Error » Microsoft Error! » Microsoft Operating Systems Error » Microsoft Windows xp error » windows IE hacked

Microsoft Windows xp error all errors and bugs related to Microsoft winxp error

Post New Thread Reply
  windows IE hacked
LinkBack Thread Tools Display Modes
Old 08-Feb-2007, 12:50 AM   #1 (permalink)
Administrator
 
Anilrgowda's Avatar

Posts: 18,715
Join Date: Jan 2006
Rep Power: 10 Anilrgowda is on a distinguished road

IM:
Default windows IE hacked

hi guys
My system has been hacked. I just clicked on a link in my email and thats it, all kinds of pop ups started showing up.
my home page automatically changed to some stupid page and when i right click on internet explorer to set the home page back
i see the "Home page" section is disabled.

any idea how i can get rid of this popup and set the home page back.

I am using windows 2000.

any help greatly appreciated as this is really frustrating!

Soln
aggernat, they're variants of SDBot and IRCBots, the entries that you removed before are possibly no longer showing in this log, if they are not showing can you tell us what they were? hijackthis creates a backup of all the entries that were fixed(backup is where your hijackthis.exe was, right now your hijackthis is in the temp folder(it's good to put it in its own folder so it's not accidentally deleted)


Anyway try this:
1. Please download The Avenger by Swandog46 to your Desktop.
http://swandog46.geekstogo.com/avenger.zip

*Click on Avenger.zip to open the file
*Extract avenger.exe to your desktop

Start up Avenger.
Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens, copy, then paste the following text(all text/characters between the lines below):

-----------------------------------------------------------------------------------------------------------
Files to delete:
C:\DOCUME~1\Jay\LOCALS~1\Temp\IEXPLORE.EXE
C:\WINNT\system\svchost32.exe
C:\WINNT\system\svhost.exe

Registry values to delete:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | SVCHOST
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | Task Manager
------------------------------------------------------------------------------------------------------------

Then click on 'Done'.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.


2. For any leftovers IRCBots,
Download SDFix and save it to your desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.zip
Please then reboot your computer in Safe Mode by doing the following:[*]Restart your computer[*]After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;[*]Instead of Windows loading as normal, a menu with options should appear;[*]Select the first option, to run Windows in Safe Mode, then press "Enter".[*]Choose your usual account.[*] In Safe Mode, right click the SDFix.zip folder and choose "Extract All", [*] Open the extracted folder and double click "RunThis.bat" to start the script. [*] Type "Y" to begin the script.[*] It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot. [*] Press any Key and it will restart the PC. [*] Your system will take longer that normal to restart as the fixtool will be running and removing files. [*] When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.[*] Finally open the SDFix folder on your desktop and copy and paste the contents of the results file "Report.txt" back


Fix these entries in Hijackthis:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Zango/ie/bridge-c8.cab?9b91da394bb089c426c4c8fcb2032040a0984db8cca d09aad24d7ebc200f0941a5b810e6eae0e4827334f18e89543 4b50ff31e0c2b0e8f858ddc2e736e:e3eb4becbb5c1ba39dd0 84361d36488e



Afterwards, can we look at a fresh hijackthis log?
Anilrgowda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 05:44 PM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228