Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Opera Hijacked!!!  (Read 5313 times)

0 Members and 1 Guest are viewing this topic.

Dilbert

    Topic Starter
  • Moderator


  • Egghead

  • Welcome to ComputerHope!
  • Thanked: 44
    Opera Hijacked!!!
    « on: April 06, 2006, 04:48:07 PM »
    I was answering a post about a "keylogger" so I googled and tried to C&P a link. However, when I got back, I couldn't type anything. Cut-and-paste was this:

    5**-**4-**** cell (I changed the numbers to *'s to secure the privacy of the person)

    I did type this in, but I don't remember putting it on the clipboard. And I could type in notepad, but nothing worked in the post box. I closed and restarted, a little annoyed. Normally I get a dialog box asking "start from previous" "start X session" "start with blank" "start with none". However, I gat about:blank as the page. I - *censored*???

    The hijacker appears to have deleted itself - no, I ran the aboutBuster. But I don't know if it'll come back. Just in case, I'm attaching a HijackThis logfile.
    « Last Edit: April 06, 2006, 04:48:37 PM by Timothy_Bennett »
    "The geek shall inherit the Earth."

    dl65

    • R.I.P.


    • Prodigy

      Thanked: 18
      Re: Opera Hijacked!!!
      « Reply #1 on: April 06, 2006, 05:09:22 PM »
      Dilbert....... So are you certain you have completely removed the highjacker ..... and I noticed that you did not include all the info in your hijacker log ......  the very top info is missing and that is important .
      BTW .... I have recently sent you 2 pMs and you dont seem to reply to them , is there some reason you dont ?

      dl65  ::)
      « Last Edit: April 06, 2006, 05:12:18 PM by dl65 »
      If you don't know the answer, it isn't a dumb question.

      Dilbert

        Topic Starter
      • Moderator


      • Egghead

      • Welcome to ComputerHope!
      • Thanked: 44
        Re: Opera Hijacked!!!
        « Reply #2 on: April 06, 2006, 05:21:14 PM »
        I only got one, and I replied to it.

        OK, sorry. I removed the top info to save space because attachments weren't working for me as they should. Top info is:

        Logfile of HijackThis v1.99.1
        Scan saved at 3:46:29 PM, on 4/6/2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        "The geek shall inherit the Earth."

        dl65

        • R.I.P.


        • Prodigy

          Thanked: 18
          Re: Opera Hijacked!!!
          « Reply #3 on: April 06, 2006, 05:27:26 PM »
          Dilbert , ok ...... How did you get rid of the hijacker ? I ask so I may suggest what apps to run to ensure your clean.


          dl65  ::)
          If you don't know the answer, it isn't a dumb question.

          Dilbert

            Topic Starter
          • Moderator


          • Egghead

          • Welcome to ComputerHope!
          • Thanked: 44
            Re: Opera Hijacked!!!
            « Reply #4 on: April 06, 2006, 05:29:23 PM »
            I ran AboutBuster
            « Last Edit: April 06, 2006, 05:34:17 PM by dl65 »
            "The geek shall inherit the Earth."

            dl65

            • R.I.P.


            • Prodigy

              Thanked: 18
              Re: Opera Hijacked!!!
              « Reply #5 on: April 06, 2006, 05:33:14 PM »
              Dilbert , the scan you attached....... was that from before you started the cleanse or after you finished ?

              dl65  ::)
              If you don't know the answer, it isn't a dumb question.

              Dilbert

                Topic Starter
              • Moderator


              • Egghead

              • Welcome to ComputerHope!
              • Thanked: 44
                Re: Opera Hijacked!!!
                « Reply #6 on: April 06, 2006, 07:29:47 PM »
                Right after.

                Ad-Aware came back with a Tracking Cookie and removed it. Norton found nothing. Spybot found and removed the following:

                Comet Cursors
                MyWay.Mysearch
                Windows Security Center.AntiVirusOverride
                Windows Security Center.FirewallDisableNotify
                "The geek shall inherit the Earth."

                Dilbert

                  Topic Starter
                • Moderator


                • Egghead

                • Welcome to ComputerHope!
                • Thanked: 44
                  Re: Opera Hijacked!!!
                  « Reply #7 on: April 06, 2006, 08:25:40 PM »
                  An aside: I downloaded SpyBot on my mother's computer. She insisted that her limited Internet use kept her safe, but no less than 22 problems were founds, including Windows Security Center.FirewallDisableNotify and Windows Security Center.AntiVirusDisableNotify
                  "The geek shall inherit the Earth."

                  dl65

                  • R.I.P.


                  • Prodigy

                    Thanked: 18
                    Re: Opera Hijacked!!!
                    « Reply #8 on: April 06, 2006, 10:08:13 PM »
                    Dilbert....ok ,  In your running processes ...... Use the device manage to kill....

                      C:\WINDOWS\system32\cfpsys.exe  

                    Now mark for removal the following :

                    O4 - HKLM\..\Run: [Warning: do not remove it! (system)] cfpsys.exe

                    017 ..... ALL of them UNLESS THEY ARE ASSOCIATED WITH YOUR ISP

                    O23 - Service: MySQL - Unknown owner - C:\MySQL\bin\mysqld-nt".exe (file missing)

                    If they are all marked .....click fix checked ......

                    Then reboot and post a fresh logfile .

                    dl65  ::)
                    If you don't know the answer, it isn't a dumb question.

                    Dilbert

                      Topic Starter
                    • Moderator


                    • Egghead

                    • Welcome to ComputerHope!
                    • Thanked: 44
                      Re: Opera Hijacked!!!
                      « Reply #9 on: April 07, 2006, 12:10:57 AM »
                      OK, the cfpsys.exe does look suspicious, but it's actually part of a password-protect program I downloaded. Info is here:

                      http://www.bleepingcomputer.com/startups/cfpsys.exe-14104.html

                      And removing the 017 things, I've found, causes issues with DynDNS updater. I've found this out by removing them, not being able to get online and getting errors from DynDNS, then restoring them and finding everything condition Green again...

                      The last one I fixed, but I'm going to bed. I'll post another one in the morning. (GMT-8 shows 11:10 PM. And it's a school night!)

                      So, G'night. :)
                      "The geek shall inherit the Earth."

                      dl65

                      • R.I.P.


                      • Prodigy

                        Thanked: 18
                        Re: Opera Hijacked!!!
                        « Reply #10 on: April 07, 2006, 01:38:34 AM »
                        Dilbert ......
                        Quote
                        017 ..... ALL of them UNLESS THEY ARE ASSOCIATED WITH YOUR ISP
                          ....... If they are from your ISP ...they are ok to stay ..... as stated .

                        Re ... cfpsys.exe ........ Yes I saw that as well , But I also saw a number of sites that were considering it an issue .......  The fact that you downloaded it confirms it .

                        dl65  ::)
                        If you don't know the answer, it isn't a dumb question.