please let me know.

    I am just not sure what programs are safe to close in the task manager so that the computer will still function while i try and fix the problems.

    Thanks, steve
     

    Attached Files:

  7. stevo4

    stevo4 Private E-2

    One last note,

    I turned off the 'make back up' in the HJT option. Just to see if that was part of the problem - it wasn't. Should i turn it back on next time?

    Steve.
     
  8. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I see a few easily that need removal, lot of stuff running still, but not your fault... Try removing:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://try-this-search.biz
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://try-this-search.biz/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://try-this-search.biz/ie.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://try-this-search.biz
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = http://try-this-search.biz
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://try-this-search.biz
    O4 - Startup: Trillian.lnk = ?
    O21 - SSODL: eplrr9 - {B0038399-4B65-4C79-9AFC-B44B9A3ACB3C} - C:\WINDOWS\System32\eplrr9.dll

    And let us know...

    P.S Yes, always make a backup of Hijack This just in case you remove something you needed.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In addtion to what MA has given you, at the same time as doing his steps add these steps:

    Fix this line too with HJT:
    O2 - BHO: IE Search Toolbar Helper - {2C5175A2-ADF3-4F57-AB70-BA90FD60A383} - C:\Program Files\IESearchToolbar\IESearchToolbar.dll

    Make sure you have enable view of hidden files as per the READ ME.
    Reboot in safe mode and delete:
    C:\Program Files\IESearchToolbar <---- the whole directory
    C:\WINDOWS\System32\eplrr9.dll
     
  10. stevo4

    stevo4 Private E-2

    FIXED!!

    Redid the process and fixing/removing the 021 line ( i think this may have been the culprit as the other lines you asked me to remove, were lines that keep re-appearing.) Don't recall having fixed the 021 line before.


    I did not get Chas's message til after i did what MA suggested. So, for the moment, i'm back to my About:blank IE startup page. Yippee.

    Thank you very much for this support.

    May i ask how you guys are compensated? Is this just a hobby and you just monitor the site 24/7? or is this a full time deal and are compensated some way?

    I'd consider a donation for the service.

    Steven

    P.S. :

    I have been very happy using NIS 2004. It has never let me down until this browser hijack. I constantly update NIS as well as use spybot and spysweeper frequently.

    Is there some reason NIS didn't catch this or does this type of thing fall outside the range of the firewall/antivirus capabilities?

    Thanks again....until next time...
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should make sure you fixed those items I gave you too.

    I'll let MA answer your questions about how we have such fantastic coverage here. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds