PDA

View Full Version : Help! Damn Browser Hijack



nameless_one
2007-08-19, 10:41
Hi all.

I've noticed the last week or so that when I tried to open a few bookmarks, I was sent to miscellanious sites instead. (you know when a site shuts down & the domain is taken up by a search-engine/advertising site, usually with a big picture and a list of 'popular searches', usually related to the previous site?)

Anyway, someone said it sounded like hijacking, which brought me straight here.

I've used your "SpyAxe, SpySheriff, Winhound, Spywarestrike" instructions which I already had saved and have run through all the steps.

I just want to confirm that I've done everything properly and there's nothing I've missed (and that I've used the right set of instructions).

Oh, and the instructions (from 2006) say to use Ewido, but when I looked on their site, they had merged with AVG - and the latest version is apparently "AVG Anti-Spyware 7.5", which I used.
I hope that's ok.

Here are the logfiles the instructions say to include:
(will post in the reply)
---

* So you don't get confused, there are 2 Ewido/AVG logs because I screwed the first one up (I told it to stop quarantining whole zipfiles because I wanted to find their locations after the AVG had quarantined everything else, but didn't realise I'd have to do a second scan just to be able to see the 'filepaths' of what AVG had found - (it doesn't show you the 'filepaths' once it's finished performing 'actions' on what it's found during the search))

-1st Ewido (AVG Anti-Spyware 7.5) log:


** Sorry again, both of these AVG scan reports are way too long (2x 4mb txt files!!).
I tried to submit this whole post and was told to shorten it from (4073110 characters -!!) to 20000 characters.

If / when someone reads and is willing to help, let me know how I can send you the 2 AVG scan reports (I used winrar to zip one from 4.5mb to 63kb for example)
Anyway, please let me know how I can send them to you or submit them to the forum somewhere.

---


** Sorry again, both of the AVG scan reports are way too long (2x 4mb txt files!!). :rolleyes:
I tried to submit this whole post and was told to shorten it from (4073110 characters -!!) to 20000 characters.

If / when someone reads and is willing to help, let me know how I can send you the 2 AVG scan reports (I used winrar to zip one from 4.5mb to 63kb for example)
Anyway, please let me know how I can send them to you or submit them to the forum somewhere.


That's everything.
Please let me know if I've missed anything or used the wrong instructions or anything like that.

Thanks.

nameless_one
2007-08-19, 11:03
Hi all.

I've noticed the last week or so that when I tried to open a few bookmarks, I was sent to miscellanious sites instead. (you know when a site shuts down & the domain is taken up by a search-engine/advertising site, usually with a big picture and a list of 'popular searches', usually related to the previous site?)

Anyway, someone said it sounded like hijacking, which brought me straight here.

I've used your "SpyAxe, SpySheriff, Winhound, Spywarestrike" instructions which I already had saved and have run through all the steps.

I just want to confirm that I've done everything properly and there's nothing I've missed (and that I've used the right set of instructions).

Oh, and the instructions (from 2006) say to use Ewido, but when I looked on their site, they had merged with AVG - and the latest version is apparently "AVG Anti-Spyware 7.5", which I used. I hope that's ok.

I'll post the 1st HijackThis Log, but the rest of the logs were too long and it wouldn't let me post them as well, so I'll have to wait for further instructions I guess.

Here's the 1st HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 3:03:21 AM, on 17/08/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\Program Files\Microsoft Office\Office\OSA.EXE
E:\Documents and Settings\Dave\Start Menu\Programs\Startup\ms.exe
E:\WINDOWS\System32\wuauclt.exe
E:\WINDOWS\system32\NOTEPAD.EXE
E:\Program Files\Hijackthis\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {93035429-6FC5-FD53-2B93-883F6B702624} - E:\WINDOWS\vkikq1.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - E:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "E:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [RegKillElbyCheck] "E:\My Documents\Tim's Stuff\Guitar Pro\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "E:\My Documents\Tim's Stuff\Guitar Pro\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [googletalk] "E:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - Startup: Metacafe.lnk = E:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Startup: ms.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Metacafe.lnk = E:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Microsoft Find Fast.lnk = E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = E:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: Download All Files by HiDownload - E:\Program Files\HiDownload\HDGetAll.htm
O8 - Extra context menu item: Download by HiDownload - E:\Program Files\HiDownload\HDGet.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - E:\Program Files\HiDownload\hidownload.exe
O12 - Plugin for .spop: E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{07EA85F8-67A7-4FE2-9541-9A0217975B4C}: NameServer = 85.255.115.27,85.255.112.181
O17 - HKLM\System\CCS\Services\Tcpip\..\{DBC92D49-1FDB-4629-A5ED-47D49B1C7FA8}: NameServer = 85.255.115.27,85.255.112.181
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = vic.bigpond.net.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.181
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe

Mr_JAk3
2007-08-19, 20:48
Hi nameless_one :)

You're badly infected. One or more of the identified infections is a backdoor trojan with rootkit function, very dangerous :sick:

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the infection has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? (http://www.dslreports.com/faq/10451)
When Should I Format, How Should I Reinstall (http://www.dslreports.com/faq/10063)

I can help you in the cleaning if you don't want to reformat but there is a possibility that we can't get you 100% clean.

Please let us know what you have decided to do in your next post:bigthumb: