need help being hijacked from email to unwanted site

Discussion in 'Malware Help (A Specialist Will Reply)' started by tkhills, Dec 31, 2004.

  1. tkhills

    tkhills Private E-2

    I have been struggling for the last few days trying to get to my sbc yahoo email account. When I select email from the sbc yahoo site I get sent to an unwanted place. When I try to access through my aol account, selecting yahoo from the pull down window sends me to the same site!
    I have run adware6.0, spybot, mcafee antivirus, aol spyware, and sbcyahoo spyware - all say my computer is clean. Below is a hjt thread.
    t
    Logfile of HijackThis v1.99.0
    Scan saved at 2:20:37 PM, on 12/31/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


    Edit by chaslang: Unrequested, inline log deleted
     
    Last edited by a moderator: Dec 31, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's! However, HJT is not the first step and we have guidelines about when and how to post logs. Please follow our guidelines in the sticky threads. Also note that Ad-Aware 6.0 is out of date. After following the steps below you will be updated.

    What is the site you are being sent too? Do you really use all those AOL & Yahoo toolbars.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
    Last edited: Dec 31, 2004
  3. tkhills

    tkhills Private E-2

    OK, here goes:
    I followed the steps outlined in the email.
    GETTING PREPARED
    1. Disabled system restore
    2. Did not find Network Security, Worstation Netlogon Services, or Remote Procedure (RPC) Helper
    3. Enabled hidden files and folders and extensions as directed
    4. Downloaded all tools
    SCANNING and CLEANING
    1. b (I’m running Windows XP)
    Could not get online in the safe mode got the following message: “ERROR 711 Cannot load Remote Access connection management service”
    In Normal mode:
    Trend Micro following Trojans detected:
    TROJ SMALL.IF C:\Program Files\Internet Explorer\mxiumnst.exe
    TROJ SMALL.IF C:\Program Files\Internet Explorer\nndhvfeb.exe
    TROJ SMALL.IF C:\Program Files\Internet Explorer\sewxcjun.exe
    TROJ DLDR.DLL C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5E.tmp
    TROJ ISTBAR.FZ C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5F.tmp
    TROJ DLOAD.A C:\Spywarebegone\backups\backups-20040728-215231533.dll

    Symantec Security
    Hacker Exposure check SAFE
    Windows Vulnerability SAFE
    Trojan Horse SAFE
    Antivirus Product AT RISK

    Entered Safe Mode from START, RUN, MSCONFIG, SAFE NETWORK
    Ran McAfee AVERT Stinger scan came up clean

    Still in SAFE MODE
    2. Ran CC Cleaner
    3. Ad-Ware came up with a variety of problems that were fixed, SPYBOT came up clean
    4. CWShredder came up clean, Kill2Me was clean. About:Buster took a LONG time to complete only thing that came up “ No ADS found on system, Error removing C:\WINDOWS\System 32\?hkdsk.exe” HSRemove cleaned 8 items from the system.

    In Normal mode, ran TrojanScan “C:\ recursive, 61,154 items scanned, 0 infected” and RAV Antivirus – came up with same 5 noted above Trend Micro scan.

    OK, now what I have done:
    In Safe mode I was able to delete all but one of the five Trojans picked up in Trend Micro and RAV (C:\Program Files\Internet Explorer\mxiumnst.exe). I deleted that final one in Normal mode.
    I have emptied my Temp and Temp Internet file folders
    On both Yahoo and AOL I have emptied the temp internet and cookie files (from tools, browser options)

    In addition to the programs I downloaded from your instructions, I ran McAfee Antivirus, AOL and SBCYahoo antivirus programs – all with a clean bill of health.

    However, when I use my SBCYahoo as a browser I still get hijacked to a page that sells everything from VIAGRA, to life insurance with penis enhancement on the way. Also, when I try to get to Yahoo mail from google I get sent to the same page. When I try to use AOL as the browser, any time I type in Yahoo! I get sent to the same page. The page does not have a name, the address box still reflects the random yahoo email address. I have had random problems using the search features on yahoo being sent to “sepro.org/search.php?q=”, “topfinder.org/ search.php?q=”, and “ifmore.com/search.php?q=”
    Also when I try to click on Internet Explorer I also get sent to the same page my SBCYahoo mail sends me to (address box in IE reads “about:blank”) Also, when I try to use the Microsoft Update feature, I go to the same place. I can’t believe they actually think I’m going to buy something from them!!!!
    I've attached a hjt .txt file from today.
    Thanks,
    TH
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exit all browsers and run HijackThis and select the below item:
    O15 - Trusted IP range: 206.161.125.149 (HKLM)

    Then click Fix and exit HJT.

    Post me a copy of your hosts file. You can bring it up in notepad like this:

    Click Start, Run, and enter notepad c:\windows\system32\drivers\etc\hosts then click OK
     
  5. tkhills

    tkhills Private E-2

    O15 Trusted IP range has been fixed by HJT.
    Here is the HOSTs as requested
    TH
     

    Attached Files:

    Last edited: Jan 3, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Your hosts file is clean.

    So what problems remain? Hijacked when using Yahoo Browse? Is that truly there own browser?
     
  7. tkhills

    tkhills Private E-2

    Yahoo is my primary browser. I get hijacked when trying to access my email. Also, when I try to use the pull down menu or I use google to access email, I get hijacked.
    AOL is my secondary browser. I get hijacked anytime I use the pull down or google to access Yahoo.
    Using IE, I get sent immediately to the hijacked site.
    T
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Open a command prompt window by clicking Start, Run, and enter cmd in the box and click OK.

    Now enter the below command followed by the enter key:
    ipconfig /flushdns

    Tell me if you still have problems.
     
  9. tkhills

    tkhills Private E-2

    as directed received "successfully flushed DNS Resolver Cache".
    Still have the same problem
     
  10. tkhills

    tkhills Private E-2

    Dr. C,
    does MG have a download Dll Compare?
    Thanks,
    Tom
     
    Last edited: Jan 5, 2005
  11. tkhills

    tkhills Private E-2

    Dr. C,
    One more thing,
    I ran a Dll Compare the log is attached.
    T
     

    Attached Files:

    • log.txt
      File size:
      482 bytes
      Views:
      1
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problems in there but it would be better to download
    Generic Find It Tool - NT/2000/XP


    Extract all the files from the Generic Tool I had you download into a folder of its own.
    Then run find.bat. Post the log it creates back here as an attachment.

    I don't expect any VX2 issues to show but possibly there are some Qooligic issues. I don't expect that these have anything to do with your problems though.

    What is the site you are being hijacked to? And you are still seeing it when you use IE?
     
    Last edited: Jan 6, 2005
  13. tkhills

    tkhills Private E-2

    Dr. C,
    I will do this when I get home tonight.
    I can't tell what the site is, it does not come with a 'title' and the pull down address shows a yahoo email random selection. when I use IE I get 'about:blank' in the window but the same webpage. When I use the search function of either sbcyahoo or aol I get sent to the same page and the URL address simply reflects yahoo search.
    I have also had some trouble with a few other sites using the search functions: “sepro.org/search.php?q=”, “topfinder.org/ search.php?q=”, and “ifmore.com/search.php?q=”

    T
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Watch the Status bar (bottom bar) of the IE window when clicking on stuff. Sometimes you can see URLs there.
     
  15. tkhills

    tkhills Private E-2

    Dr. C,
    Thanks for all the help and please, don't be offended but I think I fixed the problem with help from some friends.
    They found C:\WINDOWS\System 32\?hkdsk.exe that could not be cleaned from HJT. They recommended I run Purity Scan uninstaller and then reboot. Did that and then ran Silent Runners.vbs and the log is attached.
    Right now my system seems to be running OK. Can read email, search on all browsers and computer speed is back to normal.
    If you have some time, could you please give a short tutorial on what I did to fix it and what happened in the first place.
    Appreciate all your help you have been great! I don't know if this is a pro bono organization but if it is, is there anyway I can help with a contribution?
    Tom
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No offense taken but if you had run the Generic tool I gave you, we would have found this possibly along with some other interesting stuff. You should still run it to be sure there are no VX2 or Qooligic infections.

