Jump to content


Photo

BHO is hijacking my home-page


  • This topic is locked This topic is locked
5 replies to this topic

#1 Cardinal23

Cardinal23

    Member

  • Full Member
  • Pip
  • 18 posts

Posted 30 June 2004 - 04:35 PM

In IE, under Tools, under Internet Options, on the Advanced tab is a checkbox labelled Enable third-party browser extensions (requires restart).

If I uncheck that checkbox (disabling BHOs), everything works fine... I can surf the Internet. My home page is not hijacked. However, if I check that checkbox (enabling BHOs), my home page is immediately hijacked.

How can I fix this problem?

Thank you.

#2 RubbeR DuckY

RubbeR DuckY

    Marcin

  • Developer
  • PipPipPipPipPip
  • 878 posts

Posted 30 June 2004 - 04:35 PM

Post a Hijack this log. Information is in my signature.
Marcin Kleczynski
Chief Executive Officer
Malwarebytes Corporation

Follow me on Twitter or check out my Blog!

#3 Cardinal23

Cardinal23

    Member

  • Full Member
  • Pip
  • 18 posts

Posted 30 June 2004 - 08:50 PM

Here is my HijackThis log. Thank you.

Logfile of HijackThis v1.97.7
Scan saved at 9:46:30 PM, on 6/30/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Expertcity\GoToMyPC\GoPCSrv.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\WINDOWS\iekv32.exe
C:\Program Files\Expertcity\GoToMyPC\goServer.exe
C:\Program Files\Expertcity\GoToMyPC\goPilot.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\sysaz.exe
C:\Program Files\Expertcity\GoToMyPC\GoTransS.exe
C:\Downloads\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gumbi.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://gumbi.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gumbi.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://gumbi.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\gumbi.dll/sp.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {B7F29FCD-FE2F-1C40-6E92-5E988DC57B26} - C:\WINDOWS\system32\mssi.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [GoToMyPC] C:\Program Files\Expertcity\GoToMyPC\GoPCSrv.exe -logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sysaz.exe] C:\WINDOWS\system32\sysaz.exe
O4 - HKLM\..\RunOnce: [javagk.exe] C:\WINDOWS\javagk.exe
O4 - HKLM\..\RunOnce: [iekv32.exe] C:\WINDOWS\iekv32.exe
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: SideStep (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.side...00719/sb028.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

#4 RubbeR DuckY

RubbeR DuckY

    Marcin

  • Developer
  • PipPipPipPipPip
  • 878 posts

Posted 30 June 2004 - 08:57 PM

Visit this page http://www.ducky.atribune.org . Download About:Buster and save it to your desktop. Then startup Hijack this. Tick the boxes next to these items.


O2 - BHO: (no name) - {B7F29FCD-FE2F-1C40-6E92-5E988DC57B26} - C:\WINDOWS\system32\mssi.dll
O4 - HKLM\..\Run: [sysaz.exe] C:\WINDOWS\system32\sysaz.exe
O4 - HKLM\..\RunOnce: [javagk.exe] C:\WINDOWS\javagk.exe
O4 - HKLM\..\RunOnce: [iekv32.exe] C:\WINDOWS\iekv32.exe


Then close all windows and hit fix checked. Start About:Buster. On the first prompt hit ok, then start, then ok again. It will run a while. Once it is done there will be a log in the white box. Save that log somewhere. Restart your computer. Post a new Hijack this log and the buster log.

If the fix does not work. Reboot into safe mode by tapping F8
Several times when the computer is first booting. Then running About:Buster.

Marcin Kleczynski
Chief Executive Officer
Malwarebytes Corporation

Follow me on Twitter or check out my Blog!

#5 Cardinal23

Cardinal23

    Member

  • Full Member
  • Pip
  • 18 posts

Posted 30 June 2004 - 10:08 PM

FIRST RUN OF ABOUT_BUSTER
About:Buster Version 1.23
Removed! : C:\WINDOWS\giwabb.dat
Removed! : C:\WINDOWS\iuowwh.dat
Removed! : C:\WINDOWS\vvfsqn.dat
Removed! : C:\WINDOWS\sdkbi32.dll
Removed! : C:\WINDOWS\n_drldbc.dat
Removed! : C:\WINDOWS\n_bpfbpw.dat
Removed! : C:\WINDOWS\xlynt.dat
Removed! : C:\WINDOWS\bqiyf.dat
Removed! : C:\WINDOWS\n_bikwzz.dat
Removed! : C:\WINDOWS\n_virqpv.dat
Removed! : C:\WINDOWS\n_wtwkzz.dat
Removed! : C:\WINDOWS\n_ywjkfr.dat
Removed! : C:\WINDOWS\n_hompdn.dat
Removed! : C:\WINDOWS\n_hgrsor.dat
Removed! : C:\WINDOWS\n_dzdowf.dat
Removed! : C:\WINDOWS\n_dgxnwq.dat
Removed! : C:\WINDOWS\n_eycigt.dat
Removed! : C:\WINDOWS\n_thrqps.dat
Removed! : C:\WINDOWS\n_jrrhom.dat
Removed! : C:\WINDOWS\javagk.exe
Removed! : C:\WINDOWS\n_zwlkxr.dat
Removed! : C:\WINDOWS\ihavr.dat
Removed! : C:\WINDOWS\gdizw.dat
Removed! : C:\WINDOWS\n_szhmdh.dat
Removed! : C:\WINDOWS\n_trmgnl.dat
Removed! : C:\WINDOWS\javaxn.exe
Removed! : C:\WINDOWS\atlit.exe
Removed! : C:\WINDOWS\sdkli.dll
Removed! : C:\WINDOWS\iekv32.exe
Removed! : C:\WINDOWS\fepgt.dat
Removed! : C:\WINDOWS\acytl.dll
Removed! : C:\WINDOWS\System32\vieha.dat
Removed! : C:\WINDOWS\System32\xtodn.dat
Removed! : C:\WINDOWS\System32\gexta.dat
Removed! : C:\WINDOWS\System32\hxdvl.dat
Removed! : C:\WINDOWS\System32\ujvsp.dat
Error Removing! : C:\WINDOWS\System32\sysaz.exe
Removed! : C:\WINDOWS\System32\gumbi.dll
Removed! : C:\WINDOWS\System32\somnm.dat
Removed! : C:\WINDOWS\System32\iuoww.dat
Removed! : C:\WINDOWS\System32\cpmnt.dat
Attempted Clean Of Temp folder.
Removed LEGACY___NS_Service_3 Key
Removed __NS_Service_3 Key
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!

SECOND RUN OF ABOUT_BUSTER (I pressed OK instead of Exit. Sorry...)
About:Buster Version 1.23
Removed! : C:\WINDOWS\giwabb.dat
Removed! : C:\WINDOWS\iuowwh.dat
Removed! : C:\WINDOWS\System32\sysaz.exe
Attempted Clean Of Temp folder.
Removed LEGACY___NS_Service_3 Key
Pages Reset... Done!

REBOOT

HIJACK_THIS LOG
Logfile of HijackThis v1.97.7
Scan saved at 10:57:07 PM, on 6/30/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Expertcity\GoToMyPC\GoPCSrv.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Expertcity\GoToMyPC\goServer.exe
C:\Program Files\Expertcity\GoToMyPC\goPilot.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Expertcity\GoToMyPC\GoTransS.exe
C:\Downloads\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.msn.com/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FBFA0821-F15D-97FF-D52D-E906EAEA0F99} - C:\WINDOWS\sdkli.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [GoToMyPC] C:\Program Files\Expertcity\GoToMyPC\GoPCSrv.exe -logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: SideStep (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.side...00719/sb028.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

THANK YOU.

#6 cnm

cnm

    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,317 posts

Posted 04 July 2004 - 11:15 AM

Closed - see http://www.spywarein...indpost&p=48653

Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here
UNITE





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button