Thread: keep getting hijacked
-
January 24th, 2011, 05:13 PM #1Junior Member
- Join Date
- Jan 2011
- Posts
- 4
keep getting hijacked
i know this has prob been posted about 100 times but i am not very computer savy. so i figured it post it up on here and hope for some help. about a month or so ago i started noticing that when ever i clicked on a search on google i would be redirected to another site once in a while. now its happening all the time and is driving me crazy. i got windows vista with micro security essentials. i downloaded this prog called hijack this but have no idea what to do with it. help me please.
-
January 24th, 2011, 05:22 PM #2
Use one of the hijack this analyzers and follow the tutorial posted in this thread HijackThis Analyzer & Tutorial
you may also want to paste a copy of the log here so we can see it.
I'd also suggest getting malwarebytes and/or ad-aware and running scans with both of those
TechIMO Folding@home Team #111 - Crunching for the cure!
“Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”
-
January 26th, 2011, 04:47 AM #3Junior Member
- Join Date
- Jan 2011
- Posts
- 4
sorry for the slow response. i ran malwarebytes and a few things showed up but i am still getting hijacked. i noticed that in my ms office email 2010 i keep getting this urlredirect dll that i delete but it keeps comming back no matter what i do. im not sure if that is what is causing this. all i know is if my firefox gets hijacked i close it and reopen it and it works fine for a bit. i also have it so it clears all the cookies upon exit.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:45:08 AM, on 1/26/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\WindowsMobile\wmdcBase.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin \IE\rpbrowserrecordplugin.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\s wg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MI1933~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MI1933~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: AutorunsDisabled - (no CLSID) - (no file)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: dlbk_device - - C:\Windows\system32\dlbkcoms.exe
O23 - Service: Google Update Service (gupdate1ca1579ff881793) (gupdate1ca1579ff881793) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\Windows\system32\wwSecure.exe
--
End of file - 6685 bytes
-
January 26th, 2011, 04:55 AM #4
Hi Jack...
Sorry, couldn't help it..
I've seen the light... It was green, flashy and attached to a Network Interface Card...Whenever someone says "You can't miss it", I invariably do...
-
January 26th, 2011, 07:14 AM #5
Your HJT log looks fine so can you provide any details as to what you are being redirected to?
TechIMO Folding@home Team #111 - Crunching for the cure!
“Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”
-
January 26th, 2011, 09:01 PM #6Junior Member
- Join Date
- Jan 2011
- Posts
- 4
as usual when i need to prove it it does not do it but i went back into my history on firefox and this is what i found when it redirected
these are just 2 of maybe 20. tazinga is the one i get sent to the most. maybe 4 out of 5 times. i click the back button and click the same link and it either sends me back to tazings or comes up saying "no search results" or "no results" in the upper top left of the pageCode:http://www.tazinga.com/directory/results_l/Tommy%20Chong%20Ndp?_session_id=f9d23d835e5084242f34d51b7f0a5f7c http://1a5bng.abctrck2.com/tracking202/redirect/cl2.php?q=http%3A%2F%2Fdailycontestwinner.com%2FCanada%2FWinner
Last edited by RicheemxX; January 26th, 2011 at 09:24 PM.
-
January 26th, 2011, 09:06 PM #7Junior Member
- Join Date
- Jan 2011
- Posts
- 4
i found this while doing some research
Tazinga redirect virus - how to remove
my mse antivirus does not find it and neither does malwarebytes
-
January 26th, 2011, 10:19 PM #8
general rule of thumb when dealing with these types of issues is to turn off system restore, boot to safe mode and run your scans from there. If malwarebytes doesn't work you might try the avira rescue cd or kaspersky rescue disk
TechIMO Folding@home Team #111 - Crunching for the cure!
“Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”
-
February 15th, 2011, 08:56 PM #9Junior Member
- Join Date
- Feb 2011
- Location
- Gulf Coast USA
- Posts
- 2
Redirect problem with Firefox
Smart move using Firefox! Did you add a redirect add on from Mozilla.com? There are several from this link... https://addons.mozilla.org/en-US/fir...vacy-security/
Hope this Helps! Can't be too careful in the "wild"!
N
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Hijacked! - Help!
By blanketboy in forum Technical SupportReplies: 12Last Post: April 18th, 2010, 10:09 AM -
HELP! Hijacked..?
By lessthnxero in forum Technical SupportReplies: 2Last Post: October 6th, 2008, 04:06 PM -
I think I've been hijacked
By jbtrahan85 in forum Security and Privacy IssuesReplies: 5Last Post: August 28th, 2008, 04:43 PM -
I been hijacked !
By relaxedman in forum Security and Privacy IssuesReplies: 7Last Post: March 27th, 2007, 12:58 AM



LinkBack URL
About LinkBacks



Reply With Quote


AMD has dropped to fourth in the microprocessor sales rankings due to demand for mobile device processors, with Qualcomm and Samsung substantially boosting their sales of ARM chips.
AMD Fourth in Microprocessor Sales