Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Hijacked Again!  (Read 10152 times)

0 Members and 1 Guest are viewing this topic.

jwfilion

    Topic Starter


    Intermediate

    Hijacked Again!
    « on: October 27, 2013, 07:11:18 PM »
    I have Google Chrome and a week ago I got hijacked by another Browser Hijack. This one is calling itself my-online-search. When this happened before, I believed I used RegSeeker to find them in the registry. However, this time it has hidden itself well and I cannot find any entries at all. I have read during all the searches for answers, that it must be removed before it can do real damage. When I searched, I found many results for different names of hijackers, but not this particular one. Downloaded Adwcleaner. AVG said IT was malware and suggested I remove it! Could someone help with this?


    Win XP Pro
    Version 2002 Service Pack 3
    HP Compaq dc 7100
    3.4 GhHz, 2 Gigs Ram
    AVG Antivirus, SUPERAntiSpyware, Malware Bytes

    Calum

    • Moderator


    • Egghead

      Thanked: 238
      • Yes
      • Yes
    • Certifications: List
    • Computer: Specs
    • Experience: Beginner
    • OS: Other
    Re: Hijacked Again!
    « Reply #1 on: October 28, 2013, 03:16:34 AM »
    I've moved this over to the malware removal section.  Please refer to the sticky threads at the top of the forum and post the appropriate information, and a malware specialist will assist you.

    Allan

    • Moderator

    • Mastermind
    • Thanked: 1260
    • Experience: Guru
    • OS: Windows 10
    Re: Hijacked Again!
    « Reply #2 on: October 28, 2013, 05:38:39 AM »
    Please follow the instructions in the following link and post your logs:
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    jwfilion

      Topic Starter


      Intermediate

      Re: Hijacked Again!
      « Reply #3 on: October 29, 2013, 03:31:08 PM »
      I downloaded Adwcleaner and again, AVG said it was malware. This time I allowed it and the logs follow:

      [recovering disk space, attachment deleted by admin]

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Hijacked Again!
      « Reply #4 on: October 29, 2013, 04:25:27 PM »
      Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
      *************************************************************************
      Please do not attach your logs unless absolutely necessary. Copy and paste them in your reply(ies)

      Update Your Java (JRE)

      Old versions of Java have vulnerabilities that malware can use to infect your system.


      First Verify your Java Version

      If there are any other version(s) installed then update now.

      Get the new version (if needed)

      If your version is out of date install the newest version of the Sun Java Runtime Environment.

      Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

      Be sure to close ALL open web browsers before starting the installation.

      Remove any old versions

      1. Download JavaRa and unzip the file to your Desktop.
      2. Open JavaRA.exe and choose Remove Older Versions
      3. Once complete exit JavaRA.

      Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
      ***********************************************
      Update your Adobe Reader. get.adobe.com/reader.

      Be sure to uncheck the Free McAfee Security Scan so it isn't installed.

      ***********************************************
      Malwarebytes' Anti-Rootkit

      Please download Malwarebytes' Anti-Rootkit and save it to your desktop.
      • Be sure to print out and follow the instructions provided on that same page for performing a scan.
      • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
      • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
      • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
      • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
      • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
      • Copy and paste the contents of these two log files in your next reply.
      Windows 8 and Windows 10 dual boot with two SSD's

      jwfilion

        Topic Starter


        Intermediate

        Re: Hijacked Again!
        « Reply #5 on: October 31, 2013, 01:20:44 AM »
        Well, after these programs ran, a few changes were evident. The hijack I had, seems to have disappeared. Google Chrome changed my homepage to theirs and I get an error message stating that my profile could not be opened correctly.
        Here are the logs:

        Malwarebytes Anti-Rootkit BETA 1.07.0.1007
        www.malwarebytes.org

        Database version: v2013.10.31.01

        Windows XP Service Pack 3 x86 NTFS
        Internet Explorer 8.0.6001.18702
        User :: HP36503695215 [administrator]

