My browser is hijacked

Discussion in 'adware, spyware & hijack cleaning' started by mahawan, Apr 7, 2004.

Thread Status:
Not open for further replies.
  1. mahawan

    mahawan Registered Member

    Joined:
    Apr 6, 2004
    Posts:
    4
    Hi there,

    My browser seems to be hijacked. I have read helps posted here but experts say that I should post my own log here. I have used CWShredder & remove everything suspicious. I include the log from hijackThis below, not sure if it is clean or not. Any help would be appreciated.
    Thanks.

    Iwan

    Logfile of HijackThis v1.97.7
    Scan saved at 14:53:11, on 2004/04/07
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\LTSMMSG.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\WINDOWS\System32\ctfmon.exe
    D:\Freeware\vd_0898\VD.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\System32\conime.exe
    D:\Freeware\xyzzy-0.2.2.233\xyzzy.exe
    C:\Documents and Settings\mahawan\Local Settings\Temp\hijackthis.zip の一時ディレクトリ 3\HijackThis.exe

    F0 - syst>m.ini: Shell=
    F0 - R   >ystem.ini: Shel>=
    F0 - R   >ystem.ini: UserInit=
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
    O3 - Toolbar: o_O?? - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [DialApp] C:\Program Files\SHARP\mt\3.2\bin\DialMng.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - Startup: .xyzzy
    O4 - Startup: aboutus.txt
    O4 - Startup: NTUSER.DAT
    O4 - Startup: ntuser.dat.LOG
    O4 - Startup: ntuser.ini
    O4 - Startup: PUTTY.RND
    O4 - Startup: ~
    O4 - Global Startup: NTUSER.DAT
    O4 - Global Startup: NTUSER.DAT.LOG
    O8 - Extra context menu item: FlashGetでダウンロード - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: FlashGetで全てダウンロード - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: SHARP ぺたっ!翻訳 - res://C:\Program Files\Sharp\PowerEJ\BIN\QuickTrans.ocx/234
    O8 - Extra context menu item: この画像を取込み(&I) - C:\Program Files\Internet Ninja 2001\GetImg.htm
    O8 - Extra context menu item: 選択範囲を取込み(&S) - C:\Program Files\Internet Ninja 2001\GetPart0.htm
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: FlashGet (HKLM)
    O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://www.spacetown.ne.jp/
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
     
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    Hi mahawan,

    You did remove so much that it is hard to diagnose anything.
    Can you tell us the site you were hijacked to?

    Regards,

    Pieter
     
  3. mahawan

    mahawan Registered Member

    Joined:
    Apr 6, 2004
    Posts:
    4
    Thanks for the reply Pieter,
    I'm not sure which site towhere I was hijacked, but my IE's default homepage was changed to C:\Windows\secure.html (telling something like spyware...). There were secure.html & securea.html, I've been removed both.
    Now I have pop up window that appears periodically saying like 'Picasa ...'.

    rgds,
    Mahawan
     
  4. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    Hi mahawan,

    Check for the presence of reg32.exe and/or reg33.exe in your Windows folder. If found delete them.

    Then download and run: http://www.spywareinfoforum.com/~merijn/files/CWShredder.exe
    Use the Fix button and follow the instructions you will receive.

    Do you know what this is?
    D:\Freeware\xyzzy-0.2.2.233\xyzzy.exe (a CD called Freeware as it would seem, but I'm getting paranoid)

    Regards,

    Pieter
     
  5. mahawan

    mahawan Registered Member

    Joined:
    Apr 6, 2004
    Posts:
    4
    Thanks, Pieter

    Fortunately I couldn't found reg32.exe and reg33.exe in my Windows folder. I have run CWShredder 5-6 times, and it always find the CWS variant and everytime it says "A CWS variant was detected that is still loaded into memory. You need to restart your system and run CWShredder again to remove it completely".

    D:\Freeware\xyzzy-0.2.2.233\xyzzy.exe is ok. It is my favorite text editor ... I don't use notepad ;)
     
  6. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    What version of CWShredder did you use?
    Version 1.56.0 is the latest.

    Regards,

    Pieter
     
  7. mahawan

    mahawan Registered Member

    Joined:
    Apr 6, 2004
    Posts:
    4
    Hi Pieter,
    Sorry for the late response, I slept like a log last night & now is in the morning here.
    I'm using CWShredder ver. 1.55, downloaded yesterday. I tried to update using 'check for update' button without no success. FYI, I use WinXP Japanese version.

    I include the latest hijackThis log after using CWShredder (1.55), below. Hopefully it is clean.

    rgds.


    Logfile of HijackThis v1.97.7
    Scan saved at 8:37:11, on 2004/04/08
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\LTSMMSG.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\WINDOWS\System32\ctfmon.exe
    D:\Freeware\vd_0898\VD.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\mahawan\Local Settings\Temp\hijackthis.zip の一時ディレクトリ 2\HijackThis.exe

    F0 - syst>m.ini: Shell=
    F0 - R   >ystem.ini: Shel>=
    F0 - R   >ystem.ini: UserInit=
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
    O3 - Toolbar: o_O?? - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [DialApp] C:\Program Files\SHARP\mt\3.2\bin\DialMng.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - Startup: .xyzzy
    O4 - Startup: aboutus.txt
    O4 - Startup: NTUSER.DAT
    O4 - Startup: ntuser.dat.LOG
    O4 - Startup: ntuser.ini
    O4 - Startup: PUTTY.RND
    O4 - Startup: ~
    O4 - Global Startup: NTUSER.DAT
    O4 - Global Startup: NTUSER.DAT.LOG
    O8 - Extra context menu item: FlashGetでダウンロード - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: FlashGetで全てダウンロード - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: SHARP ぺたっ!翻訳 - res://C:\Program Files\Sharp\PowerEJ\BIN\QuickTrans.ocx/234
    O8 - Extra context menu item: この画像を取込み(&I) - C:\Program Files\Internet Ninja 2001\GetImg.htm
    O8 - Extra context menu item: 選択範囲を取込み(&S) - C:\Program Files\Internet Ninja 2001\GetPart0.htm
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: FlashGet (HKLM)
    O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://www.spacetown.ne.jp/
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{30E8612F-93B3-467A-9B46-47DD8BAD2398}: NameServer = 202.158.3.7 202.158.3.6
     
Thread Status:
Not open for further replies.