+ Reply to Thread
Results 1 to 9 of 9
  1. #1
    Junior Member
    Join Date
    Jan 2011
    Posts
    4

    keep getting hijacked

     
    i know this has prob been posted about 100 times but i am not very computer savy. so i figured it post it up on here and hope for some help. about a month or so ago i started noticing that when ever i clicked on a search on google i would be redirected to another site once in a while. now its happening all the time and is driving me crazy. i got windows vista with micro security essentials. i downloaded this prog called hijack this but have no idea what to do with it. help me please.

  2. #2
    Super Stealthy Moderator RicheemxX's Avatar
    Join Date
    Jan 2003
    Location
    Outside the box
    Posts
    8,489
    Blog Entries
    4
    Use one of the hijack this analyzers and follow the tutorial posted in this thread HijackThis Analyzer & Tutorial

    you may also want to paste a copy of the log here so we can see it.

    I'd also suggest getting malwarebytes and/or ad-aware and running scans with both of those

    TechIMO Folding@home Team #111 - Crunching for the cure!
    “Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”

  3. #3
    Junior Member
    Join Date
    Jan 2011
    Posts
    4
    sorry for the slow response. i ran malwarebytes and a few things showed up but i am still getting hijacked. i noticed that in my ms office email 2010 i keep getting this urlredirect dll that i delete but it keeps comming back no matter what i do. im not sure if that is what is causing this. all i know is if my firefox gets hijacked i close it and reopen it and it works fine for a bit. i also have it so it clears all the cookies upon exit.

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 12:45:08 AM, on 1/26/2011
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18999)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\WindowsMobile\wmdcBase.exe
    C:\Program Files\Microsoft Security Client\msseces.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
    C:\Windows\system32\DllHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin \IE\rpbrowserrecordplugin.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\s wg.dll
    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MI1933~1\Office14\URLREDIR.DLL
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office14\EXCEL.EXE/3000
    O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MI1933~1\Office14\ONBttnIE.dll/105
    O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
    O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O18 - Filter: AutorunsDisabled - (no CLSID) - (no file)
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
    O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
    O23 - Service: dlbk_device - - C:\Windows\system32\dlbkcoms.exe
    O23 - Service: Google Update Service (gupdate1ca1579ff881793) (gupdate1ca1579ff881793) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\Windows\system32\wwSecure.exe

    --
    End of file - 6685 bytes

  4. #4
    [He who is Nude..] Nude_Lewd_Man's Avatar
    Join Date
    Mar 2007
    Location
    My own little world.
    Posts
    11,764
    Hi Jack...


    Sorry, couldn't help it..
    I've seen the light... It was green, flashy and attached to a Network Interface Card...
    Whenever someone says "You can't miss it", I invariably do...

    TechIMO Folding@home Team #111 - Crunching for the cure!IE Team111 FAQs TEAM STATS Apps

  5. #5
    Super Stealthy Moderator RicheemxX's Avatar
    Join Date
    Jan 2003
    Location
    Outside the box
    Posts
    8,489
    Blog Entries
    4
    Your HJT log looks fine so can you provide any details as to what you are being redirected to?

    TechIMO Folding@home Team #111 - Crunching for the cure!
    “Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”

  6. #6
    Junior Member
    Join Date
    Jan 2011
    Posts
    4
    as usual when i need to prove it it does not do it but i went back into my history on firefox and this is what i found when it redirected

    Code:
    http://www.tazinga.com/directory/results_l/Tommy%20Chong%20Ndp?_session_id=f9d23d835e5084242f34d51b7f0a5f7c
    
    http://1a5bng.abctrck2.com/tracking202/redirect/cl2.php?q=http%3A%2F%2Fdailycontestwinner.com%2FCanada%2FWinner
    these are just 2 of maybe 20. tazinga is the one i get sent to the most. maybe 4 out of 5 times. i click the back button and click the same link and it either sends me back to tazings or comes up saying "no search results" or "no results" in the upper top left of the page
    Last edited by RicheemxX; January 26th, 2011 at 09:24 PM.

  7. #7
    Junior Member
    Join Date
    Jan 2011
    Posts
    4
    i found this while doing some research
    Tazinga redirect virus - how to remove
    my mse antivirus does not find it and neither does malwarebytes

  8. #8
    Super Stealthy Moderator RicheemxX's Avatar
    Join Date
    Jan 2003
    Location
    Outside the box
    Posts
    8,489
    Blog Entries
    4
    general rule of thumb when dealing with these types of issues is to turn off system restore, boot to safe mode and run your scans from there. If malwarebytes doesn't work you might try the avira rescue cd or kaspersky rescue disk

    TechIMO Folding@home Team #111 - Crunching for the cure!
    “Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”

  9. #9
    Junior Member
    Join Date
    Feb 2011
    Location
    Gulf Coast USA
    Posts
    2

    Question Redirect problem with Firefox

    Smart move using Firefox! Did you add a redirect add on from Mozilla.com? There are several from this link... https://addons.mozilla.org/en-US/fir...vacy-security/

    Hope this Helps! Can't be too careful in the "wild"!
    N

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Hijacked! - Help!
    By blanketboy in forum Technical Support
    Replies: 12
    Last Post: April 18th, 2010, 10:09 AM
  2. HELP! Hijacked..?
    By lessthnxero in forum Technical Support
    Replies: 2
    Last Post: October 6th, 2008, 04:06 PM
  3. I think I've been hijacked
    By jbtrahan85 in forum Security and Privacy Issues
    Replies: 5
    Last Post: August 28th, 2008, 04:43 PM
  4. I been hijacked !
    By relaxedman in forum Security and Privacy Issues
    Replies: 7
    Last Post: March 27th, 2007, 12:58 AM

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Recommended Sites: ResellerRatings Store Reviews