        10/30/2013 8:31:09 PM
        mbar-log-2013-10-30 (20-31-09).txt

        Scan type: Quick scan
        Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
        Scan options disabled:
        Objects scanned: 238907
        Time elapsed: 38 minute(s), 5 second(s)

        Memory Processes Detected: 0
        (No malicious items detected)

        Memory Modules Detected: 0
        (No malicious items detected)

        Registry Keys Detected: 0
        (No malicious items detected)

        Registry Values Detected: 0
        (No malicious items detected)

        Registry Data Items Detected: 0
        (No malicious items detected)

        Folders Detected: 0
        (No malicious items detected)

        Files Detected: 0
        (No malicious items detected)

        Physical Sectors Detected: 0
        (No malicious items detected)

        (end)

        ---------------------------------------
        Malwarebytes Anti-Rootkit BETA 1.07.0.1007

        (c) Malwarebytes Corporation 2011-2012

        OS version: 5.1.2600 Windows XP Service Pack 3 x86

        Account is Administrative

        Internet Explorer version: 8.0.6001.18702

        Java version: 1.6.0_23

        File system is: NTFS
        Disk drives: C:\ DRIVE_FIXED
        CPU speed: 3.391000 GHz
        Memory total: 2138292224, free: 1438724096

        Downloaded database version: v2013.10.31.01
        Downloaded database version: v2013.10.11.02
        =======================================
        ------------ Kernel report ------------
             10/30/2013 20:30:59
        ------------ Loaded modules -----------
        \WINDOWS\system32\ntkrnlpa.exe
        \WINDOWS\system32\hal.dll
        \WINDOWS\system32\KDCOM.DLL
        \WINDOWS\system32\BOOTVID.dll
        ACPI.sys
        \WINDOWS\system32\DRIVERS\WMILIB.SYS
        pci.sys
        isapnp.sys
        pciide.sys
        \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
        MountMgr.sys
        ftdisk.sys
        dmload.sys
        dmio.sys
        PartMgr.sys
        VolSnap.sys
        atapi.sys
        disk.sys
        \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
        fltmgr.sys
        sr.sys
        KSecDD.sys
        Ntfs.sys
        NDIS.sys
        Mup.sys
        avgrkx86.sys
        avgidshx.sys
        \SystemRoot\system32\DRIVERS\igxpmp32.sys
        \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
        \SystemRoot\system32\DRIVERS\usbuhci.sys
        \SystemRoot\system32\DRIVERS\USBPORT.SYS
        \SystemRoot\system32\DRIVERS\usbehci.sys
        \SystemRoot\system32\DRIVERS\HDAudBus.sys
        \SystemRoot\system32\DRIVERS\i8042prt.sys
        \SystemRoot\system32\DRIVERS\mouclass.sys
        \SystemRoot\system32\DRIVERS\kbdclass.sys
        \SystemRoot\system32\DRIVERS\parport.sys
        \SystemRoot\system32\DRIVERS\serial.sys
        \SystemRoot\system32\DRIVERS\serenum.sys
        \SystemRoot\system32\DRIVERS\fdc.sys
        \SystemRoot\system32\DRIVERS\imapi.sys
        \SystemRoot\system32\DRIVERS\cdrom.sys
        \SystemRoot\system32\DRIVERS\redbook.sys
        \SystemRoot\system32\DRIVERS\ks.sys
        \SystemRoot\system32\DRIVERS\intelppm.sys
        \SystemRoot\system32\DRIVERS\wmiacpi.sys
        \SystemRoot\system32\DRIVERS\audstub.sys
        \SystemRoot\system32\DRIVERS\rasl2tp.sys
        \SystemRoot\system32\DRIVERS\ndistapi.sys
        \SystemRoot\system32\DRIVERS\ndiswan.sys
        \SystemRoot\system32\DRIVERS\raspppoe.sys
        \SystemRoot\system32\DRIVERS\raspptp.sys
        \SystemRoot\system32\DRIVERS\TDI.SYS
        \SystemRoot\system32\DRIVERS\psched.sys
        \SystemRoot\system32\DRIVERS\msgpc.sys
        \SystemRoot\system32\DRIVERS\ptilink.sys
        \SystemRoot\system32\DRIVERS\raspti.sys
        \SystemRoot\system32\DRIVERS\rdpdr.sys
        \SystemRoot\system32\DRIVERS\termdd.sys
        \SystemRoot\system32\DRIVERS\swenum.sys
        \SystemRoot\system32\DRIVERS\update.sys
        \SystemRoot\system32\DRIVERS\mssmbios.sys
        \SystemRoot\System32\Drivers\NDProxy.SYS
        \SystemRoot\system32\DRIVERS\usbhub.sys
        \SystemRoot\system32\DRIVERS\USBD.SYS
        \SystemRoot\system32\drivers\RtkHDAud.sys
        \SystemRoot\system32\drivers\portcls.sys
        \SystemRoot\system32\drivers\drmk.sys
        \SystemRoot\system32\DRIVERS\avgmfx86.sys
        \SystemRoot\system32\DRIVERS\usbccgp.sys
        \SystemRoot\System32\Drivers\Fs_Rec.SYS
        \SystemRoot\System32\Drivers\Null.SYS
        \SystemRoot\System32\Drivers\Beep.SYS
        \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
        \SystemRoot\System32\drivers\vga.sys
        \SystemRoot\System32\Drivers\mnmdd.SYS
        \SystemRoot\system32\DRIVERS\emOEM.sys
        \SystemRoot\system32\DRIVERS\emBDA.sys
        \SystemRoot\system32\DRIVERS\BdaSup.SYS
        \SystemRoot\system32\drivers\emAudio.sys
        \SystemRoot\System32\DRIVERS\RDPCDD.sys
        \SystemRoot\System32\Drivers\Msfs.SYS
        \SystemRoot\System32\Drivers\Npfs.SYS
        \SystemRoot\system32\DRIVERS\rasacd.sys
        \SystemRoot\system32\DRIVERS\ipsec.sys
        \SystemRoot\system32\DRIVERS\tcpip.sys
        \SystemRoot\system32\DRIVERS\avgtdix.sys
        \SystemRoot\system32\DRIVERS\ipnat.sys
        \SystemRoot\system32\DRIVERS\wanarp.sys
        \SystemRoot\system32\DRIVERS\netbt.sys
        \SystemRoot\System32\drivers\afd.sys
        \SystemRoot\system32\DRIVERS\netbios.sys
        \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
        \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
        \SystemRoot\system32\DRIVERS\rdbss.sys
        \SystemRoot\system32\DRIVERS\mrxsmb.sys
        \SystemRoot\System32\Drivers\Fips.SYS
        \SystemRoot\system32\DRIVERS\avgldx86.sys
        \SystemRoot\system32\DRIVERS\hidusb.sys
        \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
        \SystemRoot\system32\DRIVERS\AGRSM.sys
        \SystemRoot\System32\Drivers\Modem.SYS
        \SystemRoot\system32\DRIVERS\mouhid.sys
        \SystemRoot\System32\Drivers\Cdfs.SYS
        \SystemRoot\System32\Drivers\dump_atapi.sys
