Jump to content


Photo

Mozilla Hijack


  • Please log in to reply
1 reply to this topic

#1 Seefyre

Seefyre

    Member

  • Full Member
  • Pip
  • 4 posts

Posted 18 July 2004 - 03:12 PM

Ok, here we go again. After a terrible bout with CWS in IE. I got it cleaned up (or so I thought) and went to MOZILLA to be done with the IE curse and security flaws.
I now have been hijacked in MOZILLA. My homepage was google, now I get a fake google and the message "The requested URL /cgi-bin/webcm?getpage=../html/hurl_status_real.html was not found on this server." Any help would be appreciated. I currently update and scan with SPYBOT, ADAWARE, SPYWAREBLASTER and BROWSER HIJACK BLASTER. Recent scans with CWShredder and ABOUT:BLASTER reveal nothing. Wow, these guys are good. My latest reseach indicates a completely hidden DLL not even regedit can expose, thus leaving the root of reinfection. Can anyone help?

#2 PGPhantom

PGPhantom

    Superman of SWI

  • Emeritus
  • PipPipPipPipPip
  • 3,494 posts

Posted 16 September 2004 - 11:18 AM

  • HijackThis ...
    • Double click on "My Computer" to open it.
    • Double click on the local "C-Drive" to open it.
    • Click on "File" => "New Folder" and name it HJT. i.e. The folder will be C:\HJT.
    • Please download HijackThis from any of the following locations:
    • spywareinfo.com
    • subratam.org
    • tools.zerosrealm.com
  • Install/Unzip it into C:\HJT.
  • Only run HijackThis from C:\HJT\HijackThis.exe. That way we can ensure that we have the backup files available in the event that they are needed.
  • Run HijackThis, click on scan and wait for the scan to finish.
  • The "Scan" button will change to "Save Log", click on it and simply press "Save" on the window that will appear.
  • Notepad will open with a copy of the log.
    • Click on "Edit" => "Select All".
    • Click on "Edit" => "Copy". This will copy the contents of the Notepad instance to the clipboard.
  • Please post your entire log here for analysis.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button