User User name Password  
   
Sunday 31.8.2025 / 08:49
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > windows hijacked, please assist! thank you~
Show topics
 
Forums
Forums
Windows Hijacked, please assist! Thank you~
  Jump to:
 
Posted Message
LuckySevn
Newbie
_
5. April 2007 @ 15:07 _ Link to this message    Send private message to this user   
Dear all,

I'm running Win2k Pro w/ SP4. Just 2 nights ago, I noticed whenever I type in a search string on Yahoo or Google, IE would be redirected to some site completely irrelevant. I ran Spybot, cleaned up about 10 malwares including SpyMarshall and followed by HijackThis. HjT picked up several search string redirecting keys plus a bunch of keys for TCP protocols that has IP addresses in them that I manually entered to block in my router. I removed those and the problem stopped....for an hour.

About one hour after that, my system became SUPER SLOW. I checked it and found the CPU and memory were under 100% load. Opened process view, saw Winmngt.exe that was never there before plus 2 extra scvhost.exe with one being 22,364kb and the other being 8780kb. I immediately ended those and ran HjT again...found nothing. Then I went online looking for latest AVG and Killbox...but couldn't click on ANY links nor dl anything at all. Then I found out that the Windows Search was disabled..when I clicked on it, it doesn't even run in the process. Plus, the winmngt.exe and scvhost.exe came back again. So I opened WINNT folder looking for files that weren't there before(I didn't install anything in over a week), and found the folder "empty" with no sub folders and files, same under Explorer. Opened its Properties, it's shared as $ADMIN$, so I disabled it, but re-enabled by itself again. The desktop background setting is also disabled, can't select any wallpaper nor even move its scrollbar.

Opened Control Panel, all icons are now on the leftside. MS Update is blocked. MS main site is blocked. And now Spybot's homepage is blocked also, can't access those sites at all. Before all this happened, my sister's system started hogging down my connection about 2 weeks ago. I ran scans on her system found nothing. But in the process I saw a file named "g0ld.exe" that can't be ended, and is not found anywhere on the system. I unplugged her LAN for the past 2 weeks while she wasn't home....now that she's back, I plugged her back in and not long after all the problems started. I already ran outta ideas, please assist anyone, much appreciated!


Blessings

The Greatest Beauty is found in the hearts of those who Love-
The_Fiend
Suspended permanently
_
5. April 2007 @ 15:18 _ Link to this message    Send private message to this user   
g0ld.exe is a keylogger, and a nasty one at that.
Try starting both systems in safemode with networking options *tap F8 at startup, then choose said option*, then download AVG anti spyware, update and run it, then run HijackThis on both systems, and post the logs here *be sure to note which log belongs to which computer*.

irc://arcor.de.eu.dal.net/wasted_hate

Wanna tell me off, go ahead.
I dare ya !
LuckySevn
Newbie
_
5. April 2007 @ 15:45 _ Link to this message    Send private message to this user   
Hi Fiend thx for the reply. I'm at work right now, will be in home in about 2 hours and I'll run those steps and paste the logs. Thx again.

The Greatest Beauty is found in the hearts of those who Love-
Advertisement
_
__
 
_
The_Fiend
Suspended permanently
_
5. April 2007 @ 16:19 _ Link to this message    Send private message to this user   
By that time, i'll be at work, so it might take a bit to get a response, but there's several other folks here who can help you just as well *if not better* with this.
In any case, good luck.

irc://arcor.de.eu.dal.net/wasted_hate

Wanna tell me off, go ahead.
I dare ya !
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > windows hijacked, please assist! thank you~
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2025 by AfterDawn Ltd.

  IDG TechNetwork