Hijacker removal
From: Etan (anonymous_at_discussions.microsoft.com)
Date: 07/08/04
- Next message: Lawrence Abrams: "Re: how to remove this virus??"
- Previous message: Interrogative: "Re: ZoneAlarm ver 5.0.590.015"
- Next in thread: Lawrence Abrams: "Re: Hijacker removal"
- Reply: Lawrence Abrams: "Re: Hijacker removal"
- Reply: Kevin: "Re: Hijacker removal"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 8 Jul 2004 06:30:13 -0700
Dear expert,
My computer is attacked by a spyware and hijack program.
The symptomps are as follow :
1. Everytime I open website using internet explorer, it
open the pornsite.
2. The default/start page of internet explorer changes to
C:/windows/secure.html and I can not change the default
page.
3. My realtime protection scan notify me that hosts file
(c:/windows/system32/etc/drive/hosts) contain trojan
horse virus. This notification repeats and re-appear
continously.
I try to remove the hijacker using freeware
hijackthis.exe (download from :
http://www.spywareinfo.com/~merijn/files/hijackthis.zip).
And here is the log :
Kindly need your advise what component that I must remove.
Logfile of HijackThis v1.98.0
Scan saved at 8:27:22 PM, on 7/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Network ICE\BlackICE\blackd.exe
C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\DefWatch.exe
C:\WINDOWS\system32\acstp\icserv.exe
C:\WINDOWS\system32\acstp\wake_up.exe
C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\RSA Security\Web PassPort\Plug-
In\system\sdtray.exe
C:\Program Files\RSA Security\Web PassPort\Plug-
In\System\sdlss.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\WindowsSA\omniscient.exe
C:\WINDOWS\System32\lgihhh.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\ACNU\ACNUpdater.exe
C:\Documents and Settings\etananto.budiarto\Application
Data\oosm.exe
C:\WINDOWS\System32\hvhbxfsk.exe
C:\Program Files\Network ICE\BlackICE\blackice.exe
C:\Program Files\TurboNote\tbnote.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
c:\program files\acnu\acnupdatersvc.exe
C:\Program Files\Save\Save.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\taskmgr.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL
= http://www.omega-search.com/go/panel_search.html
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Bar =
http://www.couldnotfind.com/search_page.html?
&account_id=136299
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://www.couldnotfind.com/search_page.html?
&account_id=136299
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = C:\WINDOWS\secure.html
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
http://www.couldnotfind.com/search_page.html?
&account_id=136299
R1 - HKCU\Software\Microsoft\Internet
Explorer\SearchURL,SearchURL = http://www.omega-
search.com/go/panel_search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local
Page = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local
Page = C:\WINDOWS\secure.html
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=C:\Windows\System32
\wsaupdater.exe,
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-
7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1
\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0
\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {42A86E7C-CF3A-08C7-D127-
63550FA22C14} - C:\WINDOWS\System32\zaocqzro.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-
10AC9BABA46C} - C:\Program Files\Canon\Easy-
WebPrint\Toolband.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-
892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1
\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\RSA
Security\Web PassPort\Plug-In\system\sdtray.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1
\vptray.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI
Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program
Files\Support.com\bin\tgcmd.exe" /server /nosystray
O4 - HKLM\..\Run: [eSupInit] "C:\Program
Files\Support.com\bin\eSupCmd.exe" -inituser
O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\system32
\explorer.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1
\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1
\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1
\CookiePatrol.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program
Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [jbwguhxtvpytv] C:\WINDOWS\System32
\lgihhh.exe
O4 - HKLM\..\Run: [RunDLL]
rundll32.exe "C:\WINDOWS\Downloaded Program
Files\bridge.dll",Load
O4 - HKLM\..\Run: [jvtafqxjz] C:\WINDOWS\System32
\lgihhh.exe
O4 - HKLM\..\Run: [WhenUSave] "C:\Program
Files\Save\Save.exe"
O4 - HKLM\..\Run: [WhenUSearch] "C:\Program
Files\WhenUSearch\Search.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program
Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!
\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32
\ctfmon.exe
O4 - HKCU\..\Run: [Wcoe] C:\Documents and
Settings\etananto.budiarto\Application Data\oosm.exe
O4 - HKCU\..\Run: [Snj] C:\WINDOWS\System32\hvhbxfsk.exe
O4 - Global Startup: RealSecure(r) Desktop Protector.lnk
= ?
O4 - Global Startup: TurboNote.lnk = C:\Program
Files\TurboNote\tbnote.exe
O8 - Extra context menu item: &Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-
00010333D0AD} - C:\Program Files\Yahoo!
\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-
4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!
\Messenger\yhexbmes0521.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\MSMSGS.EXE
O12 - Plugin for .PDF: C:\Program Files\Internet
Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF:
START_PAGE_URL=https://portal.accenture.com
O15 - Trusted Zone: *.slotch.com
O16 - DPF: ppctlcab -
http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2F175895-5819-4014-83BF-385FA6833677}
(IObjSafety.eSupportWS) -
https://esupport.accenture.com/inc/download/IObjSafety.ocx
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13}
(PPSDKActiveXScanner.MainScreen) -
http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D}
(Autodesk MapGuide ActiveX Control) -
http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF}
(MediaTicketsInstaller Control) - http://www.mt-
download.com/MediaTicketsInstaller.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999}
(YAddBook Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suit
e/autocomplete.cab
O18 - Protocol: saphtmlp - {D1F8BD1E-7967-11D2-B43A-
006094B9EADB} - C:\Program
Files\SAP\FrontEnd\Controls\saphtmlp.dll
O18 - Protocol: sapr3 - {D1F8BD1E-7967-11D2-B43A-
006094B9EADB} - C:\Program
Files\SAP\FrontEnd\Controls\saphtmlp.dll
O21 - SSODL: System - {151AD395-08C5-4D0E-B833-
26487FA6FCB9} - C:\WINDOWS\system32\system32.dll
- Next message: Lawrence Abrams: "Re: how to remove this virus??"
- Previous message: Interrogative: "Re: ZoneAlarm ver 5.0.590.015"
- Next in thread: Lawrence Abrams: "Re: Hijacker removal"
- Reply: Lawrence Abrams: "Re: Hijacker removal"
- Reply: Kevin: "Re: Hijacker removal"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]