Browser was Hijacked. Please help.

Reply

Join Date: May 2005
Posts: 5
Reputation: Sagan is an unknown quantity at this point 
Solved Threads: 0
Sagan Sagan is offline Offline
Newbie Poster

Browser was Hijacked. Please help.

 
0
  #1
May 31st, 2005
First, let me thank anyone who is willing to try an help me. I have tried to fix this for the past 3 hours and it keep coming back. It seems to be related to this stupid Home Search proggy and something called Shopping Wizard. I am unable to remove them from the add/remove programs box. I have also tried following the directions on a post from March of this year regarding the Home Search program to no avail. I have HiJackThis, About:Buster, HSRemove, and Spybot S&D already on my machine. Here is my hijack this log. Any help at all is appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 11:33:51 AM, on 5/31/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\System32\3Com_DMI\3CDMINIC.EXE
C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\DMI\WIN32\bin\DellDmi.exe
C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
C:\Program Files\Dell\OpenManage\Client\DLT.exe
C:\WINNT\SYSTEM32\DWRCS.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\dmi\win32\bin\Win32sl.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\ntvn.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\system32\LXSUPMON.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\system32\iehq.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\twsys.dll/sp.html#55135
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\twsys.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\twsys.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\twsys.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\twsys.dll/sp.html#55135
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\twsys.dll/sp.html#55135
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {E242AD05-F49E-8697-B586-6E43C236C954} - C:\WINNT\msxg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINNT\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iehq.exe] C:\WINNT\system32\iehq.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab34246.cab
O16 - DPF: {D1ACD2D8-7312-4D06-BECD-90EB094D2277} - http://mediaplayer.walmart.com/installer/install.cab
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\netah.exe (file missing)
O23 - Service: 3Com DMI Agent (3ComDMIService) - 3Com Corporation - C:\WINNT\System32\3Com_DMI\3CDMINIC.EXE
O23 - Service: ActionAgent - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: DellDmi - Dell Computer Corporation - C:\DMI\WIN32\bin\DellDmi.exe
O23 - Service: DEventAgent - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
O23 - Service: DLT - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\DLT.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: Win32Sl - Intel - C:\dmi\win32\bin\Win32sl.exe

Thanks again for any help you can provide.

Sagan
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 23
Reputation: Gaffer Sport is an unknown quantity at this point 
Solved Threads: 0
Gaffer Sport Gaffer Sport is offline Offline
Newbie Poster

Re: Browser was Hijacked. Please help.

 
0
  #2
May 31st, 2005
http://www.soft32.com/download-CWShredder-19014-5.html

Download this, update once open and run.

Steve.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 5
Reputation: Sagan is an unknown quantity at this point 
Solved Threads: 0
Sagan Sagan is offline Offline
Newbie Poster

Re: Browser was Hijacked. Please help.

 
0
  #3
May 31st, 2005
I downloaded, updated, and ran the program. It did not find any problems. Any other suggestions?
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 23
Reputation: Gaffer Sport is an unknown quantity at this point 
Solved Threads: 0
Gaffer Sport Gaffer Sport is offline Offline
Newbie Poster

Re: Browser was Hijacked. Please help.

 
0
  #4
May 31st, 2005
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 5
Reputation: Sagan is an unknown quantity at this point 
Solved Threads: 0
Sagan Sagan is offline Offline
Newbie Poster

Re: Browser was Hijacked. Please help.

 
0
  #5
May 31st, 2005
Already ran that. It did not help. It found and fixed problems, only to have them reappear on reboot.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 23
Reputation: Gaffer Sport is an unknown quantity at this point 
Solved Threads: 0
Gaffer Sport Gaffer Sport is offline Offline
Newbie Poster

Re: Browser was Hijacked. Please help.

 
0
  #6
May 31st, 2005
Run it again but after it fixes the items, do not reboot. Just switch off at the wall. By doing it this way, you skip the standard windows shutdown procedure.

If this does not work, then visit:

http://www.short-media.com/forum/sho...d.php?p=172774
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 5
Reputation: Sagan is an unknown quantity at this point 
Solved Threads: 0
Sagan Sagan is offline Offline
Newbie Poster

Re: Browser was Hijacked. Please help.

 
0
  #7
May 31st, 2005
OK... I will try the alternate shutdown first and then try the web site. I will post back this evening with the results. Thanks for all of your help.

Sagan
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 5
Reputation: Sagan is an unknown quantity at this point 
Solved Threads: 0
Sagan Sagan is offline Offline
Newbie Poster

Re: Browser was Hijacked. Please help.

 
0
  #8
May 31st, 2005
The hard reboot didn't work, but the web pages instructions did!!! I am going to keep checking it for a few days, but I think it may have done the trick.

Thanks a great deal for your help!

Sagan
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 23
Reputation: Gaffer Sport is an unknown quantity at this point 
Solved Threads: 0
Gaffer Sport Gaffer Sport is offline Offline
Newbie Poster

Re: Browser was Hijacked. Please help.

 
0
  #9
May 31st, 2005
No probs, Bud. I am glad you seem to have got rid of it. They are nasty buggers.

Steve

---------

http://www.thegaffer.com
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 362
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Browser was Hijacked. Please help.

 
0
  #10
Jun 1st, 2005
Originally Posted by Sagan
The hard reboot didn't work, but the web pages instructions did!!! I am going to keep checking it for a few days, but I think it may have done the trick.

Thanks a great deal for your help!

Sagan
Can you please post a final log from HijackThis for us to review before we sign off on this one?

Removal procedures often fix the visible signs of infections, but there may still be dormant or "dangling" remainders which need to be taken care of.

Thanks.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum


Views: 1763 | Replies: 9
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC