GeekPolice
Welcome to GeekPolice.net!

GeekPolice is a website which provides free Computer Technical Support & Virus/Spyware Removal to our members.

You are currently viewing the forum as "Guest" which doesn't give you the same privilege as members to ask questions or post comments.

Click the Register button below to unlock the limitations of this website and start asking questions to discover new computer knowledge now!

browser hijack, not cleaned by MalwareBytes or Zone Alarm

Post new topic   Reply to topic

Page 2 of 2 Previous  1, 2

View previous topic View next topic Go down

browser hijack, not cleaned by MalwareBytes or Zone Alarm

Post by solr on Fri 03 Jul 2009, 9:35 am

First topic message reminder :

Running XP SP3, latest Java, Flash, all Windows Updates, IE8.
Browsing is hijacked to other sites psoting ads.

Scanned with latest MalwareBytes and Zone Alarm Security Suite, fully updated.

Attached is HijackThis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:44 AM, on 7/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = [You must be registered and logged in to see this link.]
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Task Manager.lnk = C:\WINDOWS\system32\taskmgr.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [You must be registered and logged in to see this link.]
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6044 bytes

solr

Newbie Surfer
Newbie Surfer

Posts: 11
Joined: 2009-07-03
Operating System: XP SP3

View user profile

Back to top Go down


Re: browser hijack, not cleaned by MalwareBytes or Zone Alarm

Post by Belahzur on Fri 03 Jul 2009, 1:38 pm

Hello.
Go inside this folder in bold:

c:\windows\Internet Logs

Delete everything inside the folder, but do not delete the folder itself.

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /u



This will also reset your restore points.

How is the machine running now?






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 26109
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Re: browser hijack, not cleaned by MalwareBytes or Zone Alarm

Post by solr on Fri 03 Jul 2009, 2:23 pm

Some of the files in Internet Logs belong to zone alarm, and are locked.

Machine seems to be running fine. I have been browsing around and not getting redirected.

Combofix updated itself, on the last run.

May I ask, where can I learn how to use Combofix and the other tools?

BTW, I donated $10 to geeekpolice.

Thanks!

solr

Newbie Surfer
Newbie Surfer

Posts: 11
Joined: 2009-07-03
Operating System: XP SP3

View user profile

Back to top Go down

Re: browser hijack, not cleaned by MalwareBytes or Zone Alarm

Post by Belahzur on Fri 03 Jul 2009, 2:40 pm

Hello.

These files
c:\windows\Internet Logs\xD***.tmp are created by Zone Alarm.
To stop the creation of these files execute this.

Open ZoneAlarm control.
Select Alerts and Logs on the left Pane.
Set Event Logging to Off.
Close ZoneAlarm control.

There are many online schools where they will teach you this stuff for free if you are serious about learning it. It can take a while to get your head around it if your not at a decent stage of computing already though.






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 26109
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Re: browser hijack, not cleaned by MalwareBytes or Zone Alarm

Post by solr on Fri 03 Jul 2009, 2:51 pm

I am fairly expert in Windows and the Registry, and know how to recover the Registry from the System Restore points, when system restore doesnt work. That works on XP, but Vista does not appear to allow you to do the same thing.

So I image all my drives using Norton Save and Restore or Acronis True Image.

I used to do C++ development, but gave up on that about 8 years ago.

What are the sites where I can learn to use these malware removal tools?

solr

Newbie Surfer
Newbie Surfer

Posts: 11
Joined: 2009-07-03
Operating System: XP SP3

View user profile

Back to top Go down

Re: browser hijack, not cleaned by MalwareBytes or Zone Alarm

Post by Belahzur on Fri 03 Jul 2009, 3:08 pm

As I said, there are many.
Two links of schools I recommend are:

[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]






From now on, I will no longer answer any requests for help via PM, please post in the forum.

If I have helped, please consider a [You must be registered and logged in to see this link.] to help keep us alive.

"Dark Saviour, he can save you"

Belahzur

Super Moderator | Tech Officer
Super Moderator | Tech Officer

Posts: 26109
Joined: 2008-08-03
Operating System: XP SP3 Media Centre

View user profile

Back to top Go down

Re: browser hijack, not cleaned by MalwareBytes or Zone Alarm

Post by solr on Fri 03 Jul 2009, 3:44 pm

Thanks,

I have great weekend.

solr

Newbie Surfer
Newbie Surfer

Posts: 11
Joined: 2009-07-03
Operating System: XP SP3

View user profile

Back to top Go down

Page 2 of 2 Previous  1, 2

View previous topic View next topic Back to top


Permissions of this forum:
You cannot reply to topics in this forum