IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
I have been hijacked..can't do a hjt or cwshredder. mature porn pics in favorites can't delete. I have been to all different download sites. keeps redirecting back to search page.I also did a system restore. Please help.
Hi, Then you must try downloading HJThis to a floppy disk and installing it that way on your computer....you can also copy the logfile from HJthis to a disk so you can post it here, that way we can help you. It takes a bit longer to fix things, but it has been done before and will work- it helps if the good computer you use to work with the forum, download etc, is right there with you.
You can also download SpyBot Search and Destroy, AdAware 6.0, CWShredder, or any of the tools used to remove malwares on another computer and burn the downloads/installs for them onto a CD and install them on your computer. You will not have the updates though...unless you download them manually, also burn them to the same CD, and then manually place them in the correct folder for each program.
when I go hijackthis page or cws, I try to download and it redirects me to a search page. If I try to get weather for a city it redirects me to the search page. We have 3 users with passwords on this computer. I was able to do hjt on one of the user accounts. I am going to try CWS. be right back. here is hjt.
Logfile of HijackThis v1.97.7
Scan saved at 10:58:51 AM, on 4/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
The only thing on that HijackThis log you should fix is:
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
Also move the HijackThis and CWShredder programs into a directory that is accessible to the other users. THey should be able to run it from there. Remember that these programs need to be run for each user as a lot of hijackers/spyware launch themselves from the Current User section of the registry in which each individual user has their own.
I was able to get CWS & hjt. CWS removed 9 infected IE reg values. Here is my hjt.
Logfile of HijackThis v1.97.7
Scan saved at 11:19:58 AM, on 4/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Logfile of HijackThis v1.97.7
Scan saved at 11:30:27 AM, on 4/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
I was using AVG but had to uninstall because it would not work properly. I run S&D, ADaware6 at least 3 times a week on all three user accounts. I have wincleaner installed. I just installed spyblaster.
Below looks suspcious and can not find any reference. If you do not know what it is, fix it
O4 - HKCU\..\RunServices: [Runtime Process] C:\WINDOWS\sysdlrv.exe
Reboot and delete the following:
C:\Program Files\DR_S
C:\WINDOWS\System32\wnscpcc.exe
C:\WINDOWS\sysdlrv.exe (if you chose to delete above)
I have never seen two of these files. So can you please email me both the DR_S.exe and the sysdlrv.exe files so that I can inspect and identify them to [email protected]. Thanks.
If you Internet Explorer you should definitely install IE-spyad. WIll make it so your computer can not reach thousands of known malicious sites.
I was not able to send files. Windows said they may been an email attchment descrambled wrong or something to that effect. They were corrupted. I deleted what was left. Everything seems to be back to normal.,except when I open Yahoo, I have to refresh page to get content. Any advice? Thank you so much for all the help.
yahoo opens, but it is blank, I hit refresh & it appears.
ogfile of HijackThis v1.97.7
Scan saved at 1:48:29 PM, on 4/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
You can get rid of below if you want as it uses resources
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
Hi Grinler.....if I remove 04-Global startup..will I lose spell check in outlook express?
Also, Yahoo still won't load without hitting refresh any suggestions?
Thank you so much for all your help.
I do not believe OSA is responsible for spellchecker. At least I have never had that problem.
OSA.exe is the Microsoft Office Startup Assistant that is loaded at start-up and improves performance by handling automation, Office fonts, certain Office commands, and Outlook notification
THe yahoo part sounds strange. Are you having this behaviour anywhere else?
No, just yahoo. I thought maybe I had a bad shortcut, so I deleted short cut. went to yahoo thru mamma,,it loaded so I created a new shortcut...but it still doesn't work.
A forum community dedicated to tech experts and enthusiasts. Come join the discussion about articles, computer security, Mac, Microsoft, Linux, hardware, networking, gaming, reviews, accessories, and more!