Hi jack this log file, please help.Browser hijack.

Discussion in 'Malware Help (A Specialist Will Reply)' started by rapidman, Jun 15, 2006.

  1. rapidman

    rapidman Private E-2

    Hi there, can anyone help me please? My browser has been hijacked and I keep getting redirected to"adarson.com". In internet options my homepage is greyed out so I can't change it. I have included my logfile from Hijack this.

    Thanks.

    Inline log converted to attachment
     

    Attached Files:

    Last edited by a moderator: Jun 15, 2006
  2. AbbySue

    AbbySue MajorGeeks Administrator

    Welcome to MajorGeeks!:)

    You have a few issues that need to be addressed. Using things like key generators usually come with a price (malware). For example from your log: C:\Program Files\winupdates\nero_keygen.exe

    Start with the below and be sure to provide the requested feedback. Chaslang or Shadow_Puter_Dude will be along to assist you further once you provide the logs.


    - Please run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.



    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    You currently have Hijack This here: C:\DOCUME~1\HENRYT~1\LOCALS~1\Temp\Rar$EX00.328\HijackThis.exe so please be sure to install it properly per the instructions so the backups are in a safe location.


    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you
    attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)

    Bitdefender
    Panda Scan
    HijackThis

    Good Luck!:)
     
  3. rapidman

    rapidman Private E-2

    I have done all you said and it is still present. I could'nt get Bitdefender to work and Panda came uyp with no problems.

    I have attached my Hijack this file.
     

    Attached Files:

  4. AbbySue

    AbbySue MajorGeeks Administrator

    Your HJT log says different.:confused: If you completed the Panda scan there would be an entry in your log for it, the same for BitDefender.

    Please explain the difficulties you indicate you had with BitDefender. Did you get an error message? etc. Are you trying to run the scans in safe mode with networking or from normal boot mode? Please be specific so we can resolve it and you can run the scan. HJT is NOT a 'cure all' malware removal tool as many seem to think. There are many things these online scans pick up that HJT doesn't see at all so it is crucial they be done if you want to rid your computer of malware.

    I don't see where you have SpyBot Search and Destroy installed per step 4 which may be because it appears that you either ran HJT from safe mode or you edited the running processes. HJT is to be run from normal boot mode per the instructions given here: Downloading, Installing, and Running HijackThis

    You also still have not installed HJT as I pointed out you needed to in my previous reply to you. You still have it here: C:\DOCUME~1\HENRYT~1\LOCALS~1\Temp\Rar$EX01.859\HijackThis.exe We will be asking you to remove entries with HJT and these entries are backed up by default. If there is a problem and they need to be restored HJT needs to be in a permanent location such as C:\Program Files\Hijack This, not running it from a temporary location like you are now where backups are easily lost or unable to be created at all. This is for your own protection.

     
  5. rapidman

    rapidman Private E-2

    I think I have now done what you wanted.

    Bdscan is attached as is a new HJT.

    Panda would not finish the scan it made internet explorer shut down,

    Thanks for your help so far.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.whatsfind.com/route.html
    O4 - HKLM\..\Run: [rmalt] C:\Program Files\winupdates\nero_keygen.exe
    O4 - HKCU\..\Run: [Spyware Vanisher] c:\spywarevanisher-free\FreeScanner.exe -FastScan
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\winupdates <--- the whole folder
    C:\spywarevanisher-free <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. rapidman

    rapidman Private E-2

    I have attached my HJT file for you. It all seems to be ok. I guess all I need to do now is system restore?

    Many thanks.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your log is clean. And there is more to do than toggling system restore.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds