This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] infected and hijack this error

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Ken Thanks again for your time, trouble and expertise - here's the Esat log - 2 files picked up both variations of the 'Kryptik' virus/trojan ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) # OnlineScanner.ocx=1.0.0.6048 # api_version=3.0.2 # EOSSerial=cb5885f421d9d0438cb5f925f3a1c533 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-08-14 06:53:44 # local_time=2009-08-14 07:53:44 (+0000, GMT Standard Time) # country="Ireland" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=769 21 100 100 58796875000 # compatibility_mode=5889 61 66 100 747336344218750 # scanned=83036 # found=0 # cleaned=0 # scan_time=4754 # version=6 # IEXPLORE.EXE=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) # OnlineScanner.ocx=1.0.0.6048 # api_version=3.0.2 # EOSSerial=cb5885f421d9d0438cb5f925f3a1c533 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-08-19 04:49:45 # local_time=2009-08-19 05:49:45 (+0000, GMT Standard Time) # country="Ireland" # lang=9 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=769 21 100 100 55328281250 # compatibility_mode=5889 61 66 100 751581950937500 # scanned=98631 # found=2 # cleaned=2 # scan_time=5215 C:\System Volume Information\_restore{3E894255-E391-4DFD-B4C2-0C39833F0E22}\RP352\A0076650.dll a variant of Win32/Kryptik.QY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3E894255-E391-4DFD-B4C2-0C39833F0E22}\RP402\A0116131.dll a variant of Win32/Kryptik.SR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
Hi Matts,

Not to worry, your good to go, :thumbup: what ESET found where files in your System Restore Program, lets flush it all out as to not reinfect you. This was going to be part of the final clean up anyway.

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.

  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.

Reboot your computer

Turn ON System Restore.

  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.

Create a new Restore Point <– Very Important

  • Go to Start> All Programs> Assesories> System Tools> System Restore and create a New Restore Point
System Restore Tutorial <– If you need it




Lets update your Java to make your system more secure

Go to your Control Panel and click on the Java Icon ( looks like a little coffee cup ) click on About and you should have Version 6 Update 15, if not proceed with the instructions.

Download the latest version Here save it, do not install it yet.

Java SE Runtime Environment (JRE)JRE 6 Update 15 <–The wording is confusing but this is what you need

  • Go to your Add Remove Programs in the Control Panel and uninstall any previous versions of Java
  • Reboot your computer
  • Install the latest version
You can verify the installation Here



Matts, basically the hosts file converts language into numbers, example is when you type in www.amazon.com your computer converts it to number which is the IP address of that site so it can find it on the internet . If someone asked you where you got that nice shirt it would be easier if you told them at Marvinshirts instead of 212.034.112.123. Malware changed most of those numbers so that on some sites that you would try to inter it basically directed you to anyplace they wanted you to go. In the meantime the hosts file got corrupted but its all fixed now and back to Microsoft defaults.
Info here
http://www.mvps.org/winhelp2002/hosts.htm

How are things running now???
Hi Ken done everything that you requested - PC is running well now - ive reset my home page back to google and it's working a treat. anything else i need to do ?- any recomendations for protecting myself in the future or things that i should download to keep me safe ?. thanks,your aid was invaluable. matts
Good Morning Matts,

When I first got into computing in the days of windows 3.1 and then to windows 95, kids and people that had nothing better to do wrote viruses, at the most they would make your screen wobble or some other stupid thing, but thats all changed now, cyber criminals write this garbage and there aim is to steal anything they can from you, bank account numbers, credit card numbers , passwords and the list goes on. The reason for me stating this is because there is no silver bullet for staying safe on line but every thing that you add to that arsenal helps. Your Operating System is out of date and thats not good, your Internet Explorer browser is out of date as well.

Open IE and go to Tools> Windows updates and download and install every critical update that is offered , this should include SP3 (Service Pack 3) and beyond and also include Internet Explorer 8

Malwarebytes <– Yours to keep also, check for updates and run a scan now and then.

Combofix <—Is not a general cleaning tool, just run it with supervision or you can bork your system

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


    • [external image: Posted Image]

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports



Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster and Spyware Guard, they will conflict with the TeaTimer in Spybot , you can still install Spybot Search and Destroy but do not enable the TeaTimer .



Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.6
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Safe Surfn
Ken
cheers again i'll do as you suggest when i get the chance to as im in work - again thanks for the prompt and expert help, you really know your stuff ! have a good one and slainte ! Matts
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI