This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE being hijacked on load up to fake google site

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is a follow-up on post http://forums.whatthetech.com/findpost_p529201.html being looked at by Catbyte but which has been closed due to inactivity. I was unable to follow up due to other commitments during the week and was intending to look at it at the weekend.

In response to Catbyte requets, performed instructions and new Hijack log attached as well as Malware log.

Both files have been uplaoded as requested. Computer seems to be working fine and no re-occurance of problem

Regards

NeilD
Hi neild, sorry for the closure - thought we'd lost you, Logs look better There is a little bit of clean up still left to do…I'll be back shortly with instructions CB
Hi neild

Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Hello Catbyte Scan took 5 hrs plus. Report shown below. What now Thanks NeilD —————————————————————————————————————- *KASPERSKY ONLINE SCANNER 7 REPORT* Saturday, February 21, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Saturday, February 21, 2009 07:37:27 Records in database: 1825018 *Scan settings* Scan using the following database extended Scan archives yes Scan mail databases yes *Scan area* My Computer C:\ D:\ E:\ *Scan statistics* Files scanned 216688 Threat name 1 Infected objects 1 Suspicious objects 0 Duration of the scan 05:10:09 *File name* *Threat name* *Threats count* C:\Documents and Settings\Neil Darby\My Documents\My Received Files\k89ll.zip Infected: Backdoor.Win32.Agent.deu 1 * The selected area was scanned.* ———————————————————————————————————
Hi neild


You should still have OTMoveIt3 on your desktop:

(if you have deleted it down load a fresh copy here - OTMoveIt3 by OldTimer.

Please do the following:

  • Please click OTMoveIt3 and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Services

:Reg

:Files
C:\Documents and Settings\Neil Darby\My Documents\My ReceivedFiles\k89ll.zip

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


In your next reply I need
  • OTlogs
Hi OT Log below Thanks NeilD ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== File/Folder C:\Documents and Settings\Neil Darby\My Documents\My ReceivedFiles\k89ll.zip not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\NEILDA~1\LOCALS~1\Temp\etilqs_q6rAINrkjo0fgP1qb3uh scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\NEILDA~1\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\NEILDA~1\LOCALS~1\Temp\~DF5E36.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\NEILDA~1\LOCALS~1\Temp\~DFBBAC.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_72c.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_7K2bMxkZMZTEy52 scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_kXIX8AVqbwB91v4 scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_pPBYXk8UiXQJ37o scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\TMP0000004069F08E4F716EB785 scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\TMP000009C29122EA26F68571C7 scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\TMP00004042227EE69833D4D01D scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\ZLT009d9.TMP scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully Error: Unable to interpret <[Reboot> in the current context! Error: Unable to interpret < * Return to OTMoveIt3, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.> in the current context! Error: Unable to interpret < * Click the red Moveit! button.> in the current context! Error: Unable to interpret < * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.> in the current context! Error: Unable to interpret < * Close OTMoveIt3> in the current context! OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02212009_173829
Hi Am rebooting computer. Results as below. Am I doing anything wrong ? Thanks NeilD ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== File/Folder C:\Documents and Settings\Neil Darby\My Documents\My ReceivedFiles\k89ll.zip not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\NEILDA~1\LOCALS~1\Temp\etilqs_icY8u1C3jMUJ7H1ILSos scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\NEILDA~1\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\NEILDA~1\LOCALS~1\Temp\~DF69E7.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\NEILDA~1\LOCALS~1\Temp\~DFE3AD.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_678.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_bkfcLyCabsFtHcU scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_dvTAoktWsrTIvRE scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_veTnJ83Vjra26gC scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\TMP0000003D424E41F115689C85 scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\ZLT006c1.TMP scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Neil Darby\Local Settings\Application Data\Mozilla\Firefox\Profiles\rxbr4xsv.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02212009_183701
Good news: computer looks clean :thumbup:

Now we need to clean up after ourselves:


Clean up with OTMoveIt3:
  • Double-click OTMoveIt3.exe to start the program.
  • Close all other programs apart from OTMoveIt3 as this step will require a reboot
  • On the OTMoveIt3 main screen, press the CleanUp! button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Next:

You have outdated Java remaining on your system, this can lead to a security vulnerability so they need to be removed:
The good news is, you need only do this one time, as the newest Java programs will now overwrite the old.

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer. (Java 6 update 12)

Next

Your Adobe Reader is outdated and should be replaced for the same reason:

Visit ADOBE and download the latest version of Acrobat Reader (version 9).

Next

You have various items on your computer that you may not know are installed as they generally come bundled with other programs.
If you do not use these items, I suggest you remove them via Add/Remove Programs
  • Ask Toolbar
  • Viewpoint Media Player
  • Viewpoint

There are remnants of Norton still remaining on your system. Symantec offer a removal tool to delete the remaining files:
Download the Norton Remover tool for your product and follow the instructions for removal.

Next:

We need to set a new system restore point:

Click Start > Run > copy and paste the following into the run box:


%SystemRoot%\System32\restore\rstrui.exe


Press OK. Choose Create a Restore Point then click Next.
Name it (something you'll remember) and click Create,
when the confirmation screen shows the restore point has been created click Close.

Now remove all previous Restore Points:

Click Start > Run > copy and paste the following into the run box:


cleanmgr


At the top, click on More Options tab. Click the Clean up button in the System Restore box.
Click on the Yes button.
When finished, click on Cancel button to exit.

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • For Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
  • Please read the guide by Rorschach112 on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI