Infected? Homepage hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by brunobru, Oct 13, 2008.

  1. brunobru

    brunobru Private E-2

    Hello Geeks and non geeks,

    Last month my homepage was being redirected to v11.www.msn.com instead of my usual www.msn.com, and I don't know if it was bad, so ran different scans, and ad-aware quarantined some things, and on startup a window pops up and the bar says autoplay.exe with a searching flashlight but I always close the window before it can finish whatever it's doing. I don't remember (sorry) what all was found, some things were removed. I'm no longer getting redirected but am getting autoplay.exe at almost every startup.

    I ran panda online scan and it found virus/trojan:
    C:\Program Files\DIGStream\digstream.exe which I tried to unistall but it would not let me.

    I noticed during spybot scan that when scanning the registry it is naming the the internet Domain section as EscDomain instead of Domain, which I've never seen before.

    Yesterday (and this morning) I followed the Run and Read me first directions, hopefully did it right;).
    The superAntiSpyware scan came out clean, as did the spybot (but last month Ad-aware found and fixed a few things).

    Can you please help with reading my logs?

    MGlogs log to follow...

    Thanks!!
     

    Attached Files:

  2. brunobru

    brunobru Private E-2

    MGlogs log...

    Thanks again for any help!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    C:\Program Files\DIGStream\digstream.exe

    False positive by Panda.

    Your logs are clean......you may wish to post in the software forum to further pursue those issues.

    Now we need to clean up from the scans:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then:
     
  4. brunobru

    brunobru Private E-2

    Hello and thank you TimW!

    I will try the cleanup as you instructed and will let you know about the 'success' message. It may take me a few days to get this done and get back to you because of my work schedule.

    Should this be a concern? Did malware change the registry? :confused

    Thanks again for checking the logs.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  6. brunobru

    brunobru Private E-2

    Hi Tim! I was able to get the cleanup done and it said it was successful, so thanks again for your help...I really appreciate it! :):):)
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome.......:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds