im lost and in need of help

Discussion in 'Malware Help (A Specialist Will Reply)' started by seaside, Jan 27, 2005.

  1. seaside

    seaside Corporal

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {3DF009ED-54BF-4A31-AADC-679997254A74} - C:\WINDOWS\SYSTEM\AIGHKH.DLL
    O18 - Filter: text/plain - {7CC1DA6A-B893-4E55-997E-8046D9F77D8B} - C:\WINDOWS\SYSTEM\AIGHKH.DLL


    this is what i get when i look at the go here first screen i have tried everthing you said but i am f****d i have tried all the spy bot things and although they say its gone "da da" here i am again its called http default home can anyone help
     
    Last edited: Jan 27, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    What is the "go here first screen"?

    Did you run all the steps of the following sticky thread: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    You have one of the many forms of an about:blank hijacker.
     
  3. seaside

    seaside Corporal

    hi mate i ment that i read the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal but i dont know what it means it said that i had one of the dofas on that list
     
  4. seaside

    seaside Corporal

    fire fox

    hi i am knackered by the about blank home page twat if i install for fox will the bugger die
     
  5. jarcher

    jarcher I can't handle a title

    Re: fire fox

    well. .no and yes. . .firefox will help alot in protecting your pc
    start by running through the sticky's


    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal:
    double check everything and make sure you did do everything
    and all software is up to date
    tell us how it went

    we will ask for a log
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting:
    *Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis! Please do this!!!*
    make sure everything is closed(all open apps., tray items, windows{even this one})before you scan

    make sure the system is clean then install it
    then after we are sure you are good to go

    How to Protect yourself from malware!
     
  6. jarcher

    jarcher I can't handle a title

    chaslang, I just posted in his other thread, jumpn' the gun
    didn't see this one. .
    sorry
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: fire fox

    Seaside,

    You need to stay in one thread for your problem. You see what happens.....you just go told the same things all over again. Posting in multiple thread is normally a time waster for you and for us.

    I merging you back into one thread.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: fire fox

    Seaside,

    You should follow the guidelines below and post your HJT log as an attachment.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  9. seaside

    seaside Corporal

    Re: fire fox

     
    Last edited: Jan 28, 2005
  10. jarcher

    jarcher I can't handle a title

    Re: fire fox

    did you save your HJT log as a .txt file?
    and not as a .log
     
  11. seaside

    seaside Corporal

    dont know will do it again
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: fire fox

    jarcher,

    This has not been necessary for many months. Both .log files (the default from HJT) and .txt files are valid uploads.

    So Seaside must not be using a valid extension and may not have disabled the option to "Hide extensions for know file types" as covered in the sticky thread.
     
  13. seaside

    seaside Corporal

    i dont have a clue how it works but spysubtract stops the homepage blocker
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you are saying!

    Where is the HJT log?
     
  15. seaside

    seaside Corporal

    hi again sorry about the last message i downloaded a program called spysubtract it is stopping the about blank home page bugger from working but its only for 30 days.i went to the list you told me of i have turned off the hide thingy trying a new log now doh same thing "invalid file type"
    argg its to hard it says its ansi file type
     
  16. seaside

    seaside Corporal

    i think this is it
     

    Attached Files:

  17. seaside

    seaside Corporal

    Edit by chaslang: Inline log deleted
     
    Last edited by a moderator: Jan 29, 2005
  18. seaside

    seaside Corporal

    at last the elusive hjl
     
  19. seaside

    seaside Corporal

    this is another log with all programs stopped


    Edit by chaslang: Inline log deleted
     
    Last edited by a moderator: Jan 29, 2005
  20. jarcher

    jarcher I can't handle a title

    you attatched right the first time. . .
    that is considoed an inline log
    those last two will be most likely removed

    you need to make sure you close IE when you scan

    I see that this needs to be fixed by HJT

    O13 - WWW. Prefix: http://
    the
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting:
    states that all O13 entries need to be fixed
    ;) just so ya know. . .
    I don't see anything else myself. . . .
     
    Last edited: Jan 29, 2005
  21. seaside

    seaside Corporal

    thank you i hve read so much stuff i can't remember any of it lol
    but i will delete the twat right now
     
  22. seaside

    seaside Corporal


    Edit by chaslang: Inline log changed to an attachment. Please do not post anymore logs unless asked to do so. Also, do not post them inline. They will be deleted.
     

    Attached Files:

    Last edited by a moderator: Jan 29, 2005
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you not understand this: Now post a HijackThis log as an attachment to your message (Do not post the log inline).

    And why do you keep posting log after log! No one is asking for them. One is quite sufficient!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to fix the problem of about:blank hijacks, we need to be able to see them. Uninstall SpySubtract.

    It is possible that it already fixed your problem too. You had what is considered a relatively easy version to fix.
     
  25. seaside

    seaside Corporal

    thanks for all your help chas i really do thank you for trying to help me out. i will wait the 20 odd days left on spysubtract to see if it worked or not once again thanks mate you are an exellent guy take care
    seaside
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds