also @ TechSpot: Tech Tip: Turn Off your Display Using a Windows Shortcut and More
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Google Hijack Virus, steps complete

Closed Thread
Bookmark Thread Tools
  #1  
Old 01-06-2009
Newcomer, in training
 
Member since: Jan 2009, 1 posts
Google Hijack Virus, steps complete

Hi everyone,

I have the google hijack virus that will allow me to search on google, but once I click a link, it hijacks my browser and goes somewhere else.

I read the 8-step guide and completed what I can, but this virus is pretty tough and blocked some of the steps. Here is what I could actually do:

1 - Virus scan - Scanned with eset, removed a trojan, nothing else infected.
2 - CCleaner - I run it regularly and I just ran it again
3 - Disabled Virus scanner - Disabled it
4 - Malware bytes Anti-Malware - I have it installed, but the virus blocks the program before it can update or run, so I can't get any use out of it right now.
5 - SuperAntiSpyware - Same deal as Malwarebytes.
6 - Java - My Java was out of date, but I have it updated and I deleted everything else.
7 - HiijackThis will run, and I have attached my log.

Also, the virus disables my automatic updates, will not allow me to update eset, disabled my firewall, won't allow me to download avg, won't allow me to install spybot or visit their website, among other things. My system32 folder also pops up every time I restart.

I think that covers it. I'm pretty close to reformatting simply because my computer runs so slow now and I can't really use the internet all that well. Any solutions to my problem are greatly appreciated.

jgc
Attached Files
File Type: txt hijackthisjgc.txt (7.4 KB, 1 views)
  #2  
Old 01-09-2009
TechSpot Booster
 
Location: Illinois, USA
Member since: Feb 2007, 906 posts
System specs
  • complaining of virus blocks the program before it can update or run -
    • MBAM and SAS scans will begin handling of this thrreat.
    • HJT scan informs what has not been handled
    • Without supporting logs, anything fixed by HJT will not end this threat.

  • Scan with HJT. Tick & Fix. Restart the computer
    Code:
    O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\Joe Crandley\Application Data\gadcom\gadcom.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
    O20 - AppInit_DLLs: C:\Program,Files\RelevantKnowledge\rlai.dll,C:\Program,Files\RelevantKnowledge\rlai.dll,C:\Program,Files\RelevantKnowledge\rlai.dll,C:\Program,Files\RelevantKnowledge\rlai.dll,C:\Program,Files\RelevantKnowledge\rlai.dll,C:\Program Files\RelevantKnowledge\rlai.dll pkobtf.dll
  • Delete folders / files - if present - from the list inside code box above.


Your are describing an exploit to frustrate reaching anti-malware sites. Here are methods that have been used recently. The alternative was offered by a new member.

Your symptoms suggest that renaming executables ( "member that used renaming") can likely get things moving.
  1. Since you are discribing a case of difficulty. attempt this method (follow link for 'How To')
    • Use this method to stop any 'non-plug and play' driver that is named in this guide.
    • Please report its name for changes to the method

  2. For infections that have more severe symptoms, Unable to run or update via TechSpot 8 Steps or manually run MBAM or SAS

  3. Message #3 - link to 'fixit download' has demonstrated its effectiveness in many cases. Go to message # 3 'fixit download'. Part of the method renames the executable to get the application to run. Here is another member that used renaming.

  4. Alternative - Web site has a link to download-dot-com - phonetic spelling used
    • There appears to be a connection with 'sagipsul' popups.
    • Read this post. from member.
    • phonetic spelling for web site
      • w.dot-simplysup.dot-com/tremover/download.html

Secondary Links
Gadcom often associated with resycled. Is this what you referred to?
Majestyk; reply # 25; resycledbootcom/


resycled/boot.com is a worm that propagates on local fixed and removable USB drives. resycled/boot.com may infect drives via autorun.inf file it created that runs a command each time the drive is accessed. Malicious files will be copied to a drives attached on infected computer.
To remove this ad, sign in. To register for a new account, click here.
  
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
8-Steps Complete - please help Virus & Malware removal 2 01-02-2009 01:58 PM
Google search result links send to wrong pages, steps followed problem remains Virus & Malware removal 4 12-30-2008 06:25 PM
8-Steps Complete / Logs Posted / Help? Virus & Malware removal 8 12-25-2008 01:46 PM
8 steps complete, 3 logs posted Virus & Malware removal 2 11-23-2008 07:58 PM
Google hijack and other spyware/virus Virus & Malware removal 1 08-28-2008 02:36 AM


All times are GMT -4. The time now is 12:10 AM.