    You should also double check to make sure you still have the valid chkdsk.exe program on you PC in C:\Windows\System32.

    The equivalent of Silent runners is also found using HijackThis's StartupLog List and also you get some with the Generic Tool I gave you too.

    Be careful running uninstall tools made by the people who infected you to begin with. It more often than not creates much bigger problems.

    I'm not sure what you are asking me about a tutorial on what you did. The history is here in this thread plus I don't know what you completely did with your friends.

    Yes, this is a free forum. Those of us helping do it when we can and because we like to help and have the knowledge to do so. You can buy an MG's Teashirt.
     
    Last edited: Jan 8, 2005
  17. tkhills

    tkhills Private E-2

    Dr. C,
    Seems you may have been right. After a day, the problem is back again. I'll do what you suggested two posts ago and get back to you.
    T
     
  18. tkhills

    tkhills Private E-2

    OK,
    Ran the Generic tools and another HJT. Both logs posted. Email is still hijacked.
    T
     

    Attached Files:

  19. tkhills

    tkhills Private E-2

    Ran a registry search for SEPRO, IFMORE, and TOPFINDER - I have been sent to these pages from the search function. Only one to render any results was SEPRO, that log is attached below.
    T
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What problems came back?

    Other than all the crap the AOL, Yahoo, and McAfee have stuck on your PC (which is not malware - just bloatware) your logs are clean.
     
  21. tkhills

    tkhills Private E-2

    OK,
    You are more versed in this stuff than I am.

    I will gladly get rid of ALL the 'bloatware', as you so eloquently phrase it, if you tell me how. My computer is obviosly the '68 plymouth, yours is the '05 Ferrari - besides, I know I'm the plumber trying to paint a picasso......

    Next, ALL I want to do is get back to being able to access my email on sbcyahoo. Seemingly a simple task, yet one that is about to make me scuttle my current computer, and simply buy a new one.

    As I wrote a few posts back and the problem that is still with me:
    When I try to access my email on sbcyahoo - I get hijacked to a site I don't want. All other browsing on this site is OK. Except when I try to search for mail.yahoo - then I get hijacked immediately to the f^&*(*Ng site.

    Using an alternate browser:

    - with IE I get hijacked immediately when is simply select IE.

    - If I try to use AOL using their 'search' function and type YAHOO! I get immediately hijacked.

    Also as I said before: I don't have a 'title' or URL for said site -regardless of where I look to find it.

    I have this feeling I have the cleanest computer that doesn't work.

    Sorry I'm testy, but this sucks.
    T
    T
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Try to be more clear in you messages. I read hundreds of these in a day and we are rather over run with problems lately. It is hard to keep exact track of each thread and I have little time to keep back tracking.

    What websites are you being hijacked to? Exact full URL names please. If you are being hijacked, then you must be going somewhere. Tell me where you are going.

    Is it the same site when using AOL or IE?

    Please clarify the below:
    I'm confused. Why do you consider IE an alternate browser? And I don't understand the first dashed sentence

    For the second dashed item, are you saying you try to use AOL's built-in search function to search for YAHOO and you get hijacked? If so, tell me where you are hijacked to.

    Do you use AOL to connect to the Internet? Are they your ISP?
    I thought you said SBC was your ISP? If SBC is your ISP, why in the world would you use AOL? If you don't need AOL, uninstall all of it.
     
  23. tkhills

    tkhills Private E-2

    I browse with both because I have accounts with both.

    Do you think an uninstall and reinstall of SBC software could be the key? The problem is now intermittent, today for instance came back when I restarted my computer.

    How about a reinstall of WINDOWS NT?

    Sorry about the last email, I guess my temper, the late hour, and the frustration got the better of me.

    My apologies,
    Tom
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer all my questions or I will not be able to help you!

    Note browsing and searching does not mean the same thing.

    I have no idea what impact installing SBC's software will have. I don't even understand why they need to add any to your computer.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds