1
   

browser hijack

 
 
jeff518
 
Reply Tue 18 May, 2004 12:38 am
my web browser has been hijacked with the website http://any-find.com/index.htm

I ran ad-aware and it fixed the things with "any-find.com" in them, I then ran Hijack-this and found the "any-find.com" software, I used the "fix checked" box for the links, restarted the computer and my browser is still set to "http://any-find.com/index.htm" even after resetting the browser before the restart.

I just ran Hijack-this and here's the log:

Logfile of HijackThis v1.97.7
Scan saved at 2:33:32 AM, on 5/18/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\LVComS.exe
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\winnt\dllhelp.exe
C:\WINNT\twain_32\A4S2600X\WATCH.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\ADMINI~1.JEN\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://any-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://any-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://any-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://any-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://any-find.com/index.htm
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LVCOMS] C:\WINNT\System32\LVComS.exe
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [dllhelp] c:\winnt\dllhelp.exe
O4 - Startup: Watch.lnk = C:\WINNT\twain_32\A4S2600X\WATCH.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38026.8486111111
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = novocon.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{17CAAAA1-E084-404E-B7FA-305CC067BFAB}: NameServer = 64.80.15.4 64.80.15.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = novocon.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 64.80.15.2
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = novocon.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 64.80.15.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 64.80.15.2


help with getting rid of this software is extremely appreciated!!
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,576 • Replies: 3
No top replies

 
Nirvana
 
  1  
Reply Tue 18 May, 2004 06:11 am
Hi Jeff, you are running HijackThis from a temporary location which means no backups will be stored in the event you 'fix' something which is needed.

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Move HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary. Please delete the old copy so it can't be used.

You have a CoolWebSearch infection, download, update and run
CWShredder
Click Fix, don't just scan. Let it fix everything it asks about.

Then go to Windows Update and scan then download ALL of the critical updates.

Reboot then scan with Adaware again then post a fresh log as there may be more to do.
0 Replies
 
jeff518
 
  1  
Reply Fri 21 May, 2004 02:17 am
alright I did exactly as you said, here's the new log:

Logfile of HijackThis v1.97.7
Scan saved at 4:10:16 AM, on 5/21/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\LVComS.exe
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\PROGRA~1\AIM95\aim.exe
C:\winnt\dllhelp.exe
C:\WINNT\twain_32\A4S2600X\WATCH.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://any-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://any-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://any-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://any-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://any-find.com/index.htm
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LVCOMS] C:\WINNT\System32\LVComS.exe
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [dllhelp] c:\winnt\dllhelp.exe
O4 - Startup: Watch.lnk = C:\WINNT\twain_32\A4S2600X\WATCH.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38026.8486111111
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = novocon.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{17CAAAA1-E084-404E-B7FA-305CC067BFAB}: NameServer = 64.80.15.4 64.80.15.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = novocon.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 64.80.15.2
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = novocon.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 64.80.15.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 64.80.15.2


browser still remains the same....HELP
0 Replies
 
Nirvana
 
  1  
Reply Fri 21 May, 2004 04:51 am
Restart HijackThis and put checks next to the following, close all browser windows (including this one) then click on 'Fix Checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://any-find.com/sp.htm <http://www.able2know.com/go/?a2kjump=http%3A%2F%2Fany-find.com%2Fsp.htm>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://any-find.com/index.htm <http://www.able2know.com/go/?a2kjump=http%3A%2F%2Fany-find.com%2Findex.htm>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://any-find.com/index.htm <http://www.able2know.com/go/?a2kjump=http%3A%2F%2Fany-find.com%2Findex.htm>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://any-find.com/sp.htm <http://www.able2know.com/go/?a2kjump=http%3A%2F%2Fany-find.com%2Fsp.htm>
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://any-find.com/index.htm <http://www.able2know.com/go/?a2kjump=http%3A%2F%2Fany-find.com%2Findex.htm>



O4 - HKCU\..\Run: [dllhelp] c:\winnt\dllhelp.exe

Make sure you have Set Windows to show Hidden Files & Folders, then reboot intosafe mode then find and delete the following in bold:

O4 - HKCU\..\Run: [dllhelp] c:\winnt\dllhelp.exe

Reboot, then run CWShredder again, making sure you first check for updates. When you run CWShredder make sure you press 'fix' and not 'scan'.

Post a fresh log when you're done.
0 Replies
 
 

Related Topics

YouTube Is Doomed - Discussion by Shapeless
So I just joined Facebook.... - Discussion by DrewDad
Internet disinformation overload - Discussion by rosborne979
Participatory Democracy Online - Discussion by wandeljw
OpenDNS and net neutrality - Question by Butrflynet
Internet Explorer 8? - Question by Pitter
 
  1. Forums
  2. » browser hijack
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.04 seconds on 09/29/2024 at 12:21:56