Have followed READ ME - still have browser hijack

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by johng2g, Aug 26, 2004.

  1. johng2g

    johng2g Private E-2

    Hello, first of all I would like to thank you for maintaining such a great site.

    I have a browser hijack problem I hope you can help me with. Symptoms:
    (1) Internet Explorer home page is continually reset to:
    http://296f8.ilxt.info/index.php?aid=11340
    (2) Some web pages are blocked, for example:
    http://windowsupdate.microsoft.com/
    (3) Intermittent, and seemingly random, Internet Explorer crashes

    System info:
    Windows XP
    Professional
    Version 2002
    Service Pack 1

    Internet Explorer 6.0.2800.1106.xpsp2.030422-1633


    Here are the steps I have taken:
    (1) Following the FAQ at www.majorgeeks.com (http://forums.majorgeeks.com/showthread.php?t=35407)

    (a) Attempted to run Windows Update as directed in majorgeeks.com FAQ (http://forums.majorgeeks.com/showthread.php?t=35407) but browser hijack redirected.

    (b) Disabled system restore temporarily

    (c) Scanned Windows services for "Network Security Service", but it was not found

    (d) enabled viewing of hidden files and folders

    (e) I ran the online virus protection at:
    http://housecall.trendmicro.com/housecall/start_corp.asp
    It detected 4 files that seemed to be Trojan Horses, it could not remove them because IE was in use.
    The virus scanning at
    http://www.pandasoftware.com/activescan/com/activescan_principal.htm
    was temporarily unavailable

    (f) I downloaded and installed all the utilities mentioned in the FAQ (Ad-Aware and Spybot Search and Destroy were already installed - I updated them, used Ad-Aware's Immunize feature, and activated Spybot's stay resident feature)

    (g) I rebooted into safe mode

    (h) Still following the FAQ, I ran CCleaner - no bad files found

    (i) Ran Ad-aware - numerous critical entries detected and deleted, including some CoolWebSearch variants (Note - I see no indication VX2-Plug-in is installed although I did download and install it).

    (j) Ran Spybot - several problems found and fixed (including DSO exploit)

    (k) Ran CWShredder - no problems detected

    (l) Ran About-Buster 3 times, rebooting (into safe mode) as instructed

    (m) Ran HSRemove - no problems detected

    (n) Rebooted, normal mode - ran AdAware on start-up, no problems found. Dared to hope at this point that success was in reach...

    (o) Notified that Windows updates were available - installed them with the icon on the taskbar

    (o) opened IE - redirected to
    http://296f8.ilxt.info/index.php?aid=11340
    Doh!

    (p) Ran Ad-Aware again - found critical problems, but fewer. CoolWebSearch still in the list

    (q) Ran Sbybot – only problems now found are DSO exploit, which can be ignored according to an existing thread on www.majorgeeks.com

    (s) Still getting home page hijacked.

    (t) I have run HijackThis at a few points in the process. I can post the latest run, but I’m holding off as requested in the FAQ.

    Thanks so much for your help.

    Best,
    johng2g
     
    Last edited: Aug 26, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    John,

    First thanks for writing a thorough description of what you have done and the results.

    The new VX2 cleaner plugin for Ad-aware SE is available at: http://download.lavasoft.de.edgesuite.net/public/plvx2cleaner.exe

    Run Ad-aware SE and select "Use Custom scanning options". Then click Customize.
    Make sure you select Scan within archives.
    And then for the Memory & Registry area make sure all items are selected (they should be green).
    Then click Proceed. The back on Scan window click next. Tell me if it finds anything.

    After this download HijackThis and follow the directions in the below link and post me a HijackThis log as a .txt file attachment:
    http://forums.majorgeeks.com/showthread.php?t=38752
     
  3. johng2g

    johng2g Private E-2

    Hello Chasling,

    Thank you very much for your reply. I followed the instructions you gave me.

    Attached is my new HijackThis Log...

    It seems as though my IE homepage under my profile <John> is now staying put, but the one for the other profile <Karon> is still set to the Hijacked page.

    Thanks again,
    Johng2g
     

    Attached Files:

  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    If you have multiple profiles, you need to repeat for each account, its a downside to multiple profiles.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As MA said, you need to run all cleanup procedures for each user.

    Your log looks good. The only thing I have a comment on is the items in the trusted zone:
    O15 - Trusted Zone: www.expedia.com
    O15 - Trusted Zone: http://www.msn.com
    O15 - Trusted Zone: http://www.stopbioterrorism.com
    O15 - Trusted Zone: http://www.texgarrison.com
    O15 - Trusted Zone: www.utexas.edu

    Did you put them in the Trusted Zone? Do you want them in the Trusted Zone? Personally I don't put anything in the Trusted Zone? Not that there is anything wrong with those links but I just feel it is safer to not have anything there. That way if anything show up there you know it shouldn't be there.
     
  6. johng2g

    johng2g Private E-2

    Hello Chaslang, Major Attitude,

    Thanks for your help. Both profiles seem to be working well now.

    As for the domains in the Trusted Zone, I had switched off my ActiveX, but 3 of those sites required it, so I put them in the trusted zone. The other 2 are domains I own. I will look at removing them.

    Thanks again for everything,
    johng2g
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good news John. Happy we could help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds