 |
|
|
|
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
WebHancer help

04-28-2008, 06:12 PM
|
|
Newcomer, in training
|
|
Member since: Apr 2008, 14 posts
|
|
|
WebHancer help
Hi there! I'm new to this website but it seems very helpful.
hijackthis.log
I've recently been infected with WebHancer. I know that for sure because it was in the Add/Remove programs list. But I'm not sure if anything else has infected me. This is what is happening:
1) Ads from "From Internet Speed Rating" (or something very similar) randomly pop up.
2) A little bubble pops up in the bottom right of the screen telling me that spyware has been detected and I should click it to fix the problem. It goes to winsecuritysolutions . com which is a spyware sight.
3) It will mimic a windows security alert window and say it found a trojan, but its really fake.
4) My background changes to a blue screen with a warning about spyware on it and a link to winsecuritysolutions.
5) Task manager is disabled (says my Administration disabled it).
6) I can't install Ad-Aware.
7) Internet doesn't connect. It says it is connected but it cant get on a website. (I'm using a different computer right now.)
That's what I have noticed.
I don't want to manually delete it because I've read that that causes problems. (However, I will if there is no other way.)
I've attached a Hijack This file. I have no idea what any of it means but I figured I should post it.
Thank you!
jbone
EDIT: Also, I think I should mention that I ran Hijack This in Safe Mode.
Last edited by jbone : 04-28-2008 at 10:00 PM.
|

04-29-2008, 12:13 AM
|
|
Newcomer, in training
|
|
Member since: Apr 2008, 2 posts
|
|
|
This should help
Hey,
I've been struggling with the exact same virus for about 5-6 hours and after numerouns tries and searches I found something that got rid of it.
You'll need a program called SDFix and you have to run it in the command prompt after starting windows in safe mode. It is all explained here: at forums.majorgeeks.com/showthread.php?p=869653
After the whole thing is over (it will probably take about 30 minutes to scan through everything, at least it took that long on my old vaio), you will still need to apply a task manager fix (just google it) to get your task manager up and running again.
Hope this helps.
I hate Viruses with a passion, at least my Mac was working so I could get the PC fixed.
Cheerio
|
 You can remove this banner by registering, join the TS Community for free. |
|
|

04-29-2008, 08:41 PM
|
|
Newcomer, in training
|
|
Member since: Apr 2008, 14 posts
|
|
|
Thank you, but now my computer won't display the start bar, any icons, the Windows Button doesn't work, and Task Manager is still disabled. I'll try to save SDFix on a disk and install it from the disk.
|

04-29-2008, 08:46 PM
|
|
Newcomer, in training
|
|
Member since: Apr 2008, 14 posts
|
|
|
No... the window with the CD folder didn't appear. I'm starting to think that I'm done... any suggestions?
If I am done, is there some way that I can transfer files at this point?
EDIT: WAIT, do CD's run in safe mode? Because the computer was in safe mode when I tried it.
Last edited by jbone : 04-29-2008 at 09:19 PM.
|

04-30-2008, 01:08 AM
|
|
Newcomer, in training
|
|
Member since: Apr 2008, 2 posts
|
|
|
I am not sure that I am following you. Did you start windows in safe mode? Are you running XP or Vista? In case it is Vista, I am afraid I cannot help you. I put SDfix on a USB stick and that worked. Though, I got rid of the virus, my computer is still unstable and I think I will have reinstall windows, or just give up on it and just use my mac.
|

04-30-2008, 01:00 PM
|
|
Newcomer, in training
|
|
Member since: Apr 2008, 14 posts
|
|
|
I have a laptop running Windows XP.
Okay here is what happened.
I started my computer regularly. When I logged on, all I saw was my desktop's regular background, with no icons, no start bar, nothing. Ctrl-Alt-Delete doesn't work because "Task Manager has been disabled by my administrator." The Windowsbutton doesn't do anything. I'm forced to shut off my computer by holding the power button.
Then I tried running in Safe Mode, but I got the same thing, except the background was black and it said Safe Mode in the four corners.
The CD drive autoplay also doesn't work.
I have an idea that I have to try when I get home. Windowsbutton + R maybe?
I don't know..
|

05-03-2008, 08:41 PM
|
|
Newcomer, in training
|
|
Member since: Apr 2008, 14 posts
|
|
|
Sorry for bumping this but I really need help!
bump.
|

05-04-2008, 02:43 PM
|
 |
TechSpot Evangelist
|
|
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
|
|
Please uninstall whichever version of SDFix you installed
Download to your Desktop this self-extracting ZIP archive FixPolicies.exe
• Double-click FixPolicies.exe
• Click the Install button on the bottom toolbar of the box that will open.
• The program will create a new Folder called FixPolicies
• Double-click to Open the new Folder, and then double-click the file named Fix_Policies.cmd
• A black box will briefly appear and then close. This will enable your Control Panel, Task Manager and stop any Administrative warnings.
==========================
Download and Install SDFix- Download SDFix and save it to your Desktop.
- Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Boot into Safe Mode- Restart your computer and start pressing the F8 key on your keyboard.
- Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.
Run SDFix- Open the extracted SDFix folder and double click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
- Attach Report.txt back here
============================
Attach fresh Hijackthis log with Report.txt
|

05-06-2008, 09:34 AM
|
|
Newcomer, in training
|
|
Member since: May 2008, 4 posts
|
|
|
Winsecuritysolutions.com bug
Blind Dragon, thanks for your help. I followed your instructions and it removed the very nasty bug that infected my computer last week and was difficult to remove. Here is the report.txt attached. Thanks again
|
 You can remove this banner by registering, join the TS Community for free. |
|
|

05-06-2008, 09:50 AM
|
 |
TechSpot Evangelist
|
|
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
|
|
That was nasty.
What about post a fresh Hijackthis log now so that I can double check that it all was removed.
Highjackthis Instructions- Make sure you have the LATEST version of HJT (currently v2.0.0.2) it can be downloaded from HERE
- Run the HijackThis Installer and it will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe. Please don't change the directory.
- After installing, the program launches automatically, select Scan now and save a log
- After the scan is complete please attach your log onto the forums using the paper clip icon above your reply.
|

05-06-2008, 02:41 PM
|
|
Newcomer, in training
|
|
Member since: May 2008, 4 posts
|
|
|
Thanks Blind Dragon. Here is the log file. I think it is time I did a reinstall just to make sue it is clean.
|

05-07-2008, 08:16 AM
|
 |
TechSpot Evangelist
|
|
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
|
|
|
I agree there are still other infections on there. A lot of which we could clean but there is no guarantee that we can get 100% of it.
|

05-15-2008, 03:55 AM
|
|
Newcomer, in training
|
|
Member since: May 2008, 4 posts
|
|
|
hi blind dragon, how do I use the log file output from hijackthis to remove infections? is there another tool that tells me which ones to remove? Thanks.
|

05-15-2008, 09:20 AM
|
 |
TechSpot Evangelist
|
|
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
|
|
|
Do NOT use an analyzer. You really need to research the entries one at a time, or get somebody who is trained at reading the logs to do it for you.
Did you reformat your computer? Are you still wanting to clean it?
Let me know. I will tell you what to do if you would prefer to clean the system.
|

05-15-2008, 11:41 AM
|
|
Newcomer, in training
|
|
Member since: May 2008, 4 posts
|
|
|
thanks for the offer of help. I was re infected after re-installing (should stop my wife using my PC!!). I have now cleaned it up with anti-virus, but I like to know how to use hijackthis log file to make sure it is cleaned. to investigate each item in the log file takes some time, I was looking for some faster solution. cheers.
|

05-15-2008, 12:02 PM
|
 |
TechSpot Evangelist
|
|
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
|
|
|
sorry there is no 100% full proof shortcuts.
|

05-28-2008, 09:14 AM
|
|
Newcomer, in training
|
|
Member since: Apr 2008, 14 posts
|
|
|
Sorry!
Hey I hate to bump this 13 days later but I haven't been on a computer in a long time (due to the fact that mine is broken). I'm on another computer right now.
BlindDragon, thank you for your input. However, I don't see how I can install FixPolicies.exe onto my Desktop because my internet doesn't work, and the AutoPlay on my disk drive doesn't seem to be working. (Does AutoPlay ever work in Safe Mode? That's the only time I tried it.) I highly doubt that a USB stick will work (though I could try it..). There are no icons or start bar, and task manager doesn't work.
I never installed SDFix on my computer for these reasons.
So my question is, how do I install FixPolicies.exe to my desktop?
|

05-28-2008, 09:42 AM
|
 |
TechSpot Evangelist
|
|
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
|
|
|
You absolutely can use a USB drive. I have a 4GB USB stick with installers for every program I use to remove malware. I usually do complete removals with the computer disconnected then only reconnect when I think it is clean to update and run an online scan for 2nd opinion
|

06-01-2008, 06:52 PM
|
|
Newcomer, in training
|
|
Member since: Apr 2008, 14 posts
|
|
Quote:
|
Originally Posted by Blind Dragon
Please uninstall whichever version of SDFix you installed
Download to your Desktop this self-extracting ZIP archive FixPolicies.exe
• Double-click FixPolicies.exe
• Click the Install button on the bottom toolbar of the box that will open.
• The program will create a new Folder called FixPolicies
• Double-click to Open the new Folder, and then double-click the file named Fix_Policies.cmd
• A black box will briefly appear and then close. This will enable your Control Panel, Task Manager and stop any Administrative warnings.
|
I'm going to buy a USB stick and try this. My question is: when I put the USB stick in will FixPolicies automatically install?
Also, I can't delete SDFix because there's no way to access my files.
|

06-01-2008, 07:56 PM
|
 |
TechSpot Evangelist
|
|
Location: Tampa FL
Member since: Oct 2007, 3,118 posts
|
|
|
When you boot to safe mode do you have a start menu?
What happens when you hit the windows key on your keyboard and Press R at the same time?
|
| Thread Tools |
Search this Thread |
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -4. The time now is 04:57 AM.
|
|