|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
Generate data entry and reporting .NET Web apps in minutes, straight from your database. Read our FREE whitepaper “Build Web 2.0 Applications Without Hand-Coding” Download now! |
|
#1
|
|||
|
|||
|
IE hijacked by serach.com
My IE has been hijacked by search.com. Using Spybot Search and Destroy suppresses the hijack temporarily but it returns periodically - not only to hijack my home page, but it puts toolbars on my IE, interferes with IE web page loading; fills up my Favorites with crap; etc. I ran Hijackthis and got the following log. Can anyone tell me what to do next?
Logfile of HijackThis v1.97.7 Scan saved at 10:56:18 AM, on 9/8/2004 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe C:\WINNT\System32\PackethSvc.exe C:\WINNT\System32\svchost.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe C:\WINNT\system32\regsvc.exe C:\Program Files\Dantz\Retrospect\Launcher.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\stisvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINNT\System32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\Program Files\Dell\Solution Center\service.exe C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe C:\PROGRA~1\Adaptec\DirectCD\directcd.exe C:\Program Files\Winamp3\winampa.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\HP\HP Software Update\HPWuSchd.exe C:\Program Files\Netropa\Multimedia Keyboard\mmusbkb2.exe C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Netropa\Onscreen Display\OSD.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\wuauclt.exe c:\progra~1\intern~1\iexplore.exe C:\winnt\temp\LOerhizEv.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\documents and settings\administrator\local settings\temp\n.exe C:\Program Files\Internet Explorer\iexplore.exe C:\documents and settings\administrator\local settings\temp\2.exe C:\WINNT\system32\ctfmon.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe C:\America Online 6.0\aoltray.exe C:\WINNT\SYSTEM32\mapiicon.exe C:\Palm\HOTSYNC.EXE C:\WINNT\DownloadWizard\DownloadWizard.exe C:\WINNT\System32\HPZipm12.exe C:\Program Files\AnalogX\POW\pow.exe C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\TKLAF77J\HijackThis[1].exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lexis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.lexis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.ppgllswxepbfkpdswdlmqotwg.info/gSE95T8dODK6Fd0esMKpiROb5ECfVJ/Kk7TFfvfdNSIoubJ2xI4wSdYOJHreB_L4.html R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.lexis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa O2 - BHO: (no name) - {27557CF1-A237-496D-8C8F-08F3844C6A8B} - (no file) O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Administrator\Local Settings\Temp\tDP1.dll O2 - BHO: (no name) - {FC592840-E20C-0CE4-1E5B-1A8119E2C307} - C:\PROGRA~1\INTERN~2\EGGS FIND.exe O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off O4 - HKLM\..\Run: [DellSC] C:\Program Files\Dell\Solution Center\service.exe O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe O4 - HKLM\..\Run: [ADSL_A2] A2Installed O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [peakspam] C:\PROGRA~1\SEEKRE~1\amok road.exe O4 - HKLM\..\Run: [LOerhizEv] C:\winnt\temp\LOerhizEv.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [n] C:\documents and settings\administrator\local settings\temp\n.exe O4 - HKLM\..\Run: [2] C:\documents and settings\administrator\local settings\temp\2.exe O4 - HKLM\..\Run: [01greyheckdefy] C:\Documents and Settings\All Users\Application Data\HTMLIES01GREY\CityJunk.exe O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe O4 - Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe O4 - Startup: America Online 6.0 Tray Icon.lnk = C:\America Online 6.0\aoltray.exe O4 - Startup: ADSL Diagnostic Tools.LNK = C:\WINNT\SYSTEM32\mapiicon.exe O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE O4 - Startup: eBot.lnk = C:\WINNT\DownloadWizard\DownloadWizard.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O4 - Global Startup: CorelCENTRAL 10.lnk = C:\Program Files\Corel\WordPerfect Office 2002\Programs\CCWin10.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP OfficeJet Startup.lnk.disabled O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Net2Phone (HKLM) O9 - Extra 'Tools' menuitem: Net2Phone (HKLM) O9 - Extra button: Real.com (HKLM) O12 - Plugin for .efp: C:\Program Files\Internet Explorer\Plugins\NPEFPrn.dll O12 - Plugin for .efv: C:\Program Files\Internet Explorer\Plugins\NPEFV.dll O12 - Plugin for .fmp: C:\Program Files\Internet Explorer\Plugins\NPFMP.dll O12 - Plugin for .fmr: C:\Program Files\Internet Explorer\Plugins\NPFME.dll O12 - Plugin for .ifx: C:\Program Files\Internet Explorer\Plugins\NPWebPrn.dll O12 - Plugin for .lfx: C:\Program Files\Internet Explorer\Plugins\NPLaunch.dll O12 - Plugin for .mwp: C:\Program Files\Internet Explorer\Plugins\NPMWPrn.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O12 - Plugin for .tif: C:\Program Files\Internet Explorer\Plugins\NPTVP.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {0FF3E97F-433D-11D2-B31A-00A0C9B135DB} (CoDetectDigitalRiver Class) - http://ebot.digitalriver.com/v2.0-doc/dlwizard/wizard3.0.4.3.cab O16 - DPF: {12589FA1-C456-11CE-BF01-10AA1055595A} - http://www.wsel.net/imcupdatefiles/whistlesilent610.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab O16 - DPF: {18B01F09-2965-11D3-9461-00A0C9B1E042} (FunnyVoiceCtl Class) - http://www.kiddonet.com/kiddonet/luvclicks2/FunnyVoice.ocx O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/22085c3c3e6563515220/netzip/RdxIE6.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38027.3096180556 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{291886B5-6B6F-4831-80E3-7A11F5AF33EE}: NameServer = 63.203.35.55,206.13.28.12 |
|
#2
|
||||
|
||||
|
How about upgrading IE, installing all service and security patches for IE and your OS (I hope you are using Win2K or XP, if not, upgrade or stop whining about security) and running your browser at at least medium security (I typically browse at high).
__________________
Left DevShed May 28, 2005. Reason: Unresponsive administrators. Free code: http://sol-biotech.com/code/. Secure Programming: http://sol-biotech.com/code/SecProgFAQ.html. Performance Programming: http://sol-biotech.com/code/PerformanceProgramming.html. It is not that old programmers are any smarter or code better, it is just that they have made the same stupid mistake so many times that it is second nature to fix it. --Me, I just made it up The reasonable man adapts himself to the world; the unreasonable one persists in trying to adapt the world to himself. Therefore, all progress depends on the unreasonable man. --George Bernard Shaw |
|
#4
|
||||
|
||||
|
You posted this thread twice - please don't cross post in the future. I've moved the thread which already had some replies (this one) into the correct forum and deleted the other one.
|
|
#5
|
|||
|
|||
|
Try the new Windows Firewall. Might help.
|
|
#6
|
|||
|
|||
|
What to do with hijack this log
Let me rephrase the question a bit more precisely. Does anyone know how to use the hijackthis log to fix the problem. If not, spare me the preaching about other workarounds.
|
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > IE hijacked by serach.com |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|