Front Page Hi Jack Issue

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by golftp, Sep 28, 2004.

  1. golftp

    golftp Private E-2

    This is my first post and I appreciate the opportunity.

    Currently I run Ad-Ware and Spy Bot daily and have Start Page Guard v2.51

    Recently my front page was Hi-Jacked and I've tried all sorts of ways
    to defeat it and finally decided to post here and ask for HELP. The above programs have not provided a cure.

    Whenever I try to bring my front page URL up the URL below hi jacks the page:

    http://t.swapx.cc/h.php?aid=20009

    Thank you in advance for any help.

    Golftp
     
  2. Kodo

    Kodo SNATCHSQUATCH

  3. golftp

    golftp Private E-2

    Again, I want to thank you for having this service available.

    Per your instructions I did read and perform the tasks today at

    http://forums.majorgeeks.com/showthread.php?t=35407

    I'm running Windows 98 and downloaded the programs you did
    suggest. Unfortunately I still am having problems with my front
    page being hi jacked and the hi jack page is even popping up when I'm
    trying to work on other pages.

    Thank you in advance for any additional help.

    Golftp
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    Post a HijackThis log as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT
     
  5. golftp

    golftp Private E-2

    Again thank you for the assistance. Attached is my log file per your
    request.

    Golftp
     

    Attached Files:

  6. Kodo

    Kodo SNATCHSQUATCH

    you have a remote trojan on your PC.

    Make sure NAV is up to date and scan again. If it is still found then you may need to try a specific Trojan Cleaner like A-Squared.
    http://www.majorgeeks.com/download.php?det=4281


    C:\WINDOWS\SYSTEM\SUCHOST.EXE
    C:\WINDOWS\SYSTEM\SUCHOSTP.EXE
    C:\WINDOWS\SYSTEM\GBFY5LCYI0Z1.EXE

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [jopa] C:\WINDOWS\SYSTEM\SYSSTARTUP.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    It would be a good idea to go to add/remove and uninstall anything you don't recognize and all search toolbars like mywebsearch , websearch.. etc.

    I don't know if the following are legit so stand by for chaslang to confirm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://super-spider.com/sp.htm?id=80
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRAM FILES\SPYBLOCS\SpyBlocs.exe
    O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan
     
  7. golftp

    golftp Private E-2

    Thanks Kodo, I'll stand by for Chaslang to confirm.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Kodo was correct in all those items but there are also a few more to remove and a couple other steps to take. So I'm going to duplicate much of what he gave you, add a few more items to fix, along with a list of files to delete.

    First, from Add/Remove Programs, uninstall Spyware Begone and SpyBlocs.
    These are on lists of rogue/fake spyware removers. You don't need them or want them.
    Add to this what Kodo said about anything you don't recognize.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them (if found):
    SUCHOST.EXE
    SUCHOSTP.EXE
    GBFY5LCYI0Z1.EXE

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=80
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://super-spider.com/sp.htm?id=80
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\SYSTEM\3JWRSF~1.DLL
    O4 - HKLM\..\Run: [Olive System] C:\WINDOWS\SYSTEM\suchost.exe
    O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRAM FILES\SPYBLOCS\SpyBlocs.exe <--- if still here
    O4 - HKLM\..\Run: [jopa] C:\WINDOWS\SYSTEM\SYSSTARTUP.EXE
    O4 - HKCU\..\Run: [romahere2] C:\WINDOWS\SYSTEM\GBFY5LCYI0Z1.EXE
    O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan <--- if still here
    O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    Did you add this to your trusted zone? If not, add it to the fix list.
    O15 - Trusted Zone: *.greg-search.com

    Now reboot in safe mode and delete:
    C:\WINDOWS\SYSTEM\3JWRSF~1.DLL <--- may be a shortened file name look for any dll file beginning with 3JWRSF
    C:\WINDOWS\SYSTEM\suchost.exe
    C:\WINDOWS\SYSTEM\SUCHOSTP.EXE
    C:\PROGRAM FILES\SPYBLOCS\SpyBlocs.exe <--- if still here
    C:\WINDOWS\SYSTEM\SYSSTARTUP.EXE
    C:\WINDOWS\SYSTEM\GBFY5LCYI0Z1.EXE
    C:\FREESCAN\FREESCAN.EXE <--- if still here
    C:\WINDOWS\System32\image.dll

    Now reboot in normal mode and tell us how these steps went and post a new HJT log.

    NOTE: YOU ALSO NEED TO GET YOUR WINDOWS CRITICAL UPDATES! YOU ARE WAY OUT OF DATE!
     
    Last edited: Oct 1, 2004
  9. golftp

    golftp Private E-2

    ChasLang thank you for your time.

    Performed the tasks you asked me to do.

    Spyblocs.exe was not there.
    FREESCAN.EXE was not there.

    I attached the new HGT log per your request.

    Please advise.

    My home page is still HiJacked.

    Golftp
     

    Attached Files:

  10. Kodo

    Kodo SNATCHSQUATCH

    You still have quite a problem.
    Coolweb is still there and so is the Treb Trojan.
    Download this

    http://www.majorgeeks.com/download172.html
    |MG| Free Download - a-squared (a²) Personal Edition 1.1

    Run through the tutorial again but dot not reboot to normal mode. Run teh A2 trojan scanner. Then Run HJT and get rid of the following

    C:\WINDOWS\SYSTEM\SUCHOST.EXE
    C:\WINDOWS\SYSTEM\SUCHOSTP.EXE
    (see if you can manually delete this files too)
    C:\WINDOWS\SYSTEM\GBFY5LCYI0Z1.EXE

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\SYSTEM\SRU6ET~1.DLL

    O4 - HKLM\..\Run: [Olive System] C:\WINDOWS\SYSTEM\suchost.exe
    O4 - HKLM\..\Run: [jopa] C:\WINDOWS\SYSTEM\SYSSTARTUP.EXE
    O4 - HKCU\..\Run: [romahere2] C:\WINDOWS\SYSTEM\GBFY5LCYI0Z1.EXE
    O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\SYSTEM\SRU6ET~1.DLL

    O4 - HKLM\..\Run: [Olive System] C:\WINDOWS\SYSTEM\suchost.exe
    O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRAM FILES\SPYBLOCS\SpyBlocs.exe
    O4 - HKLM\..\Run: [jopa] C:\WINDOWS\SYSTEM\SYSSTARTUP.EXE
    O4 - HKCU\..\Run: [romahere2] C:\WINDOWS\SYSTEM\GBFY5LCYI0Z1.EXE
    O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan
    O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kodo,

    It does not look to me like my (and your) steps were followed before. At least not properly.

    Also the read me first tutorial has not been run. There is no evidence of online scanners.

    Golftp,
    Did you run the READ ME FIRST tutorial? Did you have viewing of hidden files enabled? Did you follow our steps before with HJT and deleting file in safe mode?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds