still have a problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Alicia, Apr 18, 2005.

  1. Alicia

    Alicia Private E-2

    ok well i did everything in the thread that u recommended, downloaded all the programs and in terms of the "onlythe best" popups those have not reappeared so far, but i'm still getting the homepage problem where it is being automatically changed to about blank. i downloaded the hijackthis file as u recommended and i saved the log which i've attached to to this message. in here is the log, please help me :(
     
  2. jarcher

    jarcher I can't handle a title

    try to keep the same problem in one thread
    I see you have three

    run cwshredder(wich you should have)
    run hjt and check

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [MessengerPlus3] \"C:\Program Files\Messenger Plus! 3\MsgPlus.exe\"
    O4 - HKLM\..\Run: [sdkjp.exe] C:\WINDOWS\system32\sdkjp.exe
    O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    click fix

    Go to "Add/Remove Programs" in the Control Panel and uninstall Messenger Plus.
    (Messenger Plus adds features to MSN Messenger, but also adds the lop.com trojan)

    Delete the file gah95on6.exe which resides in C:\WINDOWS\System32\ or C:\WINDOWS\System\

    run ccleaner(which you should have if you completed the read me's)
    restart
    and post a new log
    in this thread
     
  3. Alicia

    Alicia Private E-2

    ok this is the new log i did not find gah95on6.exe and well the homepage is still coming up as about blank. :(
     

    Attached Files:

  4. jarcher

    jarcher I can't handle a title

    open the task manager( ctrl>alt>del)
    and end this process
    winon.exe

    run hjt and check
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {24C57E96-1520-C344-184A-B7C38F985690} - C:\WINDOWS\system32\sdkkm32.dll
    O4 - HKLM\..\RunOnce: [winon.exe] C:\WINDOWS\system32\winon.exe

    O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html <<<<< I am not familier(sp) with it

    O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysif32.exe (file missing)

    close all windows(including this one)
    click fix
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds