| Windows 7: browser hijack. |
12 Aug 2012
|
#1 | | Windows 7 Professional 32bit |
browser hijack. i have this issues   . every time i click on the Google search result URL it go to the other website  . i already try to use the Malwarebytes Anti-Malware, Rkill , and tdsskiller to scan and remove but it still there.
this is the website it direct me to--> (click dot expandsearchanswers dot com).
any solution for this??
Sorry for my bad english.
Last edited by Airbot; 12 Aug 2012 at 02:21 PM..
| My System Specs |
| OS Windows 7 Professional 32bit |
13 Aug 2012
|
#2 | | Windows 7 Home Premium 32 bit In a house with a cat trying to kill me |
Since none of the the tools you mentioned seemed to have any effect at removing the infection, try d/l ing & running Windows Offline Defender. This is a boot disk/USB scanner. Download this on a clean PC (not the infected one), follow the directions and post back what the results were. Windows Defender Offline | My System Specs | | System Manufacturer/Model Number Dell Hell oh Well OS Windows 7 Home Premium 32 bit CPU Intel Core 2 Duo 2.93GHz Memory Not much with my ADHD Graphics Card ATI Radeon HD 4350 Monitor(s) Displays I have one...It's bright. A 19 inch CRT actually. Keyboard It's 10 years old and amazingly still works Mouse Same deal with the mouse, 10 yrs old, if it ain't broke... Case Don't get on my case...man :D Cooling I have an Air Conditioner & Diet Pepsi Hard Drives 250 GB Main Drive, 2 - 1 TB Externals, various FD's. |
14 Aug 2012
|
#4 | | Windows 7 Ultimate SP1 (x64) South Australia |

Quote: Originally Posted by shawn77 Reinstall your browser.
Try the following please:
Copy the following text exactly as shown into a new instance of Notepad, and save it as flush.bat on your desktop. @Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0
Close any open applications. Right-click on flush.bat and choose to Run as Administrator. Your computer will reboot itself.
Now download TFC.exe (Temporary File Cleaner) to your desktop, from this location: TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums
Ensure all applications are closed. Right-click on TFC.exe and choose to Run as Administrator.
Click Start to run TFC - note: - do not interrupt it! Let it finish completely.
- if TFC prompts you to reboot, then do so immediately.
- once finished, if you were not prompted to reboot, reboot anyway
Once rebooted, perform an online scan using the ESET online scanner: ESET Online Virus Scanner | ESET
Report back on anything it finds.
Regards,
Golden | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate SP1 (x64) CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
3*Samsung F1 SpinPoint 1TB in RAID5;
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! Antivirus MSE and Malwarebytes Pro Browser Chrome Version 25 Other Info Laptop: ASUS X54C, Intel Core i3-2330M @ 2.0Ghz, 4GB RAM, Intel HD on-board graphics, Windows 7 Professional SP1 (x64), LinuxMint 14 (x64), PepperMint 3 (x86) |
15 Aug 2012
|
#5 | | Windows 7 Professional 32bit |

Quote: Originally Posted by Golden 
Quote: Originally Posted by shawn77 Reinstall your browser.
Try the following please:
Copy the following text exactly as shown into a new instance of Notepad, and save it as flush.bat on your desktop. @Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0
Close any open applications. Right-click on flush.bat and choose to Run as Administrator. Your computer will reboot itself.
Now download TFC.exe (Temporary File Cleaner) to your desktop, from this location: TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums
Ensure all applications are closed. Right-click on TFC.exe and choose to Run as Administrator.
Click Start to run TFC - note: - do not interrupt it! Let it finish completely.
- if TFC prompts you to reboot, then do so immediately.
- once finished, if you were not prompted to reboot, reboot anyway
Once rebooted, perform an online scan using the ESET online scanner: ESET Online Virus Scanner | ESET
Report back on anything it finds.
Regards,
Golden ok. will use your methods 1st.
now using the ESET scanning the file.
Last edited by 2PMHottest; 15 Aug 2012 at 07:04 AM..
| My System Specs | | OS Windows 7 Professional 32bit |
15 Aug 2012
|
#6 | | Windows 7 Professional 32bit |
another update. seems like only my first user in the google chrome have the problem. the second user seem to be not infected by the malware.
and when everytime i try to key in an word on the google search bar or the google chrome address bar. the google chrome will crush and shut down itself. | My System Specs | | OS Windows 7 Professional 32bit |
17 Aug 2012
|
#7 | | Windows 7 Professional 32bit |

Quote: Originally Posted by Golden 
Quote: Originally Posted by shawn77 Reinstall your browser.
Try the following please:
Copy the following text exactly as shown into a new instance of Notepad, and save it as flush.bat on your desktop. @Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0
Close any open applications. Right-click on flush.bat and choose to Run as Administrator. Your computer will reboot itself.
Now download TFC.exe (Temporary File Cleaner) to your desktop, from this location: TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums
Ensure all applications are closed. Right-click on TFC.exe and choose to Run as Administrator.
Click Start to run TFC - note: - do not interrupt it! Let it finish completely.
- if TFC prompts you to reboot, then do so immediately.
- once finished, if you were not prompted to reboot, reboot anyway
Once rebooted, perform an online scan using the ESET online scanner: ESET Online Virus Scanner | ESET
Report back on anything it finds.
Regards,
Golden i have try your methods. but the result is still the same. no luck. thank you for your help. | My System Specs | | OS Windows 7 Professional 32bit |
17 Aug 2012
|
#8 | | Windows 7 Home Premium 64 bit. SP-1 Northern Ohio |
Did you use Windows Defender Offline as per Borg post #2??
Two other things.
1. Removing it using Safe Mode.
2. Internet Options/Connection/Lan and make sure proxy is not checked.
I just went through something like this and many times a anti malware don't find it because it's not considered malware. It can also be a add on in your browser. Something like, (Price watcher, coupon saver) or the likes. Completely remove all browsers except I.E. Then set I.I. to default. Nothing added what so ever. If your okay you can add more browser of your choice. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home made Desktop OS Windows 7 Home Premium 64 bit. SP-1 CPU Intel i7-960-3.2 @ 4.25 Motherboard ASUS P6X58D-E Memory KINGSTON KHX2000C9, Hyper X,12 GIGS Graphics Card MSI/Nvidia/460GTX-Cyclone 1GD5/OC Monitor(s) Displays DYNEX 40 IN. Screen Resolution 1920-1080 or 1280-720 HDMI Keyboard M/S 3000 v 2.0 wireless Mouse M/S 5000 wireless PSU Corsair AX-850 Plus Gold Case Corsair 600T (Black) + side panel with 2 140 mm Noctua fans Cooling Corsair H50/2 Noctua NF-P12 (120 mm) Push/Pull- Hard Drives INTEL SSD 120GB-SER 510
Seagate 1TB SATA 600 7200 rpm Hard Drive Internet Speed 3.0 mb Antivirus Microsoft Security Eesentials Browser I.E. 10 default/Firefox Other Info LG BluRay-Read/Write
Sound system
KLipsch-THX
Asus Router RTN-12
2 Noctua 140 added on top of 600t case
Malwarebytes Anti Malware Professional
Windows 7 Firewall |
17 Aug 2012
|
#9 | | Windows 7 Ultimate SP1 (x64) South Australia |

Quote: Originally Posted by 2PMHottest i have try your methods. but the result is still the same. no luck. thank you for your help. I'm guessing you ran ESET? What did it find. Try post some more detail in your replies. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate SP1 (x64) CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
3*Samsung F1 SpinPoint 1TB in RAID5;
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! Antivirus MSE and Malwarebytes Pro Browser Chrome Version 25 Other Info Laptop: ASUS X54C, Intel Core i3-2330M @ 2.0Ghz, 4GB RAM, Intel HD on-board graphics, Windows 7 Professional SP1 (x64), LinuxMint 14 (x64), PepperMint 3 (x86) browser hijack. problems? All times are GMT -5. The time now is 07:08 PM. | |