PLZ Help with hijacked browser

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by zooper, Sep 21, 2004.

  1. zooper

    zooper Private E-2

    i have one big problem about hijacked browser my friends

    i download Browser Hijack Recover(BHR) 1.01 and run the program

    how to delete the problem i dont know

    the log is my friends
    [Log file removed]
     
  2. Kodo

    Kodo SNATCHSQUATCH

  3. zooper

    zooper Private E-2

    yes yes my friend i have read this posts because i have windows /me

    i do all the steps i check the box . now this programs not run when i restast my computer

    after this steps what i can do?

    plz tell me step by step
     
  4. Kodo

    Kodo SNATCHSQUATCH

    I'm not really sure I understand what you're saying.

    So let me try to translate.

    You read both the links I posted and followed all the steps?
    (The steps in there include instructions for scanning winME machines. )

    You believe that you've cleaned your computer and you want to know what to do after it's cleaned?
     
  5. zooper

    zooper Private E-2

    noooo i dont say my computer now is clean

    simply the programs not run and now i can delete this

    now iam in site http://hijackthis.de/index.php and i try to find the nasty programs to delete them

    is the right way my friend?

    and sorry again about my english

    i hope to understand me
     
  6. zooper

    zooper Private E-2

    one last question

    i delete only the nasty files?or and unknown files

    only safe files not delete?
     
  7. Kodo

    Kodo SNATCHSQUATCH

    I'm having a launage barrier problem. What is your native language. Maybe someone here can help translate for you.
     
  8. zooper

    zooper Private E-2

    why u dont unterstand...

    i follow(The steps in there include instructions for scanning winME machines. ) as u say

    and now try to delete files with
    http://hijackthis.de/index.php

    BUT THE NASTY FILES IS HERE AGAIN..

    I CANT UNDERSTANT MY FRIEND

    MAYBE ITS TIME TO FORMAT.?

    can u explain me why the nasty files dont deleted...and is back again
     
  9. Kodo

    Kodo SNATCHSQUATCH

    HijackThis is a last step mechanism to removing the problem.
    Please copy your Hijackthis log to a TXT file and attach it to a post in this thread and we'll take a look. You have other problems on the machine that need to be fixed first.
     
  10. zooper

    zooper Private E-2

    ok my friend thanks

    my log file is this
     
    Last edited by a moderator: Sep 22, 2004
  11. zooper

    zooper Private E-2

  12. zooper

    zooper Private E-2

    Re: someone to explain me plz

    my log now is this
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: someone to explain me plz

    Please do not create new threads for a problem on which you have already started a thread.
    I have merged them together.

    Second issue: we do not look at BHR logs. At least not yet. You were asked to post a HijackThis log file as an attachment not a BHR log.

    But first I would like to know what you problem is. You never explained why or what you think you are being hijacked by.
     
  14. zooper

    zooper Private E-2

    ok my friend thanks for explain me about log

    i cant speak english and this is the reason to not explain

    but i have or i fad problem about my internet explorer

    the first page was coolsearch.biz and dialers

    my log is this
     

    Attached Files:

    Last edited by a moderator: Sep 22, 2004
  15. Kodo

    Kodo SNATCHSQUATCH

    zooper. this looks like you ran HJT from a temporary directory. Make sure you save it to it's own directory and then run if from there.

    So make a directory called "HJT" and place the pogram in there and then run it.

    But from what I see so far, it looks clean.

    ------------

    For Chaslang Only:
    I see this
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll

    but I think it's ok. I remember seeing it someplace before.
     
  16. zooper

    zooper Private E-2

    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll

    i delete and this my friend kodo for sure

    now my friend i have 2 last questions

    1)its good to Enable System Restore ? because i want my computer works as before
    2)its better to download internet explorer 6
    now i use i.e 5.5

    plz answer the 2 last questions

    thanks for all my friend
     
  17. Kodo

    Kodo SNATCHSQUATCH

    using system restore and periodically making restore points is a good idea.

    As for a browser, I would upgrade to IE6 and get all the critical updates for it but I would USE the following browser instead of IE on a daily basis.

    FireFox 1.0PR
    http://www.majorgeeks.com/download.php?det=2248

    It's highly customizable and very easy to use.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, it's OK. It is part of Adobe Acrobat Reader.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm concerned about this line from you HJT log:

    O4 - HKLM\..\RunServices: [NVSvc] C:\WINDOWS\SYSTEM\nvsvc.exe -runservice

    It appears to be a worm. See the below link.

    http://www.sophos.com/virusinfo/analyses/w32agobotel.html

    I would run McAfee Avert Stinger to see if it can repair this. Otherwise we may have to do this manually.

    As Kodo said, you need to get the Critical Updates from Microsoft.
     
  20. Kodo

    Kodo SNATCHSQUATCH

    Agobot..
    Damn, I saw that I thought "Nvidia"..
     
  21. zooper

    zooper Private E-2

    thanks a million my friends

    kodo what do u mean
    (Agobot..
    Damn, I saw that I thought "Nvidia)

    i hope all is ok

    thanks again an again my friends
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    He is referring to my message on:
    O4 - HKLM\..\RunServices: [NVSvc] C:\WINDOWS\SYSTEM\nvsvc.exe -runservice
     
  23. zooper

    zooper Private E-2

    ok i understand

    now what is the

    FireFox 1.0PR

    i download this

    is about explorer?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is a browser that you can use instead of Internet Explorer. Has less problems with malware than IE.
    Get it here: http://www.majorgeeks.com/download2248.html
     
  25. Kodo

    Kodo SNATCHSQUATCH

    yes. it is an alternative browser to using Internet Explorer.
     
  26. zooper

    zooper Private E-2

    thanks a million my friend

    i install firefox

    thanks for all again
     
  27. Kodo

    Kodo SNATCHSQUATCH


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds