PDA

View Full Version : Has my internet connection/browsers been hijacked?



helms
2006-09-22, 20:38
http://img217.imageshack.us/img217/2593/screenhunter002us3.th.jpg (http://img217.imageshack.us/my.php?image=screenhunter002us3.jpg)
http://img217.imageshack.us/img217/2593/screenhunter002us3.jpg

This even happens with google

helms
2006-09-22, 21:17
http://img217.imageshack.us/img217/2593/screenhunter002us3.th.jpg (http://img217.imageshack.us/my.php?image=screenhunter002us3.jpg)
http://img217.imageshack.us/img217/2593/screenhunter002us3.jpg

This even happens with google
http://img479.imageshack.us/img479/3871/screenhunter1fd0.th.jpg (http://img479.imageshack.us/my.php?image=screenhunter1fd0.jpg)
http://img479.imageshack.us/img479/3871/screenhunter1fd0.jpg
It appears I really have been hijacked

Spybots doesnt work on my computer it stops at win32.sober, I dont think it stops just takes too long to scan it, maybe because i have a lot of avi files.
When i use adaware, avg and antivir nothing shows up

This is wat happens when i use ewido
http://img479.imageshack.us/img479/8783/screenhunter4dh3.th.jpg (http://img479.imageshack.us/my.php?image=screenhunter4dh3.jpg)
http://img479.imageshack.us/img479/8783/screenhunter4dh3.jpg

finally I cant ewido in safe mode because i have an old mouse the mouse doesnt work.

I dont really want to use hijack this unless i really have to.

Zenobia
2006-09-22, 22:29
I dont really want to use hijack this unless i really have to.

To be perfectly honest,where there was an error quarantining Downloader.Agent.uj,I kind of think the easiest way for you would be to get help in the malware removal section of this forum,which would involve you using Hijackthis.(but you'll have help from a helper)

If you decided to do that,there are instructions here:
http://forums.spybot.info/showthread.php?t=288
Of course,since you have trouble when booting into safe mode,and also running a Spybot scan all the way through,I think you'd be allowed to skip that part.

Here's malware removal:
http://forums.spybot.info/forumdisplay.php?f=22

helms
2006-09-23, 12:13
Thnx for the reply, it fixed spybots problem with stopping at win32.sober, I was able to run a spybots scan in safe mode without using the mouse. After the safe mode scan, The problem when scanning in normal mode was fixed. Unfortunately spybot didnt detect the browser redirect hijacker but it fixed some other things.

I was put off with using hijack this because looking at other ppls logs it seemed complicated, but now i used it I realize its nearly the same as the spybots startup list under tools. Well I posted my log in the malware removal forum, hope there is something wrong with it that can be fixed.

Zenobia
2006-09-24, 01:17
Good,glad you posted your log in Malware Removal. :) Good luck. :bigthumb:

helms
2006-09-24, 07:00
Well for some reason the browser redirect hijack stopped happening. Is it possible that my hijack this log is actually clean?

Are these possible reason for getting the redirect hijack?
-my internet service provider is the one having the problems with a hijack
-my internet service provider is like Earthlink
-something to do with my host file but it looks clean when I open it with wordpad and displayed in hijack this.

Why did it stop happening????

********i was wrong its still happening just not as severe eg google works again********

tashi
2006-09-24, 07:17
Hello helms

Bearing in mind that the forum is busy and it is also a weekend, a helper will assist you as soon as available. :)

http://forums.spybot.info/showthread.php?p=43656#post43656
Please don't analyse or fix items the log shows before someone helps you, our helpers are trained and do not need log items pointed out. ;)

Your log does show three anti virus programs.

Rule of thumb is one Firewall/AV to avoid conflicts and loss of program efficiency.

tashi
2006-09-24, 16:27
I moved your two new posts and merged them with your topic here:
http://forums.spybot.info/showthread.php?p=43701#post43701

As you are being helped in Malware removal please direct any further information to the topic there.

Thank you.