jdimiceli wrote:
Do I have to use the malware software to get rid of the hijacker? I have the fake windows firewall warning on my computer, but I have not downloaded Personal Defender. Most of the websites tell you how to get rid of Personal Defender, but not the hijacker program itself. Some other message boards say that there is just an executable file on my computer doing this called mupd1_2_1711951.exe that you just have to find and delete, which I cannot find by searching my computer. Does the executable file have another name or should I just use a spyware/malware program to get rid of it?
Hi jdimiceli
Just got up a short while ago,
You are infected with a form of "about:blank" and something has made bad trusted zones, so here goes.
After all this you will have enter your browser homepage as that is gone. Start Hijackthis again and tick only these entries.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {DD6FA5AD-FA2E-7FF9-4D4C-8C32A4EAEF3F} - C:\WINDOWS\system32\winhg32.dll
O4 - HKLM\..\Run: [Task Manager Help] tskmgrhlp.exe (worm)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k (Not needed on startup)
O4 - HKLM\..\RunServices: [Task Manager Help] tskmgrhlp.exe (the worm)
O4 - HKCU\..\Run: [Task Manager Help] tskmgrhlp.exe (the worm again)
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe (Bad, could be any of a group)
O4 - HKUS\S-1-5-18\..\Run: [Task Manager Help] tskmgrhlp.exe (User 'SYSTEM') (the worm)
O4 - HKUS\.DEFAULT\..\Run: [Task Manager Help] tskmgrhlp.exe (User 'Default user') (the worm)
O9 - Extra button: Advisor - {E779F1D3-115D-4185-8D53-991CCC79FA7B} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Network Security Service (NSS) (%AF夶À¨) - Unknown owner - C:\WINDOWS\system32\sdksm32.exe (file missing)
After ticking those, click "fix Checked" Hijackthis may ask to restart your PC.
Due to the worm you may want to run SDfix, See how to use SDfix here http://community.norton.com/norton/board/message?board.id=nis_feedback&thread.id=23740
Then download and install SuperAntispyware Free, Update then do a full scan.
Quads