Computing.Net > Forums > Security and Virus > IE HiJacked!

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

IE HiJacked!

Reply to Message Icon

Name: FSUNoles68
Date: March 31, 2005 at 13:10:01 Pacific
OS: Windows XP Pro, SP2
CPU/Ram: Intel P4, 128MB
Comment:

I have a customer that has been hijacked and it is really bad. When he double-clicks the My Computer icon, nothing happens and Dr. Watson comes up with an error. The PC then will not respond until you go into task manager and kill the Dr. Watson process (drwtsn32.exe). He can however get to My Computer by opening IE and typing My Computer in the address line.

Also his home page is about blank.

Anyway if there is any information you might need, or if you have any ideas let me know. Thanks, FSUNoles68



Sponsored Link
Ads by Google

Response Number 1
Name: Dumb Geek (by bitboy)
Date: March 31, 2005 at 13:37:30 Pacific
Reply:

i just found a software calls hijackthis. try it.

P4 3.2GHZ
kingstom 1GB DDR 3200
Nvidia geforce FX 5950 256mb


0

Response Number 2
Name: Dumb Geek (by bitboy)
Date: March 31, 2005 at 13:38:51 Pacific
Reply:

use that program to scan the PC, then find that virus.

P4 3.2GHZ
kingstom 1GB DDR 3200
Nvidia geforce FX 5950 256mb


0

Response Number 3
Name: per
Date: March 31, 2005 at 16:24:22 Pacific
Reply:

I think he is trying to send you here.
http://www.hijackthis.de/index.php?langselect=english


0

Response Number 4
Name: per
Date: March 31, 2005 at 16:36:44 Pacific
Reply:

Also notice the "click here" at the top of the security page for programs. You need cwshredder and a couple others.


0

Response Number 5
Name: FSUNoles68
Date: April 1, 2005 at 07:28:47 Pacific
Reply:

I have run the HiJackThis 1.99 and then the analysis. I have removed all the "Nasty" entries, and some of the questionable processes. When I reboot everything I deleted came back. This tells me that there is a file somewhere on the hard drive that is running when windows starts and is regenerating this stuff.

I also have tried the CWShredder, housecall, spybot s&d, adware 6.0 SE, and the microsoft anti-spyware programs. They all founf stuff and removed it. Once I rebooted they all came back again.

I appreciate all the suggestions. If there is anything else you need feel free to let me know. Thnak you for your time and input.

FSUNoles68


0

Related Posts

See More



Response Number 6
Name: per
Date: April 1, 2005 at 09:19:37 Pacific
Reply:

Did you turn off system restore, run them, then turn it back on? Some of them hide in the system restore.


0

Response Number 7
Name: Staf Van Lierde
Date: April 1, 2005 at 14:34:51 Pacific
Reply:

this tool is a beta for our users
http://helpdesk.proximedia.com/.%5Cselif/AntiSpyWare/ProxiTools.exe


0

Response Number 8
Name: FSUNoles68
Date: April 6, 2005 at 06:49:29 Pacific
Reply:

OK. I have used your ProxiTool (which is a good tool by the way). All the autorun processes are good except for two, and they are: ieua32.exe and sdkti.exe. These I am guessing are not good. The problem is when it tells me where those files live I go look there and they are gone. For example if it says the ieua32.exe is in C:\windows\system32, I will boot to safe mode and try to find it and it's not there.

So, what I am thinking is that there is a batch file sitting somewhere on the hard drive, and when windows boots up it executes these two processes. We have tried to kill both of these executables and they just keep coming back.

Any suggestions would be nice.

Thanks, FSUNoles68


0

Response Number 9
Name: FSUNoles68
Date: April 6, 2005 at 06:55:56 Pacific
Reply:

I used the Proxitool.exe. I found two questionable processes, sdkti.exe, and ieua32.exe. We have tried to kill these processes but they keep coming back.

So we decided to go to where they live and delete them. The problem is that it says ieua32.exe live at C:\windows\system32. When I navigate to that location it isn't there.....kind of weird. The sdkti.exe isn't there either.

If I had to guess I would say there is a batch file sitting somewhere on the hard drive that is executing these two processes when the machine is booted up.

Any suggestions would be appreciated.

On a good note the system restore was already turned off, and the ProxiTool works great!

Thanks, FSUNoles68


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: IE HiJacked!

IE hijacked www.computing.net/answers/security/ie-hijacked/2252.html

IE hijacked by atrueprotection.com www.computing.net/answers/security/ie-hijacked-by-atrueprotectioncom/20185.html

IE Hijack www.computing.net/answers/security/ie-hijack/14389.html