ZeroPaid.com

  (#1) Old
net_exodus78 Offline
Registered User
net_exodus78 Reputation is 0
 
net_exodus78's Avatar
 
Posts: 2
Join Date: Dec 2003
Location: Canada
Age: 21
Reputation Power: 0
Angry Totally shocked - May 5th, 2004, 07:11 PM

I've recently contracted a spyware on my winxp computer. It hijacked my IE home page and set the home page to something like http://fadfg.outhost.info
it didn't work when i tried to restore my browser settings. I googled the URL and found that it didn't exist, so i suspect the page was cached on my computer.
I have no idea how it got into my computer, because i have zone alarm, norton antivirus 2004, and i run ad-aware scans every so often. I made 10 complete scans with up-to-date ad-aware and found no problem. my browser was still hijacked.

What shocked me was the detail the programmer went into, to prevent me from removing the spyware.

Firstly, it simply closes my browser if i visit any sites containing words such as "spyware", "spybot" etc. It closes my Opera browser too. I had to use my other operating system on the computer just to come into this forum.

Secondly, since i couldn't visit the spybot homepage i went on download.com to try and download it. My fast clicking skills actually let me download the file before the browser closed, however when the file reachs 100% and starts to transfer from the temp folder to the designated folder, windows gives me an error saying the file is not found. I tried using the open file option when downloading and it doesn't opens. Frustrated, i used my other computer to download hijackthis and try to unhijack the browser. i saved hijackthis on a floppy and put it into the infected computer. the spyware prevented me from seeing the file in windows explorer. So i went to start->run A:\hijackthis.exe, and it closed the .exe the second it opened.
Then i went into safe mode, and actually got hijackthis to work, but it didn't fix anything, my browser was still hijacked when i restarted in normal mode.

I went and downloaded spy sweeper and scanned my system twice, it found nothing.

I then went into a different OS, win2k, and downloaded spybot and installed it on win2k and scanned my system, found no problem. I had to rename the spybot setup file in order to see it in XP. I switched back to XP, ran the setup file, as usual it closed. I tried it in safe mode, i actually got it to install but after install finishes i cannot find spybot anywhere. Not on the desktop, not in the start menu, not in program files and not even in the registry.

I tried using malwhere, in normal mode, it detected a process called zlclient.exe or dll i don't remember. It was the only suspicious process on the list. I could not end it, it gave me an access denied message.

In safemode, the zlclient process didn't exist but i still couldn't get spybot to work. Looks like who ever made this spyware took every measure to prevent me from using spybot.
I gave up after spending my entire day trying to get rid of it. I am still looking for a solution to my problem, i would be grateful if anyone would give me suggestions or advice on removing this dreaded spyware.

I am absolutely shocked and disgusted that someone would spend so much time on the details to make my life miserable.
  Send a message via MSN to net_exodus78  
Reply With Quote
  (#2) Old
shawners Offline
Hurt no more my son.
shawners Reputation is 2000shawners Reputation is 2000shawners Reputation is 2000shawners Reputation is 2000shawners Reputation is 2000shawners Reputation is 2000shawners Reputation is 2000shawners Reputation is 2000shawners Reputation is 2000shawners Reputation is 2000shawners Reputation is 2000
 
shawners's Avatar
 
Posts: 8,056
Join Date: Dec 2002
Location: An angel in Heaven and on Earth
Age: 34
Reputation Power: 583
May 5th, 2004, 07:28 PM

im wondering if you cant use the browser on the other computer to find what kind of hijack this is.. and do a registry edit and delete them.. Can you return to an earlier time on your machine? before all this happend? Sounds alot more then just your friendly Micro hijacker.
  Send a message via Yahoo to shawners  
Reply With Quote
  (#3) Old
fireforce555 Offline
We Are Penn State!
fireforce555 Reputation is 0
 
fireforce555's Avatar
 
Posts: 363
Join Date: Nov 2003
Reputation Power: 92
May 5th, 2004, 07:47 PM

You can just edit your registry to reroute the start page away from its current one.
   
Reply With Quote
  (#4) Old
chuckv64 Offline
Zeropaid Regular
chuckv64 Reputation is 0
 
Posts: 19
Join Date: Apr 2002
Reputation Power: 0
May 5th, 2004, 10:17 PM

The zlclient is not your problem. That is just your zone alarm running. Wish I could help you but I have never had a hijacker cause that much trouble. Good luck.
   
Reply With Quote
  (#5) Old
tackdaddy Offline
ZeroPaid's Forum Pimp
tackdaddy Reputation is 2000tackdaddy Reputation is 2000tackdaddy Reputation is 2000tackdaddy Reputation is 2000tackdaddy Reputation is 2000tackdaddy Reputation is 2000tackdaddy Reputation is 2000tackdaddy Reputation is 2000tackdaddy Reputation is 2000tackdaddy Reputation is 2000tackdaddy Reputation is 2000
 
tackdaddy's Avatar
 
Posts: 1,146
Join Date: Apr 2002
Location: Pittsburgh,PA(Home of the Steelers,Penquins & Pirates)
Reputation Power: 191
May 5th, 2004, 10:48 PM

i would try doing it by editing the registry or have you tried to reinstall your browsers maybe that would work.


Pimpin is easy
  Send a message via MSN to tackdaddy  
Reply With Quote
  (#6) Old
phalkon30 Offline
Jay Leno Geek
phalkon30 Reputation is 650phalkon30 Reputation is 650phalkon30 Reputation is 650phalkon30 Reputation is 650phalkon30 Reputation is 650phalkon30 Reputation is 650phalkon30 Reputation is 650phalkon30 Reputation is 650
 
phalkon30's Avatar
 
Posts: 4,236
Join Date: Nov 2002
Location: Lacrosse, Wi.
Age: 23
Reputation Power: 306
May 5th, 2004, 11:18 PM

I'm pretty sure I heard of a virus that did something like this. I know you've scanned with spyware programs, but have you done a simple antivirus scan with the latest detections?

Also, when in windows, bring up the task manager (ctrl + alt + del), and tell us EVERY singe process running. Close any you know you don't need also, you may have better luck after the program is killed.


Help save lives by doing cancer research! Click here to see the Zeropaid.com UD member page. Please take a few minutes to sign up for our UD cancer research program, it uses idle cpu cycles to help fight cancer by helping to find new drugs. This thread has more info, or you can PM me with questions/comments. I hope to finish the guide on how to start using UD soon
 Send a message via ICQ to phalkon30 Send a message via AIM to phalkon30 Send a message via MSN to phalkon30 Send a message via Yahoo to phalkon30  
Reply With Quote
  (#7) Old
aboi Offline
Zeropaid Regular
aboi Reputation is 0
 
aboi's Avatar
 
Posts: 181
Join Date: Dec 2003
Reputation Power: 82
May 6th, 2004, 01:56 AM

hmmmmmmmmm sound very much like royal search. it was a hijack thing that took over my buddys ie.


My name is *** and I like Internet Porn
   
Reply With Quote
  (#8) Old
Induna Offline
Vote John Kerry!
Induna Reputation is 0
 
Induna's Avatar
 
Posts: 661
Join Date: Oct 2002
Reputation Power: 121
May 6th, 2004, 02:58 AM

I don't think dabbling in the registry will work because as soon as you reboot it will reset the homepage. Don't you think whoever designed the hijack program would have thought about that?

http://cexx.org/adware.htm

Scroll about half way down this page and it will give you a list of known homepage hijackers around at the moment and what to do with them.
   
Reply With Quote
  (#9) Old
acegik Offline
Zeropaid Regular
acegik Reputation is 0
 
acegik's Avatar
 
Posts: 26
Join Date: Jun 2003
Reputation Power: 80
May 6th, 2004, 03:09 AM

What I would do is restart and go on command prompts, then go to windows\system32 and type dir *.exe /od
this will give u the exe sorted by date, see the newest exe file and rename it just in case.
   
Reply With Quote
  (#10) Old
cjules13 Offline
Disgruntled but Unarmed
cjules13 Reputation is 550cjules13 Reputation is 550cjules13 Reputation is 550cjules13 Reputation is 550cjules13 Reputation is 550cjules13 Reputation is 550
 
cjules13's Avatar
 
Posts: 1,791
Join Date: Aug 2003
Location: Portland
Reputation Power: 172
May 6th, 2004, 06:03 AM

you can always use p2p to find your AdAware and Spybots... don't have to use IE.

That is a hardcore hijack - never heard of one that malicious...
   
Reply With Quote
  (#11) Old
smokingbevel Offline
_
smokingbevel Reputation is 0
 
Posts: 125
Join Date: Mar 2004
Reputation Power: 76
May 6th, 2004, 07:30 AM

Ironically, http://fadfg.outhost.info/ has link labeled "Spyware Removal" at the bottom of the page, under the copyright.
   
Reply With Quote
  (#12) Old
net_exodus78 Offline
Registered User
net_exodus78 Reputation is 0
 
net_exodus78's Avatar
 
Posts: 2
Join Date: Dec 2003
Location: Canada
Age: 21
Reputation Power: 0
May 6th, 2004, 07:41 AM

yes ironically, but when i clicked on it, it gave me a list of anti-spyware programs and it closes the browser as soon as i clicked on them.

I actually sort of got it fixed, some how, by installing spybot in safemode into a directory not containing the word "spybot". I could see the directory and all the files in it except the main spybot.exe file. So i randomly tried every executable in the folder and started spybot using update.exe. I made a scan and removed some parts of the spyware. Then i restarted in normal mode and scanned again and fixed more parts.

Right now, my browser is no longer hijacked, and i can go on sites containing words like "spybot" but i still can't see the spybot files.
  Send a message via MSN to net_exodus78  
Reply With Quote
  (#13) Old
napho Offline
Antisocial Bastard
napho Reputation is 2000napho Reputation is 2000napho Reputation is 2000napho Reputation is 2000napho Reputation is 2000napho Reputation is 2000napho Reputation is 2000napho Reputation is 2000napho Reputation is 2000napho Reputation is 2000napho Reputation is 2000
 
napho's Avatar
 
Posts: 1,082
Join Date: Dec 2002
Location: The Great White North
Reputation Power: 259
May 6th, 2004, 07:53 AM

There are insidious new spyware dll's by NicTech that install this registry key

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Guardian

If you have that key then you'll know what dll's are installed and you'll be able to delete them in safe mode and get rid of the sites they redirect you to with HijackThis.
   
Reply With Quote
  (#14) Old
The Hunter Offline
Janitor
The Hunter Reputation is 2000The Hunter Reputation is 2000The Hunter Reputation is 2000The Hunter Reputation is 2000The Hunter Reputation is 2000The Hunter Reputation is 2000The Hunter Reputation is 2000The Hunter Reputation is 2000The Hunter Reputation is 2000The Hunter Reputation is 2000The Hunter Reputation is 2000
 
The Hunter's Avatar
 
Posts: 11,735
Join Date: Apr 2002
Location: Copperhead Road
Age: 56
Reputation Power: 752
May 6th, 2004, 03:22 PM

That sounds very similar to what has happened to a friends pc. On his pc initially it just seemed that when he went to beta news the page was hijacked. I went to download the new spybot beta, and all hell broke loose. IE page not found, downloads blocked. The only way i could get the program, was to download it on his daughters pc, and mail it to him. Running it has not solved anything. Im still looking for answers, but if needed we will just frigging format.


Grow old along with me, the best is yet to be.
 Send a message via ICQ to The Hunter Send a message via MSN to The Hunter  
Reply With Quote
  (#15) Old
miss_silver Offline
Zeropaid Regular
miss_silver Reputation is 0
 
Posts: 84
Join Date: Dec 2003
Reputation Power: 77
May 7th, 2004, 08:22 AM

Something like that happened to me a while ago.

Each time I'd try to access the net, my start page was automatically redirected to porn sites! And after, it was popup galore, they kept popping up even after i've disconnected to the net. Was lucky enough to be able to access the net and cry for help at the bb I usually hangout. They told me to get AVG installed. AVG is a kick ass antivirus and warns ya if a virus/trojan is detected. What I caught according to AVG was the trojan esrporQ, which no one have never heard of. At the end, I was sure I had to reformat my drive to get rid of it but AVG and precise surgery on the WINDOW folder, was able to finally get rid of it.

A lot of times, those malicious files hide themselves in WINDOW\Temp internet files\content IE files...
   
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
File-Sharing Is, Like, Totally Uncool Miniver General Discussion 22 August 20th, 2004 02:27 PM




vBulletin Skin developed by: vBStyles.com