Persistant BHO!! Any Help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by BoondockSaint, Sep 7, 2005.

  1. BoondockSaint

    BoondockSaint Private E-2

    I been having a difficult time to try and get rid of what i think is a bho that
    on certain web sites will redirect me to the following

    www.find-line.net/inse.php?id=dname
    www.othersearch.org/inse.php?id=dname
    www.findbetter.net/inse.php?id=dname
    www.find-browse.com/inse.php?id=dname
    holenpoker.com/search.php?q=online%20casino%20gambling
    cool-pharmacy.com/secret.php
    www.find-quick.net/inse.php?id=dname
    casinotech.info/search.php?qq=online%20casino
    www.find-up.net/inse.php?id=dname
    www.line-find.net/inse.php?id=dname
    69.50.190.131/?to=dname&from=fh

    these are taken from my hosts file which i deleted but didnt solve the problem at all

    you get the idea..

    anyway i followed the sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal. and i did what i could
    i ran the online scans Bitdefender found nothin and Ravantivirus found 2 worms of some kind but i couldnt do all this in safe mode (networking) as my interent didnt work.

    spy bot found about 5 items and removed them, some of the other tools i ran didnt find anything at all

    ive studied my HJT log and nothing looks real suspisious except for duplicated processes

    so i need some guidance on what the problem is and how i can remove it from my machine

    any help i would appreciate
    cheers

    Boondock Saint
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program

    After doingthe above, make sure you are in normal mode and run the steps below exactly as written:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. BoondockSaint

    BoondockSaint Private E-2

    OK since i already Hoster i restored original

    heres my HJT log attached

    cheers

    BS
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log shows no apparent problems, however you have some problems you need to resolve with your PC:

    1) your OS & IE versions are seriously out of date and represent a major security risk. You must get updated.

    2) You have no antivirus application. You must install one.

    3) You have no firewall. You must install one.


    See How to Protect yourself from malware!
     
  5. BoondockSaint

    BoondockSaint Private E-2

    :) ok ill sp2 my machine and upgrade to latest version of IE!!!

    ive got norton 2004 which i will use for now and ill look for a firewall other than the windows xp one

    so im hoping this upgrade will solve it, if not i guess you will hear from me again :)

    thanks again chaslang
    p.s ill let you know how i go and if it keeps re-occuring

    Cheers

    BS
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have Norton installed, it does not appear to be installed properly because there are very little signs of it in you HJT log and there should be a bunch. Were you deleting items using HJT at some point or are you filtering lines using HJT's filter capability. If not, you need to reinstall Norton. Your log is much smaller than a normal log should be. Usually this happens when people start fixing lines they should not be fixing using HJT.

    Everything you need is in the How to protect link I gave you! Even the link to get your OS updated.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds