My IE6 Browser Is Being Hijacked, etc.

Discussion in 'Malware Help (A Specialist Will Reply)' started by multipede, May 10, 2006.

  1. multipede

    multipede Private E-2

    Hello; I'm Nigel.

    I have read and performed all the preliminary tests and downloads mentioned in the briefing above but did not find any problem until I performed the on line scans.

    I just don't know how to deal with this; I have EZ anti-virus and SpyWare Doctor but they never caught these.

    I would be so grateful for help.

    I enclose all the files requested below....

    Thank you,

    Nigel
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below DETECTIVE folder appears to contain a bunch of things the scanners are questioning. Did you install this stuff youself. If so, what is it. One item in the folder even says Keylogger according to Bitdefender.
    C:\Documents and Settings\All Users\Start Menu\Programs\DETECTIVE

    If you did not install this folder or the stuff in it. You should delete this DETECTIVE folder where indicated in my later steps.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [defender] C:\\defender1.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\defender1.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\DETECTIVE <--- delete this whole folder of questionable software unless you are responsible for it.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. multipede

    multipede Private E-2

    First of all Chaslang...many thanks for your prompt reply and your help.

    I have performed all the operations you have underlined and it appears that my browser is now no longer being hijacked.

    Spyware Doctor continues to deter cookies...currently "tribalfusion.com" appears to be attempting to get into my system.

    The "DETECTIVE" folder IS safe. A while back I had a system crash and had to reinstall but I was able to preserve my original directory/category structure which I had created in "Start Up" programmes to guide me as to what I had to reinstall. This folder is currently empty.

    I enclose the second HJT log (which you implied required creating in "normal" mode...yes?)

    Nigel
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most Cookies are not issues of concern and even the ones that would be of concern are very minor problems. Spyware programs love to blow them out of proportion. It makes their hit counts of malware being detected higher. Anytime you surf you will get cookies. You are getting triablfusion from majorgeeks. It for example is a tracking cookie that helps you to avoid seeing the same advertisements on the main download pages over and over again.

    It was not empty according to your logs. Did you just empty it? If empty, why do you need to keep it?

    Is Spyware Doctor a paid version or a free trial? If paid, you should now uninstall MS Windows Defender to avoid wasting excess system resources and avoid possible conflicts. If Spyware Doctor is a free trial, you should unintall Spyware Doctor and keep MS Windows Defender.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  5. multipede

    multipede Private E-2

    Thanks Chaslang!!!

    I retain these empty folders as I haven't yet finished putting my software back on HDD and they remind me what I have to do, etc.

    Thanks for all your help.

    I will now do the Restore Point stuff.

    The article you directed to me is excellent as, indeed, is the level of professionalism, efficiency and enthusiasm of the whole forum.

    Again...my thanks...a bit of peace at last!

    Nigel
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Nigel! And thanks for the compliments! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds