Help with w32.desktophijack...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JeffBrown, Sep 21, 2005.

  1. JeffBrown

    JeffBrown Private E-2

    Chaps,

    Getting browser hijacked and norton is picking up w32.desktophijack and trojan.desktophijack.b but it's unable to delete or quarantine (access denied, unable to repair etc). It's turning off autoprotect in norton antivirus on startup so I have to keep turning it on.

    It's directing my homepage to www.updatecentre.com and adding desktop shortcuts (secuity centre etc).

    Tried the symantic method of removal to no avail.

    Have followed all the steps as per your "read this first" page. Was unable to update definitions to Spybot as it says "bad sumcheck" on attempt. Also got a runtime error when attempting to update Aboutbuster.

    Other than that managed to install and run all ten applications as well as online scans/ change of settings etc. Lots of things were picked up and deleted but it still hasn't gone.

    I've installed Hijack this as per instruction and eagerly await your help!!

    I've used hijackthis before for deleting things (having looked up what they are on forums etc) but am not an expert by any stretch.

    Thanking you in advance...
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have completed ALL the steps in the READ ME FIRST, follow the steps below.

    Did you run your Norton scan in safe mode with no network connection available? If no, please do so.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. JeffBrown

    JeffBrown Private E-2

    Chaslang

    Thanks for the prompt reply.

    Norton in safe mode found quarantined and was able to delete trojan.desktophijack.b.
    Also found w32.desktophijack and was unable to delete or quarantine.

    I think I ran this in safe mode before and both seem to have come back again.

    I've attached HJT log file.

    Cheers

    Jeff
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download smitRem.exe and save the file to your desktop.

    Double click on the file to extract it to it's own folder on the desktop.

    Reboot into safe mode.

    Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.

    The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please attach this log to your next reply.

    Also attach a new HJT log. Let me know if there is any improvement.
     
  5. JeffBrown

    JeffBrown Private E-2

    Chaslang,

    As requested here's the logs:

    It's all looking tickety boo at the moment - no hijacking and it's running quicker. Anything else I should do to protect in future?

    Regards

    Jeff

    Ps Cheers to you contemporary Knights!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. JeffBrown

    JeffBrown Private E-2

    Chaslang,


    Thanks for all the help - you chaps are invaluable!

    Cheers

    Jeff
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Jeff. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds