Internet Explorer Hijacked (read&run first sticky completed)

Discussion in 'Malware Help (A Specialist Will Reply)' started by lexino, Apr 5, 2006.

  1. lexino

    lexino Private E-2

    Hello Everyone,

    *Read Me & Run Me First Sticky* COMPLETED


    Over the weekend April'01'06 I was infected with some spyware the symptoms of which were :-

    A search toolbar in my IE
    All searches when clicked upon were being redirected to various sites

    Note: When I would search from Yahoo or Google the search yieled perfect results only when I would click on them I would end up on spyware sites.

    I ran Adware, Spybot and fixed everything they came up with. VOILA the spyware toolbar was removed. I thought "wow all my problems are solved" unlike last time when I was effected with Spysherrif and had to format my PC. But I was wrong, my PC is still running slower than before and my IE still redirects me when I click on search results from search engines like Yahoo and Google.

    By the way the spyware ToolBar had no particular name it just read REMOVE TOOLBAR on the left side of the search box where it says Google on the Google toolbar. Obviously when I clicked on it, it didn't remove.

    I also ran HijackThis and deleted dubious DLLs and files such as redirection addresses they started off with 85.117.***.** but still my IE is the same. I then removed IE from Add/Remove and Windows Components and re-installed it again from there and that didnt work either. I have Norton 2004 with updated definations, Norton firewall and I scanned my system and it found nothing.

    Then I found about majorgeeks.com I read other people's problems and was happy for everyone that thanked MODs for solving them I can imagine how they must feel. So I went to the Read Me & Run Me First Sticky and tried everything from Windows Denfender and it found nothing. Ran Windows Malicious software removal which found nothing. Bitdefender didnt find anything but Panda did.

    Here is my Panda and Hijack log.
     

    Attached Files:

  2. lexino

    lexino Private E-2

    I deleted manually all the files that Panda mentioned cookies, the dll file and the exe file and it WORKED. Panda is seriously amazing for sure and also thanks to everyone at Major Geeks for helping me in the right direction. I have a 3ghz p4 with HT, 1.5GB ram, 200GB HDD and when a system like this slows down it really hurts because I spent lots of $$$ on this. Still anyone is more than welcome to tell me what exactly this malware was and anything else, more than welcome. thanks again.

    P.S Opps in the confusion I forgot to upload the Activison log, sorry about that. But it mentioned about 25 files which I deleted manually and everything seems cool now.
     
  3. lexino

    lexino Private E-2

    I have another problem now, anytime I try I open my My Computer and then and go to the C drive and press CTRL F to search for a particualr file the window freezes computer is fine so I have to CRTL ALT DEL to close the window but the PC operates fine after that. Any suggesstions.
     
  4. lexino

    lexino Private E-2

    any suggestions, any one?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the Panda log or you attach a message you were typing up by mistake. I would like to see the log. Also did you delete everything it found?

    Your HJT log shows no problems other than you did not follow step 7 to install it properly.

    Since you remove stuff on your own, I have no idea what you may have removed (i.e., valid files ro bad files) so I don't know what you may have done to your PC if it is not working properly.

    If you had O17 lines that showed IP address that began with an 85.x.x.x you may have a WareOut infection still hiding on your PC but I do not see any signs of it in your current log. It is clean.
     
    Last edited: Apr 6, 2006
  6. lexino

    lexino Private E-2

    Hello

    I ran fixit the program for WareOut as you said I might have had it. I had attachted the log, I deleted the files it mentioned to search by name or size manually apparently now the search window when CTRL F is pressed doesnt freeze that window any more. everything is cool for now. I have nother problem that I didnt have before. Even though I have real player 10 websites that play songs on real player suggest that I upgrade to 6.7 above but I already am. Before these sites would just play the songs. any ideas. thanks for suggested wareout really appreciate it.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which files did you delete? You need ot be more specific in your info.

    I cannot help you with Windows Media Player. That is not a malware problem.
     
  8. lexino

    lexino Private E-2

    Hello Chaslang,

    All the files in the post from fixit attached in my last post.
     
  9. lexino

    lexino Private E-2

    I will be posting my Panda ActiveScan log very soon.
     
  10. lexino

    lexino Private E-2

    here it is
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess you did not read what that file said to you:
    So I repeat the same question, EXACTLY what did you delete. Did you delete this: C:\WINDOWS\SYSTEM32\IPSEC6.EXE

    It is a Windows OS file.

    You do need to delete the below from Panda (if not already deleted):
    C:\WINDOWS\system32\dmmlc.exe
     
  12. lexino

    lexino Private E-2

    Oh I am sorry I might have forgotten that part even though I was reading everything and Yes I did delete IPSEC6.EXE What can I do now?


    Okay I just checked my C:\WINDOWS\SYSTEM32\ for IPSEC6.EXE and it is there.... 43KB
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Windows probably blocked you from deleting it. So then can I assume you are not having any further malware problems?
     
  14. lexino

    lexino Private E-2

    Great I appreciate your help greatly. Would you know why my real player wouldnt be working even though I have the latest free version which is 10. the program works fine but some sites are telling me to upgrade it to a 6.7 version or later when I try to stream songs before the virus this never happened.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    No! That is a topic better suited for the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds