Help with Browser Hijack(updatescenter.com)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jturn12, Sep 23, 2005.

  1. jturn12

    jturn12 Private E-2

    I recently had the security2k.net problem. I went thru the tutorial for cleaning your system, but my browser is still being hijacked. It keeps taking me to updatescenter.com. I have attached an updated version of my HJT log. If someone could take a look and help me out that would be great. Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download smitRem.exe and save the file to your desktop.

    Double click on the file to extract it to it's own folder on the desktop.

    Reboot into safe mode.

    Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.

    The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please attach this log to your next reply.

    Also post a new HJT log after doing the above.
     
  3. jturn12

    jturn12 Private E-2

    Downloaded and ran the smitrem.exe file. I believe that fixed the problem, but i have attached the log files just to make sure.. Thanks so much for the help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is basically clean. We just have a few minor things to fix. It looks like your Symantec AV application may be partially broken though. One of the files is missing. You may need to reinistall it.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (file missing)

    After clicking Fix, exit HJT.

    Your OS and IE version are way out of date and represent a major security risk. You need to goto the below link and complete all steps beginning with step 1 which is Windows Update.

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds