Solved Browser Hijacked

James7679

Lurking
Guru
VIP
Local time
10:40 AM
Messages
1,407
Location
Central Florida
Over the past few days I have been trying to resolve an issue with IE8 having been Hijacked. Most of the time when I use a search through Google or Bing, upon clicking one of the results I will get a random redirect. I have tried scanning with MSE, Malwarebytes, Onecare.live, and Spybot S&D. I have ran multiple scans at the most stringent levels on all programs, the results are always negative. There does'nt seem to be any other programs being affected due to this, but that does'nt mean it won't eventually happen. I have even searched regisrty settings for IE8 and can't seem to find an http redirect anywhere. Your help with this is greatly appreciated. Thank you.
 

My Computer

Computer Manufacturer/Model Number
Home Made
OS
Windows 7 Home Premium x64
CPU
Intel 2500k @4.5ghz 66deg max P95/IBT
Motherboard
Gigabyte Z68A-D3-B3
Memory
8 Gigs Patriot Viper 2 Extreme @1600
Graphics Card(s)
EVGA GTX 580 3 GIG 35degrees idle
Sound Card
Nvidia HD audio via HDMI to 7.1 Receiver
Monitor(s) Displays
32" Olevia hdtv
Screen Resolution
1080p
Hard Drives
64gig SSD(OS/Apps)
250gig (Files and Dox)
1tb (imaging and backup)
PSU
Corsair vx550w
Case
Thermaltake V3 black
Cooling
CM 212+(push n pull) 4 case fans
Keyboard
Logitech wireless Combo, G13
Mouse
G300
Internet Speed
40mps
Other Info
Two others up and running; C2D E5200/MSI G41M-P26/Corsair XMS3 8gb/GTS 250 1gb and C2D E8200/xFx 750sli/8gb Corsair Dominator/2x EVGA 550ti
Working on; i2600 Build...
HP DV6
@Work I use a Lenovo 5536B8U + Lenovo U300s
check your proxy server through IE and your Host file
 

My Computer

OS
7 Pro
Let's flush your DNS cache and restore MS's original Hosts file:

Copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop. Right click and run the batch file as Administrator. Your computer will shut down and restart itself.

Next, download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.
Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

Now, download DDS from one of these links:
Mirror 1 Mirror 2 Mirror 3
  • Disable any script blocking protection
  • Double click the dds icon to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt <--will be minimized in the task tray
  • Save both reports to your desktop.
Include the contents of both logs in your new topic.
The scan will instruct you to post Attach.txt as an attachment.
No need for that though ..... just post it's contents as you would any other log.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

My Computer

Computer Manufacturer/Model Number
Home Made
OS
Windows 7 Home Premium x64
CPU
Intel 2500k @4.5ghz 66deg max P95/IBT
Motherboard
Gigabyte Z68A-D3-B3
Memory
8 Gigs Patriot Viper 2 Extreme @1600
Graphics Card(s)
EVGA GTX 580 3 GIG 35degrees idle
Sound Card
Nvidia HD audio via HDMI to 7.1 Receiver
Monitor(s) Displays
32" Olevia hdtv
Screen Resolution
1080p
Hard Drives
64gig SSD(OS/Apps)
250gig (Files and Dox)
1tb (imaging and backup)
PSU
Corsair vx550w
Case
Thermaltake V3 black
Cooling
CM 212+(push n pull) 4 case fans
Keyboard
Logitech wireless Combo, G13
Mouse
G300
Internet Speed
40mps
Other Info
Two others up and running; C2D E5200/MSI G41M-P26/Corsair XMS3 8gb/GTS 250 1gb and C2D E8200/xFx 750sli/8gb Corsair Dominator/2x EVGA 550ti
Working on; i2600 Build...
HP DV6
@Work I use a Lenovo 5536B8U + Lenovo U300s
Yes, go ahead and follow my instructions please.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Thanks Jacee, here you are...
 

Attachments

My Computer

Computer Manufacturer/Model Number
Home Made
OS
Windows 7 Home Premium x64
CPU
Intel 2500k @4.5ghz 66deg max P95/IBT
Motherboard
Gigabyte Z68A-D3-B3
Memory
8 Gigs Patriot Viper 2 Extreme @1600
Graphics Card(s)
EVGA GTX 580 3 GIG 35degrees idle
Sound Card
Nvidia HD audio via HDMI to 7.1 Receiver
Monitor(s) Displays
32" Olevia hdtv
Screen Resolution
1080p
Hard Drives
64gig SSD(OS/Apps)
250gig (Files and Dox)
1tb (imaging and backup)
PSU
Corsair vx550w
Case
Thermaltake V3 black
Cooling
CM 212+(push n pull) 4 case fans
Keyboard
Logitech wireless Combo, G13
Mouse
G300
Internet Speed
40mps
Other Info
Two others up and running; C2D E5200/MSI G41M-P26/Corsair XMS3 8gb/GTS 250 1gb and C2D E8200/xFx 750sli/8gb Corsair Dominator/2x EVGA 550ti
Working on; i2600 Build...
HP DV6
@Work I use a Lenovo 5536B8U + Lenovo U300s
TrojanDownloader:Win32/Renos.LX ... did you get fake Windows Security Essentials pop ups?

Please upload this file: F:\Users\James\AppData\Roaming\inst.exe
to VirSCAN.org - Free Multi-Engine Online Virus Scanner v1.02, Supports 36 AntiVirus Engines! and scan.

See this inst.exe | ThreatExpert statistics

Next, I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
TrojanDownloader:Win32/Renos.LX ... did you get fake Windows Security Essentials pop ups?

Please upload this file: F:\Users\James\AppData\Roaming\inst.exe
to VirSCAN.org - Free Multi-Engine Online Virus Scanner v1.02, Supports 36 AntiVirus Engines! and scan.
Jacee, no to fake MSE pups, and I can't find the above mentioned file on my pc. I take that back, after researching what the "renos.lx" file was, i realized that I had seen this. I immediately restarted my computer in safe mode and ran MSE scan and M'Bytes scan with no results.
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Home Made
OS
Windows 7 Home Premium x64
CPU
Intel 2500k @4.5ghz 66deg max P95/IBT
Motherboard
Gigabyte Z68A-D3-B3
Memory
8 Gigs Patriot Viper 2 Extreme @1600
Graphics Card(s)
EVGA GTX 580 3 GIG 35degrees idle
Sound Card
Nvidia HD audio via HDMI to 7.1 Receiver
Monitor(s) Displays
32" Olevia hdtv
Screen Resolution
1080p
Hard Drives
64gig SSD(OS/Apps)
250gig (Files and Dox)
1tb (imaging and backup)
PSU
Corsair vx550w
Case
Thermaltake V3 black
Cooling
CM 212+(push n pull) 4 case fans
Keyboard
Logitech wireless Combo, G13
Mouse
G300
Internet Speed
40mps
Other Info
Two others up and running; C2D E5200/MSI G41M-P26/Corsair XMS3 8gb/GTS 250 1gb and C2D E8200/xFx 750sli/8gb Corsair Dominator/2x EVGA 550ti
Working on; i2600 Build...
HP DV6
@Work I use a Lenovo 5536B8U + Lenovo U300s
Unhide hidden files and folders to find F:\Users\James\AppData\Roaming\inst.exe

Go into Control panel, click folder options, then click the 'view' tab. Now uncheck Don't show hidden files and folders and hide extensions for known file types
You should be able to find the file after doing the above..
 

Attachments

  • hidden files.jpg
    hidden files.jpg
    13 KB · Views: 1,154

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Can you post the log from Eset online scanner, please ... along with the saved text from VirScan :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
The File you wanted me to check was clean. ESET came back negative. I ran SAS and it removed 11 tracking cookies. Sorry it took so long for me to get back to you. Thank you so much for your help.
 

My Computer

Computer Manufacturer/Model Number
Home Made
OS
Windows 7 Home Premium x64
CPU
Intel 2500k @4.5ghz 66deg max P95/IBT
Motherboard
Gigabyte Z68A-D3-B3
Memory
8 Gigs Patriot Viper 2 Extreme @1600
Graphics Card(s)
EVGA GTX 580 3 GIG 35degrees idle
Sound Card
Nvidia HD audio via HDMI to 7.1 Receiver
Monitor(s) Displays
32" Olevia hdtv
Screen Resolution
1080p
Hard Drives
64gig SSD(OS/Apps)
250gig (Files and Dox)
1tb (imaging and backup)
PSU
Corsair vx550w
Case
Thermaltake V3 black
Cooling
CM 212+(push n pull) 4 case fans
Keyboard
Logitech wireless Combo, G13
Mouse
G300
Internet Speed
40mps
Other Info
Two others up and running; C2D E5200/MSI G41M-P26/Corsair XMS3 8gb/GTS 250 1gb and C2D E8200/xFx 750sli/8gb Corsair Dominator/2x EVGA 550ti
Working on; i2600 Build...
HP DV6
@Work I use a Lenovo 5536B8U + Lenovo U300s
You're welcome. :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Apparently
shrug.gif
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Fixed....

Yes, the problem is no longer. Thank you for your help.
 

My Computer

Computer Manufacturer/Model Number
Home Made
OS
Windows 7 Home Premium x64
CPU
Intel 2500k @4.5ghz 66deg max P95/IBT
Motherboard
Gigabyte Z68A-D3-B3
Memory
8 Gigs Patriot Viper 2 Extreme @1600
Graphics Card(s)
EVGA GTX 580 3 GIG 35degrees idle
Sound Card
Nvidia HD audio via HDMI to 7.1 Receiver
Monitor(s) Displays
32" Olevia hdtv
Screen Resolution
1080p
Hard Drives
64gig SSD(OS/Apps)
250gig (Files and Dox)
1tb (imaging and backup)
PSU
Corsair vx550w
Case
Thermaltake V3 black
Cooling
CM 212+(push n pull) 4 case fans
Keyboard
Logitech wireless Combo, G13
Mouse
G300
Internet Speed
40mps
Other Info
Two others up and running; C2D E5200/MSI G41M-P26/Corsair XMS3 8gb/GTS 250 1gb and C2D E8200/xFx 750sli/8gb Corsair Dominator/2x EVGA 550ti
Working on; i2600 Build...
HP DV6
@Work I use a Lenovo 5536B8U + Lenovo U300s
I had a similar problem but rarely would I get redirects, mostly the browser would just refuse to open the link to the sites i searched for. I just did system restore and all is well. Before that virus scans from AVG and Malwarebytes were negative but spybot told me some of my regestry entries were changed but the list seemed to go on forever and I got tired of clicking so i just restored the computer to an earlier point.

crossing fingers
 

My Computer

Computer Manufacturer/Model Number
HP Z400 Workstation , Acer Aspire E700
OS
32bit(Windows 7 & Ubuntu 10.10 , Windows 7 & Windows XP)
CPU
2.8GHz Intel Xeon W3530 , 2.40GHz Intel Core2 Quad
Motherboard
Acer FG965M, HP 0B4C D
Memory
3GB EEC , 4 GB
Graphics Card(s)
NVIDIA QuadroFX 380 , Radeon X1650
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
HP 2009m x2
Screen Resolution
1600x900
Hard Drives
HDS728080PLA380 [Hard drive] (82.35 GB) -- drive 1, s/n PFDB20S5T56VTJ, rev PF2OA60A, SMART Status: Healthy

SAMSUNG HD160JJ/P [Hard drive] (160.00 GB) -- drive 3, s/n S0DFJ1NLB53172, rev ZM100-34, SMART Status: Healthy

ST3500320AS [Hard drive]
Case
IBM EServer XSeries 205
Back
Top