943,699 Members | Top Members by Rank

Ad:
May 31st, 2005
0

Browser was Hijacked. Please help.

Expand Post »
First, let me thank anyone who is willing to try an help me. I have tried to fix this for the past 3 hours and it keep coming back. It seems to be related to this stupid Home Search proggy and something called Shopping Wizard. I am unable to remove them from the add/remove programs box. I have also tried following the directions on a post from March of this year regarding the Home Search program to no avail. I have HiJackThis, About:Buster, HSRemove, and Spybot S&D already on my machine. Here is my hijack this log. Any help at all is appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 11:33:51 AM, on 5/31/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\System32\3Com_DMI\3CDMINIC.EXE
C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\DMI\WIN32\bin\DellDmi.exe
C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
C:\Program Files\Dell\OpenManage\Client\DLT.exe
C:\WINNT\SYSTEM32\DWRCS.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\dmi\win32\bin\Win32sl.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\ntvn.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\system32\LXSUPMON.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\system32\iehq.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\twsys.dll/sp.html#55135
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\twsys.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\twsys.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\twsys.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\twsys.dll/sp.html#55135
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\twsys.dll/sp.html#55135
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {E242AD05-F49E-8697-B586-6E43C236C954} - C:\WINNT\msxg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINNT\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iehq.exe] C:\WINNT\system32\iehq.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab34246.cab
O16 - DPF: {D1ACD2D8-7312-4D06-BECD-90EB094D2277} - http://mediaplayer.walmart.com/installer/install.cab
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\netah.exe (file missing)
O23 - Service: 3Com DMI Agent (3ComDMIService) - 3Com Corporation - C:\WINNT\System32\3Com_DMI\3CDMINIC.EXE
O23 - Service: ActionAgent - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: DellDmi - Dell Computer Corporation - C:\DMI\WIN32\bin\DellDmi.exe
O23 - Service: DEventAgent - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
O23 - Service: DLT - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\DLT.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: Win32Sl - Intel - C:\dmi\win32\bin\Win32sl.exe

Thanks again for any help you can provide.

Sagan
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Sagan is offline Offline
5 posts
since May 2005
May 31st, 2005
0

Re: Browser was Hijacked. Please help.

http://www.soft32.com/download-CWShredder-19014-5.html

Download this, update once open and run.

Steve.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Gaffer Sport is offline Offline
23 posts
since May 2005
May 31st, 2005
0

Re: Browser was Hijacked. Please help.

I downloaded, updated, and ran the program. It did not find any problems. Any other suggestions?
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Sagan is offline Offline
5 posts
since May 2005
May 31st, 2005
0

Re: Browser was Hijacked. Please help.

Reputation Points: 10
Solved Threads: 0
Newbie Poster
Gaffer Sport is offline Offline
23 posts
since May 2005
May 31st, 2005
0

Re: Browser was Hijacked. Please help.

Already ran that. It did not help. It found and fixed problems, only to have them reappear on reboot.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Sagan is offline Offline
5 posts
since May 2005
May 31st, 2005
0

Re: Browser was Hijacked. Please help.

Run it again but after it fixes the items, do not reboot. Just switch off at the wall. By doing it this way, you skip the standard windows shutdown procedure.

If this does not work, then visit:

http://www.short-media.com/forum/sho...d.php?p=172774
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Gaffer Sport is offline Offline
23 posts
since May 2005
May 31st, 2005
0

Re: Browser was Hijacked. Please help.

OK... I will try the alternate shutdown first and then try the web site. I will post back this evening with the results. Thanks for all of your help.

Sagan
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Sagan is offline Offline
5 posts
since May 2005
May 31st, 2005
0

Re: Browser was Hijacked. Please help.

The hard reboot didn't work, but the web pages instructions did!!! I am going to keep checking it for a few days, but I think it may have done the trick.

Thanks a great deal for your help!

Sagan
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Sagan is offline Offline
5 posts
since May 2005
May 31st, 2005
0

Re: Browser was Hijacked. Please help.

No probs, Bud. I am glad you seem to have got rid of it. They are nasty buggers.

Steve

---------

http://www.thegaffer.com
Reputation Points: 10
Solved Threads: 0
Newbie Poster
Gaffer Sport is offline Offline
23 posts
since May 2005
Jun 1st, 2005
0

Re: Browser was Hijacked. Please help.

Quote originally posted by Sagan ...
The hard reboot didn't work, but the web pages instructions did!!! I am going to keep checking it for a few days, but I think it may have done the trick.

Thanks a great deal for your help!

Sagan
Can you please post a final log from HijackThis for us to review before we sign off on this one?

Removal procedures often fix the visible signs of infections, but there may still be dormant or "dangling" remainders which need to be taken care of.

Thanks.
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: VX2 and lots of other nasties ...
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: msn messenger and IE error





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC