horse-search dot net pest!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by btaussie, Mar 10, 2005.

  1. btaussie

    btaussie Private E-2

    Tried all the major ad-ware removal tools, didnt work.
    Tried add-remove programs to remove components that shouldnt be there, didnt work!
    The problem arise when after 2-10 mins of surfing on IE, the webpage gets re-directed to horse search dot net and searches a completely pornographic word. I have included below a fresh log for your viewing I dearly hope you can help me, Thank You.

    Logfile of HijackThis v1.99.1
    Scan saved at 9:00:01 AM, on 11/03/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Edit by chaslang: Unrequested inline log removed
     
    Last edited by a moderator: Mar 10, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow forum guidelines on how and when to post HijackThis logs.

    To help us to best help you, please follow the steps below closely and in the order given and do not skip anything. If you have any difficulty, please post back letting us know what steps you have completed, what you found while doing the scans if anything along with details about any problems you may have encountered in completing the steps. The more details you can provide the better. Don't be afraid to ask for additional help if you don't understand something!

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENTto your next message. (Do NOT copy/paste the log into your post).
     
  3. btaussie

    btaussie Private E-2

    After countless days of fussing around :mad: trying to fix here is a fresh HiJackThis log file for your inspection. I hope you can help as it is really affecting my internet browsing especially with exams and assignments on the way, any help would be immensily appreciated :)

    -btaussie

    P.S. Apologises about the copy and paste job before. :(
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I will go ahead and get you started while Chas isnt here at the moment.

    There are no signs of you running the online virus scans. Now please follow my instructions very closely.

    First:
    Please download: HSFix.zip
    • Extract the tool from the ZIP File to a folder you can easily find (preferably in its own folder - like c:\HSFix). Then follow the procedure below:
    • Boot to Safe Mode open the HSFix Tool folder and DoubleClick hsfix.bat and let it run. It will produce a log here - C:\hslog.txt

    Second:
    Now, please run the below virus scan.

    Third:
    Reboot to Normal Mode, Scan with Hijack This and attach the new log along with the hslog.txt from HSFix.zip for Chaslang!

    Good Luck! :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually neither online scan was run. Is there a reason you skipped the two online scanners? They are indicated in the READ ME as not being optional. Did you skip anything else?
     
  6. btaussie

    btaussie Private E-2

    Hi I have completed the given instructions you have told me to do and before I ran HSFix I ran Spybot and AD-ware and found nothing (only cookies) but after running HSFix successfully in Safe Mode upon booting back to regular windows SpyBot returned a few nasty suprises that now are gone, I have since ran Vet Anti-Virus and Ad-ware yet...one more problem now!!!

    I have five users on XP home sp2 and the background has turned to a red background with a black box saying in big letters "Danger Spyware"! All the icons have gone and only My Computer, Internet Explorer and Recycle Bin are left and the right mouse click is disabled! Also to make matters worse every so often a popup comes up with the exact same annoying image as my wallpaper.

    I have attached a fresh HiJack This log file for your inspection and evaluation. I sincerly appreciate the effort you have gone to so far and I hope you can help me just that little bit more. Also attached is a jpeg of my now 'hacked' wallpaper and I tried changing settings via Control Panel but didnt work. Please Help! :confused:

    -btaussie :eek:
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You have whats known as TROJ_SPYWAD.A so lets get rid of a lot of this before we start with HJT.

    Please follow my instructions below.

    Download Kaspersky Anti-Virus Personal 5.0.

    Note: This version is a 30 day trial.

    You must disable any AntiVirus programs you have installed

    Now install KAV 5.0

    When Installing, do the following as you come to them:

    Uncheck the Operate According to Recommended Settings Box

    Uncheck the Use Real-time Protection against Network Attacks Box

    Uncheck the Use The iStreams Technology Box

    Now, allow KAV 5.0 to download and install Updates. Then, look under Settings > Configure Updater and select Extended Database > OK > Check for Updates and allow those to install.

    Then, Click Settings > Configure On-Demand Scan Settings and Set Scan Level to Maximum > Perform Recommended Action > OK

    NOW, Close ALL Programs (including KAV 5.0) and Browsers!

    Physically Disconnect from the Internet - Pull the Cable!!

    Boot into SAFE MODE

    Now : Start a FULL SYSTEM SCAN. Click the Protection Tab and select Scan My Computer .


    This process may take HOURS . . . . LET IT RUN!

    After this is complete, post the results along with a fresh HJT log.

    Good Luck!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds