pretty sure IE is hijacked or something along those lines

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dc1984us, Jun 21, 2005.

  1. dc1984us

    dc1984us Private E-2

    I've already read and completed all the steps in the sticky post (read me first before asking for support thread) by MajorAttitude. I downloaded all files and did all the scans. I had a problem with the online scans when I went into safe mode with networking. I could not connect to the internet. I restarted in Normal mode and ran the scans. I then went back into safe mode and ran the other utilities that did not require internet access.

    The problem is when I open up IE, the progress bar flashes very fast and the bottom left of the browser, where it says what url/ip address you are connecting to flashes 'Connecting to site 152.163.211.120' and IE just sits there. I try to open up my IE properties by going to Tools>Internet Options and nothing happens. I have to go to start> right click on internet explorer and go to Internet properties to open the properties window up.

    When the problem first started about 4 hours ago when I was surfing where it says Connecting to, there was some weird url that appearing which was

    http://slirsdirect.search.aol.com/slirs_http/sredir=69&query=slirsdirect.search.aol.com/slirs_http%2

    I'm forced to use AOL to search the web now...

    If you guys need any more information let me know. Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. dc1984us

    dc1984us Private E-2

    Here is requested HJT log files. Thanks!
     
    Last edited: Dec 23, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you really have things running from three different drive letters? I see C:, D:, and G:

    I do not see where the below is loading but it is running.
    G:\Program Files\W32ALARM.exe

    Does this always load somehow at startup or did you have it running and forget to close it before running HijackThis?

    Your log shows no visible problems. Just one minor left over from running HSremove (which you should not have run). The minor item which can be fixed with HJT is:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm


    Try doing the following:
    - Open a command prompt by click Start, Run, and enter cmd and click OK
    - at the command prompt enter the below commands each followed by the enter key
    ipconfig /flushdns
    exit

    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Any improvement?
     
  5. dc1984us

    dc1984us Private E-2

    I fixed the problem with HJT and downloaded Hoster and restored original host and the problem still isn't resolved. That file W32Alarm.exe is for World Watch,which is my screen saver file I'm pretty sure. I thought that I installed that to my D: drive. C: is a partition for my windows and it's updates. D: is the rest of the HD where I throw my junk at. G: is my friends spare HD he gave me because he ordered SATA and his mobo didn't support SATA. Any suggestions?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First do the following:

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixIE.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixIE.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

    Now just try to reset your Web Settings.

    Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.



    Otherwise ask AOL why the screwed up your IE connection because that address belongs to them.

    Code:
     [url="http://samspade.org/t/whois?a=slirsredirect-rtc.search.aol.com;server=auto"][color=#606420]slirsredirect-rtc.search.aol.com[/color][/url] = [ ] 
     
    Domain Name: [url="http://samspade.org/t/whois?a=AOL.COM;server=auto"][color=#0000ff]AOL.COM[/color][/url] 
    Registrant: 
    	America Online Inc. 
    		22000 AOL Way 
    		Dulles VA 20166 
    		US 
    	Created on..............: May 17 2004 12: 34PM 
    	Expires on..............: Nov 23 2005 7: 02AM 
    	Record Last Updated on..: Feb 25 2005 4: 24PM 
    	Registrar...............: America Online Inc. 
    							 [url="http://whois.registrar.aol.com/whois/"][color=#0000ff]http://whois.registrar.aol.com/whois/[/color][/url] 
    	Administrative Contact: 
    		AOL Domain Administration (America Online Inc.) 
    		22000 AOL Way 
    		Dulles VA 20166 
    		US 
    		Tel. 703 265 4670 
    		Email: [email="domains@aol.net"][color=#0000ff]domains@aol.net[/color][/email]
     
    	Technical Contact: 
    		America Online Inc. 
    		22000 AOL Way 
    		Dulles VA 20166 
    		US 
    		Tel. 703 265 4670 
    		Email: [email="domains@aol.net"][color=#0000ff]domains@aol.net[/color][/email]
    
     
    Last edited: Jun 23, 2005
  7. dc1984us

    dc1984us Private E-2

    Unfortunately it didn't work. I'll get in touch with AOL and ask them what happened. I downloaded Firefox and I'm liking it so might not worry about it...Thanks for your assistance.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Without the ability to run IE properly you will not be able to get any Windows updates and some other websites may require IE too.
     
  9. dc1984us

    dc1984us Private E-2

    Yeah I just noticed that when I tried to upgrade my IE version like AOL told me to. I talked to two techs and one said try windows updates and well, that didn't work since IE is non-functional. I went to sleep and said I'll mess around with it later. The other tech said I need to "Talk to your computer manufacturer about the problem and reload your windows operating system because sometimes those spyware can be a real pain in the butt and that's the only way to get rid of them." Not really pleased with the level of support I got from them. Is it possible to get windows updates any other way?

    Also, I've never used system restore. Is it possible to do a system restore to like 10 days ago, which is before the problem started?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you ran ALL the steps in the READ ME FIRST as indicated in message number one, you have no restore points because System Restore was disabled in step 1. Once a system is infected it is very difficult to trust that restore points are clean. Malware can come back if from infected restore points. That is why it is the first step to disable system restore.

    Exactly what happens when you run IE? Give details!

    Does the exact same thing happen in safe mode?

    You could try the info in this link: http://support.microsoft.com/default.aspx?kbid=318378

    Or this one: http://www.theeldergeek.com/repair_ie6.htm
     
    Last edited: Jun 24, 2005
  11. dc1984us

    dc1984us Private E-2

    I'll be as detailed as I can.

    When I open up IE, my homepage is displayed in the title bar, but it doesn't appear in the address bar. In the bottom left hand corner of the screen where it says "Connecting to site...." that flashes 'Connecting to site 152.163.211.120' and other times it flashes 'http://slirsdirect.search.aol.com/s...%2Fslirs_http%2'. The progress bar at the bottom right hand corner of IE where the green bars are located at flash as well. The flashing occurs until I close down IE or until I hit stop. After I hit stop and try to type in a different URL, such as www.majorgeeks.com, the flashing 'Connecting to site....' changes to a different URL, but it also flashes 'http://slirsdirect.search.aol.com/s...%2Fslirs_http%2'. The progress bar also flahses. When I set my homepage to about:Blank, IE opens up fine. However when I try to type in a URL to navigate to, the same problem happens.

    I actually got to go to work now, but when I get back later on today, I'll try rebooting in Safe Mode with Networking and try IE, however when I tried to do the online scans in Safe Mode with Networking when I did the read me by MajorAttitude, I was unable to connect to the internet. My shortcut to connect to the internet would not open. I ran the online scans in Normal mode. I'll post with the results what happens when I get back from work when I try going to Safe Mode.

    I really appreciate the time you've taken so far to help me!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand why your IE is still trying to connect to that URL at startup when I had you Reset Web Settings. Did the RESET work? Is majorgeeks listed as your home page? If not, Reset Web Settings again.

    Make sure you check out the links in my last thread too.
     
  13. dc1984us

    dc1984us Private E-2

    Here's what I've done since the last post. I tried rebooting in Safe Mode with Networking. When I did that I was unable to connect to the internet. When I clicked on my icon to connect, it would not open up. I tried going to My Computer and then went to Network Places and there were no icons. I tried rebooting in Safe Mode as well as Safe Mode with Networking. I got the same results using both methods. I went to the geek elder and used his methods to try to restore IE. Neither worked. I went to the windows website and tried updating my IE to IE v.6 SP1. After I downloaded it and tried to re-install it, I got an error message saying that installation would not continue since I have a newer version on my computer. I got windows automatic updates enabled so I won't forget to get downloads so I guess my windows xp is up to date on all patches and updates. When I reset my web settings it makes my homepage some microsoft site. I tried opening up that page and I got the same URL and the same IP address flashing at the bottom left corner of IE. I closed down IE and reset the web settings again and changed my homepage to www.majorgeeks.com. Once again when I opened up IE, the same URL and IP were flashing when I tried using the microsoft homepage.

    Is there anything else you can think that could fix this, or do you think I should not worry about this problem and use an alternate browser such as Firefox?

    Thanks again.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already stated that you will need IE sometimes. Yes you can and should use FireFox but someday you will need IE.

    Do you need AOL to connect to the internet? If not try getting rid of all the crap they put on your PC.
    Just look at the below:
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\PROGRA~1\COMMON~1\AOL\110718~1\EE\AOLHOS~1.EXE
    C:\PROGRA~1\COMMON~1\AOL\110718~1\EE\AOLServiceHost.exe
    C:\Program Files\America Online 9.0\waol.exe
    C:\Program Files\America Online 9.0\shellmon.exe

    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1107189655\EE\AOLHostManager.exe
    O4 - HKCU\..\Run: [AIM] D:\PROGRA~1\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
    O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\PROGRA~1\AIM\aim.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe

    While I cannot be positive that this is the problem, it is there URL that you keep getting redirected to.

    The only other thing to try would be to boot into safe mode (with no network support - I do not want the ability to connect). Then use Task Manager to kill all the below processes and then reset your websettings as I described before:

    Kill the below (if running):
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\PROGRA~1\COMMON~1\AOL\110718~1\EE\AOLHOS~1.EXE
    C:\PROGRA~1\COMMON~1\AOL\110718~1\EE\AOLServiceHost.exe
    C:\Program Files\America Online 9.0\waol.exe
    C:\Program Files\America Online 9.0\shellmon.exe
     
  15. dc1984us

    dc1984us Private E-2

    Making some progress now. I used HJT and fixed the things you pointed out. I rebooted in safe mode. None of the processes you stated were running. I reset web settings anyways. Rebooted back to normal mode and opened up IE. This time the flashing URL and IP address and progress bar did not happen. However, when I type in www.majorgeeks.com, the URL on the status bar of IE went from www.majorgeeks.com.net then to www.majorgeeks.com.org then to www.majorgeeks.com.edu and the it said 'Cannot open page www.majorgeeks.com.' But at least it's not giving me the AOL URL that keeps appearing.

    I do not use AOL to connect to the internet. I use my ADSL and use AOL v9.0 to check email, chat and that's it basically...

    I'm just curious, what's the big difference between Firefox and IE?

    Thanks again!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not have fixed items for AOL using HJT. I did not recommend that. I really meant uninstall if not needed. Just want to get it out of the way to see if it was what was causing your problems. Looks like it was.

    Now with AOL uninstall or all process for it ended, repeat the fixIE.reg registry merge from message # 6.

    Firefox has fewer security holes than IE and it typical runs faster. You'll like it.
     
  17. dc1984us

    dc1984us Private E-2

    I guess I didn't read carefully enough. I did a test on AOL to make sure I didn't screw anything up and luckily I didn't thankfully.

    I ran the fixIE.reg file again. I reset my websettings before and after I ran it. The AOL URL is not appearing, however the pages are still not being found. Whatever URL I type in and after I hit enter, searches for www.majorgeeks.com, for example, then it searches www.majorgeeks.com.com, then www.majorgeeks.com.net, www.majorgeeks.com.org, etc etc. Then it says page cannot be found. I went back to the elder geeks website and tried his fix, however that didn't fix the problem. Since the AOL URL issue is resolved, should I post this on the software forums?

    Thanks for the great support!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have a feeling AOL messed up some of your IE settings too. Let's try one more thing:

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixURL.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixURL.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

     
  19. dc1984us

    dc1984us Private E-2

    Didn't work. I guess when I get time I'll re-install XP. Do you know any good backup programs? I got a spare hard drive for backups. Should I just copy paste my setup files there and whatever else I want or should I use some app? Thanks .
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are considering reinstalling XP first try removing (uninstalling) all components of AOL and see what happens.

    For info on Backups, refer to: http://www.majorgeeks.com/downloads3.html
    or ask questions in the Software Forum
     
  21. dc1984us

    dc1984us Private E-2

    Will do. I'll probably un-install AOL tomorrow night and see what that does. I'll let ya know the results. Thanks for the assistance!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     
  23. dc1984us

    dc1984us Private E-2

    Tried un-installing AOL. That didn't fix it so I'm gonna re-install XP when I get a chance. Thanks again.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds