Posts Topics Forums Images
Search videos from message boards Videos Search messages from microblogs Microblogs Search messages from imdb.com Imdb Search messages from yuku.com Yuku Search messages from lefora.com (free forums) Lefora
My account: Login | Sign Up
Loading... 

Thread: [Active] Browser hijacked

Started 1 month, 1 week ago by bobmc32
I recently inherited this machine from a household with an older teen, a tween, and a Mom that is so-so computer literate (as am I). I have found and removed numerous sypware, malware, and virii using AVG, Superantispyware, AdAware, and Spybot S&D. I haven't noticed any unusual behaviou but the browser title line reads Microsoft Interner Explorer provided by EZN. DDS (Ver_09-10-26.01) ...
Site: Windows BBS - Help and Support forum for Microsoft Windows. "A Wealth ofWindows Knowledge".  Windows BBS - Help and Support forum for Microsoft Windows.
Forum: Removing Spyware & Viruses  Removing Spyware & Viruses - forum profile
Total authors: 3 authors
Total thread posts: 23 posts
Thread activity: no new posts during last week
Domain info for: windowsbbs.com

Other posts in this thread:

Admin. replied 1 month, 1 week ago
Hi, Read this post as indicated at the top of this forum & follow the instructions.

bobmc32 replied 1 month, 1 week ago
Ok, took actions as instructed and edited my first post.

Admin. replied 1 month, 1 week ago
Thanks, please wait for a Malware Expert to look at you log, it may take a day or two.

broni replied 1 month, 1 week ago
Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop** Please, never rename Combofix unless instructed. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not ...

broni replied 1 month, 1 week ago
1. Please open Notepad Click Start , then Run Type notepad .exe in the Run Box. 2. Now copy/paste the entire content of the codebox below into the Notepad window: Code: File:: c:\windows\system32\167613B242.sys c:\docum ents and settings\Bob\Application Data\wklnhst.dat c:\windows\system32\246D192D99.sy s c:\windows\System32\drivers\Winks40.sys c:\...

bobmc32 replied 1 month, 1 week ago
ComboFix 09-11-03.01 - Bob 11/03/2009 22:46.1.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.576 [GMT -6:00] Running from: c:\documents and settings\Bob\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ...

bobmc32 replied 1 month ago
ComboFix 09-11-08.03 - Bob 11/08/2009 18:27.2.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.545 [GMT -6:00] Running from: c:\documents and settings\Bob\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Bob\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ...

broni replied 1 month ago
Uninstall Combofix : Go Start > Run Type in: combofix /u Note the space between the "combofix" and the "/u" Restart computer. Print these instructions out. NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe ***VERY IMPORTANT! Make sure, you update ...

bobmc32 replied 1 month ago
SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 11/08/2009 at 09:51 PM Application Version : 4.25.1014 Core Rules Database Version : 3724 Trace Rules Database Version: 2138 Scan type : Complete Scan Total Scan Time : 01:13:42 Memory items scanned : 227 Memory threats detected : 0 Registry items scanned : 5274 Registry ...

bobmc32 replied 1 month ago
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:10:25 PM, on 11/9/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\...

 

Top contributing authors

Name
Posts
bobmc32
12
user's latest post:
[Resolved] Browser hijacked -...
Published (2009-11-11 22:34:00)
Thanks Broni. Good to know that I finally got to the end of the tunnel as it felt as tho I was being led by the nose thru a maze but persistance and help from you paid off. I really appreciate you help and guidance. This computer that was just exorcised and I just inherited was victim of a 17 year old teenager who had no fear and no common sense in his browsing and not an inkling of internet safety.
broni
9
user's latest post:
[Resolved] Browser hijacked -...
Published (2009-11-11 22:34:00)
You're very welcome Enjoy
Admin.
2
user's latest post:
[Active] Browser hijacked
Published (2009-11-03 17:10:00)
Thanks, please wait for a Malware Expert to look at you log, it may take a day or two.

Related threads on "Windows BBS - Help and Support forum for Microsoft Windows. "A Wealth ofWindows Knowledge".":

Related threads on other sites:

Thread profile page for "[Active] Browser hijacked" on http://www.windowsbbs.com. This report page is a snippet summary view from a single thread "[Active] Browser hijacked", located on the Message Board at http://www.windowsbbs.com. This thread profile page shows the thread statistics for: Total Authors, Total Thread Posts, and Thread Activity