        \SystemRoot\System32\Drivers\dump_WMILIB.SYS
        \SystemRoot\System32\win32k.sys
        \SystemRoot\System32\drivers\Dxapi.sys
        \SystemRoot\System32\watchdog.sys
        \SystemRoot\System32\drivers\dxg.sys
        \SystemRoot\System32\drivers\dxgthk.sys
        \SystemRoot\System32\igxpgd32.dll
        \SystemRoot\System32\igxprd32.dll
        \SystemRoot\System32\igxpdv32.DLL
        \SystemRoot\System32\igxpdx32.DLL
        \SystemRoot\System32\ATMFD.DLL
        \SystemRoot\system32\DRIVERS\fssfltr_tdi.sys
        \SystemRoot\system32\DRIVERS\ndisuio.sys
        \SystemRoot\system32\DRIVERS\mrxdav.sys
        \SystemRoot\system32\DRIVERS\avgidsshimx.sys
        \SystemRoot\system32\drivers\wdmaud.sys
        \SystemRoot\system32\drivers\sysaudio.sys
        \SystemRoot\system32\DRIVERS\srv.sys
        \SystemRoot\system32\DRIVERS\avgidsfilterx.sys
        \SystemRoot\system32\DRIVERS\avgidsdriverx.sys
        \SystemRoot\System32\Drivers\HTTP.sys
        \??\C:\Program Files\Broadcom\MgmtAgent\BASFND.sys
        \SystemRoot\system32\DRIVERS\asyncmac.sys
        \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
        \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
        \WINDOWS\system32\ntdll.dll
        ----------- End -----------
        Done!
        <<<1>>>
        Upper Device Name: \Device\Harddisk0\DR0
        Upper Device Object: 0xffffffff8a80cab8
        Upper Device Driver Name: \Driver\Disk\
        Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-3\
        Lower Device Object: 0xffffffff8a80f940
        Lower Device Driver Name: \Driver\atapi\
        <<<2>>>
        Physical Sector Size: 512
        Drive: 0, DevicePointer: 0xffffffff8a80cab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
        --------- Disk Stack ------
        DevicePointer: 0xffffffff8a874c60, DeviceName: Unknown, DriverName: \Driver\PartMgr\
        DevicePointer: 0xffffffff8a80cab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
        DevicePointer: 0xffffffff8a7d12a8, DeviceName: \Device\00000069\, DriverName: \Driver\ACPI\
        DevicePointer: 0xffffffff8a80f940, DeviceName: \Device\Ide\IdeDeviceP0T0L0-3\, DriverName: \Driver\atapi\
        ------------ End ----------
        Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
        Upper DeviceData: 0x0, 0x0, 0x0
        Lower DeviceData: 0x0, 0x0, 0x0
        <<<3>>>
        Volume: C:
        File system type: NTFS
        SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
        <<<2>>>
        <<<3>>>
        Volume: C:
        File system type: NTFS
        SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
        Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
        <<<2>>>
        <<<3>>>
        Volume: C:
        File system type: NTFS
        SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
        Done!
        Drive 0
        Scanning MBR on drive 0...
        Inspecting partition table:
        MBR Signature: 55AA
        Disk Signature: 5E2A4A5

        Partition information:

            Partition 0 type is Primary (0x7)
            Partition is ACTIVE.
            Partition starts at LBA: 63  Numsec = 632655702
            Partition file system is NTFS
            Partition is bootable

            Partition 1 type is Empty (0x0)
            Partition is NOT ACTIVE.
            Partition starts at LBA: 0  Numsec = 0

            Partition 2 type is Empty (0x0)
            Partition is NOT ACTIVE.
            Partition starts at LBA: 0  Numsec = 0

            Partition 3 type is Empty (0x0)
            Partition is NOT ACTIVE.
            Partition starts at LBA: 0  Numsec = 0

        Disk Size: 323928170496 bytes
        Sector size: 512 bytes

        Scanning physical sectors of unpartitioned space on drive 0 (1-62-632652208-632672208)...
        Done!
        Read File: File "C:\Documents and Settings\All Users\Application Data\AVG2012\log\avgcore.log.3" is compressed (flags = 1)
        Scan finished
        =======================================


        Removal queue found; removal started
        Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam...
        Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_0_63_i.mbam...
        Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam...
        Removal finished
        ---------------------------------------
        Malwarebytes Anti-Rootkit BETA 1.07.0.1007

        (c) Malwarebytes Corporation 2011-2012

        OS version: 5.1.2600 Windows XP Service Pack 3 x86

        Account is Administrative

        Internet Explorer version: 8.0.6001.18702

        Java version: 1.6.0_23

        File system is: NTFS
        Disk drives: C:\ DRIVE_FIXED
        CPU speed: 3.391000 GHz
        Memory total: 2138292224, free: 1285099520

        =======================================




        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Hijacked Again!
        « Reply #6 on: October 31, 2013, 12:50:01 PM »
        I'd like to scan your machine with ESET OnlineScan

        •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
        ESET OnlineScan

        •Click the button.
        •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
        • Click on to download the ESET Smart Installer. Save it to your desktop.
        • Double click on the icon on your desktop.
        •Check
        •Click the button.
        •Accept any security warnings from your browser.
        • Leave the check mark next to Remove found threats.
        •Check
        •Push the Start button.
        •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
        •When the scan completes, push
        •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
        •Push the button.
        •Push
        A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
        Windows 8 and Windows 10 dual boot with two SSD's

        jwfilion

          Topic Starter


          Intermediate

          Re: Hijacked Again!
          « Reply #7 on: November 01, 2013, 07:28:02 AM »
          Here's the log:

          ESETSmartInstaller@High as downloader log:
          all ok
          # version=8
          # OnlineScannerApp.exe=1.0.0.1
          # OnlineScanner.ocx=1.0.0.6920
          # api_version=3.0.2
          # EOSSerial=c0b43015365ade4bb1d88e4aca12c99f
          # engine=15718
          # end=finished
          # remove_checked=false
          # archives_checked=true
          # unwanted_checked=false
          # unsafe_checked=false
          # antistealth_checked=true
          # utc_time=2013-10-31 01:50:41
          # local_time=2013-10-30 08:50:41 (-0600, Central Daylight Time)
          # country="United States"
          # lang=1033
          # osver=5.1.2600 NT Service Pack 3
          # compatibility_mode=1034 16777213 100 81 0 69371425 0 0
          # scanned=107830
          # found=0
          # cleaned=0
          # scan_time=230717184

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Hijacked Again!
          « Reply #8 on: November 01, 2013, 12:40:23 PM »
          That looks good. How's your computer working now?
          Windows 8 and Windows 10 dual boot with two SSD's

          jwfilion

            Topic Starter


            Intermediate

            Re: Hijacked Again!
            « Reply #9 on: November 01, 2013, 08:02:37 PM »
            SuperDave, thanks for all your help! The hijack is gone and the computer is actually faster, however Google is screwed up. Guess I'll have to do some more "Googling" Again, thank you kindly!

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: Hijacked Again!
            « Reply #10 on: November 02, 2013, 12:31:03 PM »
            Quote
            however Google is screwed up. Guess I'll have to do some more "Googling" Again, thank you kindly!
            Try uninstall and re-installing Google.

            Click Start> Computer> right click the C Drive and choose Properties> enter
            Click Disk Cleanup from there.



            Click OK on the Disk Cleanup Screen.
            Click Yes on the Confirmation screen.



            This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
            **************************************
            Go to Microsoft Windows Update and get all critical updates.

            ----------

            I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

            Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.
            Windows 8 and Windows 10 dual boot with two SSD's

            jwfilion

              Topic Starter


              Intermediate

              Re: Hijacked Again!
              « Reply #11 on: November 02, 2013, 01:55:23 PM »
              Thanks again. I did all you suggested and Google Chrome is back to normal. As a point of interest, I had WOT on my computer a few years ago and it seemed to have disappeared. Glad someone brought it back to my attention! Thanks again.

              Wayne

              SuperDave

              • Malware Removal Specialist


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: Hijacked Again!
              « Reply #12 on: November 03, 2013, 06:48:00 PM »
              You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
              Windows 8 and Windows 10 dual boot with two SSD's