Please Help Me. Major Hijack Problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dianawho, Dec 16, 2004.

  1. dianawho

    dianawho Private E-2

    Hi, I would like to request some help... PLEASE. My Browser has been Hi Jacked. I have read the Tutorials on how to remove it and have done all I can and I still can't get my computer back to normal. I am running Windows XP home editions. I have run a log on my computer. Could I please post my log for your veiwing? I have worked on trying to rid my computer of all this spyware and virus for three days but It isn't working. PLEASE PLEASE HELP ME!
    Thank you
    Diana
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Diana,

    If you have exhausted the resources in the Tutorial, then please send us a HijackThis Log. Be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis v1.99

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’ve been pretty busy with work lately, but somebody will try to take a look when they get a chance.

    Best :)
    PP
     
  3. dianawho

    dianawho Private E-2

    Thanks for the help..... Here is my log... Is it possible for a hijacked browser to be hijacked from another broswer? Because the log i am posting is not like the log i had orginally ran. When I orginally started having problems it was a about.blank on my browser. now it is onlygoodsearch.com. It's confusing me. Or had I maybe fixed the orginal problem and just have a new one?
    well anyways here is my log... Thanks again for the help
    Diana


    Edit by chaslang: Inline log changed to an attachment
     

    Attached Files:

    • hjt.txt
      File size:
      3.9 KB
      Views:
      2
    Last edited by a moderator: Dec 17, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Diana,

    Please remember our instructions! Phillie said, "Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post."

    You did not attach your log you posted it in line. Just save the file using HijackThis (a .log file is okay to upload too) and upload it.

    I will change your log into an attachment for you this time, but please remember to attach them from now on.

    However, you also did not follow directions on where to put HJT.
    "Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!"

    You are running it from the ZIP file. You will not getting backups this way. You must extract it from the ZIP file and put it into a directory your create. Use the example name Phillie gave you (above in blue). Do this before continuing!

    You need to uninstall Spyblocs using Add/Remove programs. It is on a list of rogue/suspect spyware removal programs. Don't use stuff like this. In most cases, if it is not available on MG's, it is not worth having.

    While there, look for an uninstall for Vcatch and uninstall it if found.

    Using Shareaza is asking for trouble too but it is up to you what you want to do with it. I did add it to my HJT lines to fix below.

    Is this your expected home page? http://www.onlygoodsearch.com/10040/ If so, ignore the line I said to fix below. Otherwise fix it.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onlygoodsearch.com/10040/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    F3 - REG:win.ini: run=C:\WINDOWS\inetm\services.exe
    O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
    O2 - BHO: (no name) - {676DD3B1-1ADF-4894-A999-1AF4ADCD5A49} - C:\WINDOWS\System32\geki.dll (file missing)
    O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetm\services.exe
    O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRA~1\SpyBlocs\SpyBlocs.exe
    P2P file sharing programs like Shareaza can be more trouble than they are worth and can be the root cause of your problems.
    O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\MP3Downloading\bindata.exe" -tray
    O4 - HKCU\..\Run: [vCatch] C:\PROGRA~1\COMMON~2\VCatch\VCatch.exe
    O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetm\services.exe
    O23 - Service: ISEXEng - Unknown - C:\WINDOWS\System32\angelex.exe (file missing)

    After clicking Fix exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\inetm\services.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Dec 17, 2004
  5. dianawho

    dianawho Private E-2

    Thank you for your assistance... I apolgies for not following directions exactly, I have been getting extremely frustrated and this darn computer is evily possessed as it won't let me do some of my normal operations. I hope that it is just this hijacked page but I fear I have more problems then just the the hi jacked page. I try to unzip file however it wouldn't unzip for reasons unknown.. I borrowed an unzip program from a friend and will try to install this program however. There is a chance that I won't be able to do this as well because I have been having problems installing programs from my drives. As far as the log. I apologies for that as well.. I really have no excuse for that I guess I just over looked that part. I hope ya don't hold it against me. I am going to attempt to down load unzip program and fix this problem I will let you know how it goes.... If this doesn't work. I might still have a hammer... :)
     
  6. dianawho

    dianawho Private E-2

    It seem to work.. Thanks alot... Now i don't have to use the hammer. Is there any programs that I can download that will prevent my browser from being Hi jacked again? Again Thanks.... I so far I am a happy Surfer now...
     
  7. PhilliePhan

    PhilliePhan Guest

    Hi Diana,

    You should submit a fresh log to make sure everything evil is gone! I'm sure Chaslang would like to doublecheck it.

    Also, check out Chas' suggestions: How to Protect yourself from malware!

    Best :)
    PP
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's great Diana! Glad we could help. But PP is right, post a final log.
     
  9. dianawho

    dianawho Private E-2

    Ok will do.... Just got back on computer since fixing problem last night... will post log shortly
     
  10. dianawho

    dianawho Private E-2

    Ok here is the log... I hope it did it right this time.... Thanks again for the help... I will check out the malware you suggested.... Thank you Thank you Thank you
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Diana! Your log is clean! Happy Holidays!
     
    Last edited: Dec 18, 2004
  12. dianawho

    dianawho Private E-2

    Wooohooo... I just finish downloading some of the suggested programs to help prevent any more virus or spyware thanks alot
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing will stop it completely! We are not so lucky. But those items are a good step towards helping to reduce chances of problems. Malware changes/morphs and we see totally new problems all the time, so make sure you keep all applications up to date. Include Windows in that list too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds