TechSpot
 
Go Back   TechSpot OpenBoards > OS & Software > Security and the Web
Forgot?

Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

WebHancer help

Reply
 
Thread Tools Search this Thread
  #1  
Old 04-28-2008, 06:12 PM
jbone jbone is offline
Newcomer, in training
 
Member since: Apr 2008, 14 posts
WebHancer help

Hi there! I'm new to this website but it seems very helpful.

hijackthis.log

I've recently been infected with WebHancer. I know that for sure because it was in the Add/Remove programs list. But I'm not sure if anything else has infected me. This is what is happening:

1) Ads from "From Internet Speed Rating" (or something very similar) randomly pop up.

2) A little bubble pops up in the bottom right of the screen telling me that spyware has been detected and I should click it to fix the problem. It goes to winsecuritysolutions . com which is a spyware sight.

3) It will mimic a windows security alert window and say it found a trojan, but its really fake.

4) My background changes to a blue screen with a warning about spyware on it and a link to winsecuritysolutions.

5) Task manager is disabled (says my Administration disabled it).

6) I can't install Ad-Aware.

7) Internet doesn't connect. It says it is connected but it cant get on a website. (I'm using a different computer right now.)

That's what I have noticed.
I don't want to manually delete it because I've read that that causes problems. (However, I will if there is no other way.)

I've attached a Hijack This file. I have no idea what any of it means but I figured I should post it.

Thank you!

jbone

EDIT: Also, I think I should mention that I ran Hijack This in Safe Mode.

Last edited by jbone : 04-28-2008 at 10:00 PM.
Reply With Quote
  #2  
Old 04-29-2008, 12:13 AM
jooonas jooonas is offline
Newcomer, in training
 
Member since: Apr 2008, 2 posts
This should help

Hey,

I've been struggling with the exact same virus for about 5-6 hours and after numerouns tries and searches I found something that got rid of it.

You'll need a program called SDFix and you have to run it in the command prompt after starting windows in safe mode. It is all explained here: at forums.majorgeeks.com/showthread.php?p=869653

After the whole thing is over (it will probably take about 30 minutes to scan through everything, at least it took that long on my old vaio), you will still need to apply a task manager fix (just google it) to get your task manager up and running again.

Hope this helps.

I hate Viruses with a passion, at least my Mac was working so I could get the PC fixed.

Cheerio
Reply With Quote
You can remove this banner by registering, join the TS Community for free.
  #3  
Old 04-29-2008, 08:41 PM
jbone jbone is offline
Newcomer, in training
 
Member since: Apr 2008, 14 posts
Thank you, but now my computer won't display the start bar, any icons, the Windows Button doesn't work, and Task Manager is still disabled. I'll try to save SDFix on a disk and install it from the disk.
Reply With Quote
  #4  
Old 04-29-2008, 08:46 PM
jbone jbone is offline
Newcomer, in training
 
Member since: Apr 2008, 14 posts
No... the window with the CD folder didn't appear. I'm starting to think that I'm done... any suggestions?

If I am done, is there some way that I can transfer files at this point?

EDIT: WAIT, do CD's run in safe mode? Because the computer was in safe mode when I tried it.

Last edited by jbone : 04-29-2008 at 09:19 PM.
Reply With Quote
  #5  
Old 04-30-2008, 01:08 AM
jooonas jooonas is offline
Newcomer, in training
 
Member since: Apr 2008, 2 posts
I am not sure that I am following you. Did you start windows in safe mode? Are you running XP or Vista? In case it is Vista, I am afraid I cannot help you. I put SDfix on a USB stick and that worked. Though, I got rid of the virus, my computer is still unstable and I think I will have reinstall windows, or just give up on it and just use my mac.
Reply With Quote
  #6  
Old 04-30-2008, 01:00 PM
jbone jbone is offline
Newcomer, in training
 
Member since: Apr 2008, 14 posts
I have a laptop running Windows XP.

Okay here is what happened.
I started my computer regularly. When I logged on, all I saw was my desktop's regular background, with no icons, no start bar, nothing. Ctrl-Alt-Delete doesn't work because "Task Manager has been disabled by my administrator." The Windowsbutton doesn't do anything. I'm forced to shut off my computer by holding the power button.
Then I tried running in Safe Mode, but I got the same thing, except the background was black and it said Safe Mode in the four corners.

The CD drive autoplay also doesn't work.
I have an idea that I have to try when I get home. Windowsbutton + R maybe?

I don't know..
Reply With Quote
  #7  
Old 05-03-2008, 08:41 PM
jbone jbone is offline
Newcomer, in training
 
Member since: Apr 2008, 14 posts
Sorry for bumping this but I really need help!

bump.
Reply With Quote
  #8  
Old 05-04-2008, 02:43 PM
Blind Dragon's Avatar
Blind Dragon Blind Dragon is offline
TechSpot Evangelist
 
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
System specs
Please uninstall whichever version of SDFix you installed

Download to your Desktop this self-extracting ZIP archive FixPolicies.exe

• Double-click FixPolicies.exe
• Click the Install button on the bottom toolbar of the box that will open.
• The program will create a new Folder called FixPolicies
• Double-click to Open the new Folder, and then double-click the file named Fix_Policies.cmd
• A black box will briefly appear and then close. This will enable your Control Panel, Task Manager and stop any Administrative warnings.

==========================

Download and Install SDFix
  • Download SDFix and save it to your Desktop.
  • Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

Boot into Safe Mode
  • Restart your computer and start pressing the F8 key on your keyboard.
  • Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.

Run SDFix
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
  • Attach Report.txt back here

============================

Attach fresh Hijackthis log with Report.txt
Reply With Quote
  #9  
Old 05-06-2008, 09:34 AM
rima rima is offline
Newcomer, in training
 
Member since: May 2008, 4 posts
Winsecuritysolutions.com bug

Blind Dragon, thanks for your help. I followed your instructions and it removed the very nasty bug that infected my computer last week and was difficult to remove. Here is the report.txt attached. Thanks again
Attached Files
File Type: txt report.txt (8.2 KB, 1 views)
Reply With Quote
You can remove this banner by registering, join the TS Community for free.
  #10  
Old 05-06-2008, 09:50 AM
Blind Dragon's Avatar
Blind Dragon Blind Dragon is offline
TechSpot Evangelist
 
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
System specs
That was nasty.

What about post a fresh Hijackthis log now so that I can double check that it all was removed.

Highjackthis Instructions
  • Make sure you have the LATEST version of HJT (currently v2.0.0.2) it can be downloaded from HERE
  • Run the HijackThis Installer and it will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe. Please don't change the directory.
  • After installing, the program launches automatically, select Scan now and save a log
  • After the scan is complete please attach your log onto the forums using the paper clip icon above your reply.
Reply With Quote
  #11  
Old 05-06-2008, 02:41 PM
rima rima is offline
Newcomer, in training
 
Member since: May 2008, 4 posts
Thanks Blind Dragon. Here is the log file. I think it is time I did a reinstall just to make sue it is clean.
Attached Files
File Type: log hijackthis.log (12.7 KB, 1 views)
Reply With Quote
  #12  
Old 05-07-2008, 08:16 AM
Blind Dragon's Avatar
Blind Dragon Blind Dragon is offline
TechSpot Evangelist
 
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
System specs
I agree there are still other infections on there. A lot of which we could clean but there is no guarantee that we can get 100% of it.
Reply With Quote
  #13  
Old 05-15-2008, 03:55 AM
rima rima is offline
Newcomer, in training
 
Member since: May 2008, 4 posts
hi blind dragon, how do I use the log file output from hijackthis to remove infections? is there another tool that tells me which ones to remove? Thanks.
Reply With Quote
  #14  
Old 05-15-2008, 09:20 AM
Blind Dragon's Avatar
Blind Dragon Blind Dragon is offline
TechSpot Evangelist
 
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
System specs
Do NOT use an analyzer. You really need to research the entries one at a time, or get somebody who is trained at reading the logs to do it for you.

Did you reformat your computer? Are you still wanting to clean it?

Let me know. I will tell you what to do if you would prefer to clean the system.
Reply With Quote
  #15  
Old 05-15-2008, 11:41 AM
rima rima is offline
Newcomer, in training
 
Member since: May 2008, 4 posts
thanks for the offer of help. I was re infected after re-installing (should stop my wife using my PC!!). I have now cleaned it up with anti-virus, but I like to know how to use hijackthis log file to make sure it is cleaned. to investigate each item in the log file takes some time, I was looking for some faster solution. cheers.
Reply With Quote
  #16  
Old 05-15-2008, 12:02 PM
Blind Dragon's Avatar
Blind Dragon Blind Dragon is offline
TechSpot Evangelist
 
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
System specs
sorry there is no 100% full proof shortcuts.
Reply With Quote
  #17  
Old 05-28-2008, 09:14 AM
jbone jbone is offline
Newcomer, in training
 
Member since: Apr 2008, 14 posts
Sorry!

Hey I hate to bump this 13 days later but I haven't been on a computer in a long time (due to the fact that mine is broken). I'm on another computer right now.

BlindDragon, thank you for your input. However, I don't see how I can install FixPolicies.exe onto my Desktop because my internet doesn't work, and the AutoPlay on my disk drive doesn't seem to be working. (Does AutoPlay ever work in Safe Mode? That's the only time I tried it.) I highly doubt that a USB stick will work (though I could try it..). There are no icons or start bar, and task manager doesn't work.

I never installed SDFix on my computer for these reasons.

So my question is, how do I install FixPolicies.exe to my desktop?
Reply With Quote
  #18  
Old 05-28-2008, 09:42 AM
Blind Dragon's Avatar
Blind Dragon Blind Dragon is offline
TechSpot Evangelist
 
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
System specs
You absolutely can use a USB drive. I have a 4GB USB stick with installers for every program I use to remove malware. I usually do complete removals with the computer disconnected then only reconnect when I think it is clean to update and run an online scan for 2nd opinion
Reply With Quote
  #19  
Old 06-01-2008, 06:52 PM
jbone jbone is offline
Newcomer, in training
 
Member since: Apr 2008, 14 posts
Quote:
Originally Posted by Blind Dragon
Please uninstall whichever version of SDFix you installed

Download to your Desktop this self-extracting ZIP archive FixPolicies.exe

• Double-click FixPolicies.exe
• Click the Install button on the bottom toolbar of the box that will open.
• The program will create a new Folder called FixPolicies
• Double-click to Open the new Folder, and then double-click the file named Fix_Policies.cmd
• A black box will briefly appear and then close. This will enable your Control Panel, Task Manager and stop any Administrative warnings.
I'm going to buy a USB stick and try this. My question is: when I put the USB stick in will FixPolicies automatically install?
Also, I can't delete SDFix because there's no way to access my files.
Reply With Quote
  #20  
Old 06-01-2008, 07:56 PM
Blind Dragon's Avatar
Blind Dragon Blind Dragon is offline
TechSpot Evangelist
 
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
System specs
When you boot to safe mode do you have a start menu?

What happens when you hit the windows key on your keyboard and Press R at the same time?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:57 AM.


  TechSpot  The PC Enthusiast Resource    |    News    |    Reviews    |    Guides    |    Downloads    |    Drivers    |    Forums    |    Pricewatch    |    News Archive    |    RSS Feeds
  Our Blog    |    Tech Deals    |   vb Sitemap    |    User Gallery    |    Startup Radar    |    Icons by Foood    |    Powered by StoryTeller    |    TechSpot in Spanish

  Copyright © 1998-2008 TechSpot.com. TechSpot is a registered trademark. All Rights Reserved.
Privacy policy.
Advertising | About TechSpot 
TechSpot Pricewatch TechSpot Hot Deals
Windows Startup Radar