Click here for AnswerPool.com Home page


Google

    AnswerPool.com  Hop To Forum Categories  Computers  Hop To Forums  Security Issues    Common Hijacker won't go away

Moderators: Dwight
Go
Post
Find
Notify
Tools
Reply
  
  Login/Join 
Posted
Hi
I come here occasionally when I have computer difficulties and someone can normally help, I have a hijacker (homepage) the address is [URL=http://169.50.191.139/search.php ]The hijacker[/URL]it never changes, I have checked the link at the bottom of the search page for apparent removal and it seems to do nothing so I left it alone, I ran a couple of spyware removers and the X-cleaner. It dfetects it and then when I restart it is ALWAYS back! Is there any hope in getting rid of it permanently?
Thanks for any help you can offer
 
Posts: 88 | Location: Guelph,Ontario,Canada | Registered: 07-03-02Reply With QuoteEdit or Delete MessageReport This Post
Posted Hide Post
UPDATE

The URL changed
The Nasty

I would love any help I can get I need this gone, it goes so far as to give you directions for removal, which you cannot perform, and tells you to enjoy your PORN free computer and tells you to use pay porn sites not free ones, LOL about all I look at online is PARENTING websites, I can't figure this one out!
 
Posts: 88 | Location: Guelph,Ontario,Canada | Registered: 07-03-02Reply With QuoteEdit or Delete MessageReport This Post
Bronze
Enthusiast
Posted Hide Post
clear out your system using the programs below:

CWShredder- CoolWebShredder will help you remove the majority of Browser Hijackers (Browser Hijackers are a type of spyware that change your default home and search pages). Download CWShredder by clicking on the blue link to CWShredder writing above or click here. To let CWShredder begin the removal process, Run CWShredder and Click "Fix" and click "Ok" to any prompts you may get. CWShredder will now go through the removal process.

Spybot- Search And Destroy- Spybot S&D will remove the majority of spyware from your system. It is an excellent program with a large database of spyware. Download Spybot S&D by clicking Spybot- Search And Destroy in red writing above or click
here. Run the file you downloaded and install Spybot Search And Destroy. Once installed follow these instructions:

1. Go to Start>Programs>Spybot- Search and Destory and click Spybot- S&D
2. When the Program has loaded, you need to update its database first so in the left hand panel click Update. Then click Search For Updates at the top.
3. If any updates are found click Download Updates and allow Spybot to download the updates. If you have trouble updating change the mirror using the button next to Search For Updates.
4. Now you need to Scan with Spybot. Click Search And Destroy in the Left hand panel and then click Check For Problems at the top.
5. Spybot will begin scanning your system. When the scan is finished ensure that there is a checkmark next to all the problems and click "Fix Selected Problems" at the top. This will remove the Spyware from your system.

Ad-aware- Ad-aware is another program for detecting and removing spyware. It is important to have both Ad-aware and Spybot- S&D installed because if one misses a piece of spyware then it is likely the other will detect it. To download Ad-aware, click the link above or click here. Run the file you downloaded and install Ad-aware. Once installed follow these instructions:

1. Go to Start>Programs>Lavasoft Ad-aware 6 and click Ad-aware 6
2. When the Program has loaded, you need to update its database first so at the bottom click "Check For Updates" next to the Start button. Click Connect to check for updates. If Ad-aware detects any, it will confirm that you want to download it. Click Ok and it will download and install the update.
3. Click Finish when it has updated. Now we need to Scan and remove Spyware. Click Start at the bottom. Then click "Perform Smart System Scan" and then click Next.
4. Ad-aware will then scan your system for Spyware. When it has finished it will tell you how many objects it has found. Simply click Next and it will list everything it has found.
5. Put a checkmark next to all entries (or click one entry and click "Select All Objects"). Then click Next. Ad-aware will confirm that you want to remove the selected entries, simply click Ok and Ad-aware will remove the entries.

You should update and scan with these programs once a week




Preventing it returning

After your problem has been resolved on the forum, it is an absoulute MUST to do the following steps to prevent the problem returning. Click on the Blue Title to get access to the software or webpage that I'm referring to.

1. Visit Windows Update
Pay a visit to Windows Update and scan for and download ALL Critical Updates and Service Packs. New updates are usually released monthly so check back to Windows Update every month.

2. Download Antivirus Software-
If you haven't already got Antivirus software, you should download and install AVG Antivirus. It is freeware and is updated nearly every 2 days (sometimes more frequently if there are a lot of new viruses) and in my opinion, is better than some Antivirus software such as Norton. Antivirus software will prevent viruses infecting your system and it is important that you update it every two days or every week at the most.

3. Download a Firewall-
If you haven't already got a firewall, it is Very important that you download one. Firewalls will prevent unauthorised access to your computer and stop data leaking out of your computer. You may think that it won't happen to you, but Hackers don't care who you are, what you do, where you live or what you had for tea last Sunday on your holiday in the Lake District, they want your data. Firewalls will keep these sneaks out and one of the best is Sygate Personal Firewall, which happens to be freeware.

4. Prevent Spyware slipping through Internet Explorer-
Quite a lot of spyware slips through Internet Explorer if your settings are not tight enough. Spyware Blaster will help you prevent spyware slipping through and installing tracking cookies. Simply run it via Start> Programs> Spyware Blaster and click Enable All Protection and it will protect you. It doesn't even have to be open! Remember to update weekly/fortnightly.

5. Constant Spyware Protection-
It is important to have constant spyware protection. Spyware Guard works like an antivirus program but detects Spyware instead. It will constantly protect your system. Check for updates monthly.

All Of these steps are very important and it is HIGHLY recommended that you download all of the programs mentioned for your own safety. Remember to Update everything (including Windows using Windows Update)! It is also a good idea to perform weekly/fortnightly scans with Spybot S&D, Ad-aware and your antivirus software.

If all this fails, post a hijack this log

Hijack This can be downloaded from here and instructions for installing Hijack This and posting a log can be found at this page.

You may sometimes be asked to disable Disable System Restore

You may also be asked to change the way you view files by showing Hidden Files and Folders
 
Posts: 306 | Location: UK | Registered: 04-07-04Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
See if downloading and running this program Coolweb shredder will get rid off your computer if it finds a match? Cool
http://209.133.47.200/~merijn/files/CWShredder.exe
It KO's most of the Known Homepage Hijackers
and save it to run another day?
Only thing you have to do is reinstate your homepage address in Internet Explorer Options as It resets it to a Blank page OK?
If it still remains post again

Why not download Spywareblaster? This is very good at stopping these sorts of Probs starting in the first place Wink www.javacoolsoftware.com
 
Posts: 13330 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Posted Hide Post
Hi again
I have spybot search and destroy, AVG for windows, regularily go to symantec and scan , have cw shredder, have hijackthis....now most of these I just got today and I am in the process of rerunning everything and then going to reboot and see if it finally gone, I will be back with the details after my reboot!
And thans to you both!
 
Posts: 88 | Location: Guelph,Ontario,Canada | Registered: 07-03-02Reply With QuoteEdit or Delete MessageReport This Post
Posted Hide Post
Still there after running and rerunning everything and adding the site to restricted sites

I am gonna go insane, really I am, I have run everything I can run, I am going to post my scan results and see if you can tell me what I should delete.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://69.50.191.139/search.php
O2 - BHO: (no name) - {37A5FF76-9919-492C-98E3-EDA3502FC829} - c:\PROGRA~1\Oasis\oasis.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINNT\p_981116.exe /Q:A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winupd] C:\WINNT\System32\winupd.exe
O4 - HKLM\..\Run: [zuishazuexg] C:\WINNT\System32\xujapc.exe
O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [Oasis] regsvr32 /s "c:\Program Files\Oasis\oasis.dll"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt2_x.cab
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} (shizmoo Class) - http://www.uproar.com/applets/activex/shizmoo/flipside_web18.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} -
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\Acadm 6\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\Acadm 6\InstFred.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\Acadm 6\AcPreview.ocx
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

Any ideas? It always looks like it is gone then I restart and back again Frown
 
Posts: 88 | Location: Guelph,Ontario,Canada | Registered: 07-03-02Reply With QuoteEdit or Delete MessageReport This Post
Posted Hide Post
OK I see that it is in that list, I removed it, and restart et voila it's back again, it doesn't seem to be a CWS version as the CWS is saying my system is clean, HELP???? Eek
 
Posts: 88 | Location: Guelph,Ontario,Canada | Registered: 07-03-02Reply With QuoteEdit or Delete MessageReport This Post
Posted Hide Post
THIS IS RIDICULOUS

I have literally tried everything, I get it off and it somehow reinstalls, this

If you don't want to continue using this page, follow instruction below:
1. Download uninstaller (right click and choose "Save target as.." from pulldown menu

2. Run it

3. Reboot your PC

4. Run it second time

5. Change your start page to "about:blank" in the IE settings (Tools -> Internet Options)

6. Click "Start" -> "Run" -> regedit

7. Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

8. Select key {FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} and delete it

Enjoy with your clear PC.. and stop looking for free porn - try to buy membership on a good

Is what happens if you click on the link on the page that says PROBLEMS WITH PAGE: CLICK HERE

Pretty please, I am going on 4 hours trying to fix this now Mad
 
Posts: 88 | Location: Guelph,Ontario,Canada | Registered: 07-03-02Reply With QuoteEdit or Delete MessageReport This Post
Bronze
Enthusiast
Picture of Dixie
Posted Hide Post
This might not help at all, but have you tried pcpitstop? Go there and just test anonymously if you don't want to register. When test is finished, click on "view details." It is a free test. http://pcpitstop.com/
 
Posts: 314 | Location: Mobile, Alabama | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
Bronze
Enthusiast
Posted Hide Post
Close all windows

Restart Hijack this and put a check mark against the following

R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://69.50.191.139/search.php
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winupd] C:\WINNT\System32\winupd.exe
O4 - HKLM\..\Run: [zuishazuexg] C:\WINNT\System32\xujapc.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

Click Fix Checked

Restart your computer
Go to C:\WINNT\System32 delete the following

xujapc.exe
winupd.exe

post a fresh Hijack this log
 
Posts: 306 | Location: UK | Registered: 04-07-04Reply With QuoteEdit or Delete MessageReport This Post
Posted Hide Post
Thanks for all the help! I ended up reformatting my whole hard drive, however everything is gone and now I have all kinds of protection (everything you suggested I have).

Never again, YUCK!
 
Posts: 88 | Location: Guelph,Ontario,Canada | Registered: 07-03-02Reply With QuoteEdit or Delete MessageReport This Post
Gold
Enthusiast
Picture of soaringhorse
Posted Hide Post
I had a similar virus called Dialer that was really a hard one to remove, I did notice under the IE downloaded objects that there was an Active X control that I had to remove. Pretty sneaky little viruses from porn sites!
I do want to say the advice on this page about Spybot S&D, Adaware, the antivirus programs, and Spyware Blaster helps a lot.
 
Posts: 1031 | Location: Greater Cincinnati Area | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
 Previous Topic | Next Topic powered by eve community  
 

    AnswerPool.com  Hop To Forum Categories  Computers  Hop To Forums  Security Issues    Common Hijacker won't go away

© 2002-2008 AnswerPool.com



Visit DiscussionPool.com!