This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Hijacked, Please Help

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am brand new to this service, but I have been under attack from "quickmetasearch" for about 6 weeks now. Please help me get rid of this pest! Jkirchner
Yahoo Sue, Here is a little music to celebrate with, give it a moment to start.
http://www.chefrick.com/html/cajunspeak.html

Keep an eye on your log for a few days, I will leave this link open. I have given you information on how to stay clean, I personally run Ad-aware SE Personal, Spybot S&D 1.3 and the proactive programs SpywareBlaster, SpywareGuard and IE-Spyad and of course antivirus software and a firewall.

If you ever want to get rid of the Yahoo stuff, I believe the Google Toolbar is the best search engine and popup blocker available, you can read about it here: http://toolbar.google.com/
If you ever want to learn more about spyware removal to help yourself and perhaps others, free training is available. Just PM any member of classroom for instuctions. Good Luck.

Thanks…pskelley
TomCoyote forum
Classroom Advanced
If you get help here consider a donation:
http://tomcoyote.com/donate.php
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
Sue, I apologize for JKirchner. The instructions must not be posted on each page in bold enough letters?

JKirchner, please see the instructions on each page.
DO Not post help or your HijackThis Log to another user's hijackthis log unless you have been given permission to do so,
not following this guideline can get you banned from this forum


Please look for the NEW TOPIC button, you are in the correct forum, post your HijackThis log making sure it is Version 1.99 and in a permanent folder. Give as much information as you can about the issue and then be patient. We are very buzy and are all volunteers. Thanks.
Pskelly, LOL, That was great, come on down to New Orleans for Mardi Gras, It is getting ready to start up full swing. C'est se bon ton roule!! ( let the good times roll ). Thank you so much for your help. Cajun Sue
I would love to, I having been trying to get to Mardi Gras for a while. Perhaps soon, we have a small festival this time of the year when the pirates take over the city in Tampa, Florida. I am glad I was able to help, and I will try a little cajun on you…lol. From Clearwater, Florida, right across the Gulf of Mexico I would like to say, Je te souhaite une bonne journée. pskelley
Pskelly, :unsure: Don't have a clue of what you just said, so I will be safe and just say uh huh. :lol: LOL I am just a little scottswoman that was born in New Orleans. I am still getting a couple of popups and I am not totally sure how the system is going to work. I really would like to thank you and everyone here that puts in so many hours to helping people. Thank you also for the links and the info. The classes sound like somethng that would help. If these popups get worse I will post again and wait my turn. Thank you again. Cajun Sue
I took another look at the log and do not see where the popups could be coming from. What are they? Not Messenger popups? These have nothing to do with the actual Windows Messenger in windows and can be turned off. I do suggest you consider the Google toolbar/popup stopper. The popups could be coming from Yahoo. The French/Cajun came from a website and is supposed to mean "Have a nice day" lol.
Pskelly, I am away from home tonight, staying with a sister. I will check the popup tomorrow. It is a casino, poker game site popup. When I cleaned this morning with adaware , I still had a few files from Cool web search. Adaware, seemed to get them all. I also reinstated spybot tea timer this afternoon before I left home and it only found the five DSO exploits. It may just be yahoo, I will keep and eye on it. Relaxing here and finally at ease over this pc. If I had any advice for anyone, it would be, make sure you know the people you let use your computer are responsible and respectful. This problem was caused by someone else's irresponsible behavior. The fact that they are seventeen is the only reason I am cutting them some slack, so to speak :lol: Thanks again, Cajun Sue
Pskelly, Ok, I hate to say this but I am back. I ran adaware this morning and it found 3 cool web search objects and 2 vx2. I am still getting quite a few popups but it takes a while for them to start showing up. The longer I am online the more there are. The wkyro.exe was back in there again till adaware finished. The web page that is popping up is USSEEK.com. There is also online casino. WWW.888.com. I have deleted the files a few times and after a while, poof they reappear. I don't know where to start. :huh: This is a new log. Thank you, Cajun Sue
:blink:
Sorry, forgot to add the log.

Logfile of HijackThis v1.99.0
Scan saved at 7:07:53 PM, on 1/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hnytyp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\unzipped\hijackthis[1]\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_3_12_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_03\bin\npjpi141_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_03\bin\npjpi141_03.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/isan/default/popcaploader_v6.cab
Hi Sue, It appears your antivurus program is not running in the log you just sent me. This is a fast way to get infected. Please activate whatever you are using right away. If you need something free, here are three to choose from.
I suggest the free version of AVG:
http://free.grisoft.com/freeweb.php
http://www.avast.com/eng/avast_4_home.html
http://store.ca.com/dr/v2/ec_main.entry25?…5715&CID=179825

Please open your Windows XP Control Panel and find out what is going on with your Security Center. You should be getting messages like mad about the AV being off. Make sure the SP2 Firewall is enabled unless you are running another firewall which I do not see.

Once you have this taken care of, please remember you will need to turn off or exit TeaTimer to make changes.

Follow these intructions, use the link below to download CWShredder Version 2.1. When you get to the download page please choose "Download the stand-alone version of CWShredder". Once installed make sure you update it first, then choose FIX not scan. Allow it to run and remove what it finds. Let me know what it located along with a new log. The last post had no log with it. Thanks…pskelley

http://www.intermute.com/spysubtract/cwshr…r_download.html

As soon as you have run this, please post the results, also information about what is going on with your Antivirus protections. Turning it off results in all sorts of infections being invited into your computer. I need to see a new log after CWShredder has been run. I also suggest you get SpywareBlaster and SpywareGuard installed and running for starters. the links below will provide the link to the download and a tutorials for their configuration and use.

http://www.bleepingcomputer.com/forums/tutorial49.html

http://www.bleepingcomputer.com/forums/tutorial50.html

Let's stick with this Sue, you are not finished until you have looked at the information provided and acted on that information to protect your computer. Thanks…pskelley
Sue, The log you just posted is from days ago??? Logfile of HijackThis v1.99.0 Scan saved at 7:07:53 PM, on 1/26/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Your second log posted: Logfile of HijackThis v1.99.0 Scan saved at 11:58:10 AM, on 1/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Shows your antivirus program clearly running. C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\Mcshield.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe O23 - Service: McAfee Framework Service - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe Please follow the instructions to download an run CWShredder then post a new log. While you wait on my next post, please review the information about SpywareBlaster and SpywareGuard. These programs will do much to protect you and they are free. There is one other program I stongly suggest, called IE-Spyad. Information is in the links I provided and I will send a tutorial for it soon. Thanks…pskelley
Pskelly,
Please forgive me I must have copied the wrong log, I will have to delete all of them.
I was so fried when I found that file this morning.
I will work on what you gve me. Sorry, I am not really a total ditz.

C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hnytyp.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\unzipped\hijackthis[1]\HijackThis.exe
O2 - BHO: (no name) - {00000000-F09C-02B4-6EC2-AD0300000000} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_3_12_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA} -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/isan/default/popcaploader_v6.cab
O23 - Service: McAfee Framework Service - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager - Network Associates,
Slow down Sue, the log you just posted has lines cut off the top. There is no need to post another log until after you run CWShredder. You may delete all old logs, just leave the backups for now. I usually keep a few so I can compare with the new one to make sure nothing has changed. We will defeat this malware. pskelley :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI