A friend of mine has had his browser seriously hijacked (BT Yahoo browser, plus latest Firefox (downloaded and installed today) and IE are ALL affected) and it keeps going to porn sites.
He's on XP Home, SP2. Norton anti-virus is up to date as are windows updates. Spybot S&D was installed last night and some things were deleted, but we followed the instructions in the thread mentioned below anyway.
I read post #2 on this thread - http://forums.spybot.info/showthread.php?t=288 - and will go through in order what was done.
Results of online virus scan -
Apologies for the xxxxxxxx stuff but his name is there and I'd rather not post it.
Part 2 says reboot PC into safe mode - this was done.
Part 3 was also done. Spybot S&D removed everything it found and the last test was clean.
If I add the Hijackthis log to this post it is too big so I will followup in a sec. It's not looking good to me so far, but I'm no expert, the worst I had was coolwebsearch many moons ago.
He's on XP Home, SP2. Norton anti-virus is up to date as are windows updates. Spybot S&D was installed last night and some things were deleted, but we followed the instructions in the thread mentioned below anyway.
I read post #2 on this thread - http://forums.spybot.info/showthread.php?t=288 - and will go through in order what was done.
Results of online virus scan -
Incident Status Location
Potentially unwanted tool:application/unspypc Not disinfected c:\windows\system32\filesafer23.exe
Adware:adware/secure32 Not disinfected c:\program files\secure32.html
Adware:adware/winprotect Not disinfected c:\windows\help\SPAlert.chm
Adware:adware/vog Not disinfected Windows Registry
Adware:adware/emediacodec Not disinfected Windows Registry
Dialer:dialer.cso Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E53458D2-5A83-4BD1-8DE2-EEEBE73BAB49}
Adware:adware/tubby Not disinfected Windows Registry
Dialer:dialer.py Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8522F9B3-38C5-4AA4-AE40-7401F1BBC851}
Potentially unwanted tool:application/funweb Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Spyware:spyware/new.net Not disinfected Windows Registry
Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Application Data\Mozilla\Firefox\Profiles\ezunvc3z.default\cookies.txt[.paycounter.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@247realmedia[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@adrevolver[2].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@adtech[2].txt
Spyware:Cookie/Adviva Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@adviva[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@atdmt[2].txt
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@bfast[2].txt
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@counter.hitslink[2].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@counter9.sextracker[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@doubleclick[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@fastclick[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@mediaplex[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@questionmarket[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@serving-sys[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@sextracker[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@stats1.reliablestats[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@tribalfusion[1].txt
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@www.systemdoctor[1].txt
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@z1.adserver[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\xxxxxxxx xxxxxxxx\Local Settings\Temp\Cookies\xxxxxxxx xxxxxxxx@zedo[2].txt
Spyware:Spyware/New.net Not disinfected C:\Program Files\filesubmit\calvinhobbesaniss.exe\NNWDAC638.EXE
Adware:Adware/WhenUSearch Not disinfected C:\Program Files\filesubmit\calvinhobbesaniss.exe\SetupInst.exe
Apologies for the xxxxxxxx stuff but his name is there and I'd rather not post it.
Part 2 says reboot PC into safe mode - this was done.
Part 3 was also done. Spybot S&D removed everything it found and the last test was clean.
If I add the Hijackthis log to this post it is too big so I will followup in a sec. It's not looking good to me so far, but I'm no expert, the worst I had was coolwebsearch many moons ago.