Jump to content


Photo

Hijacked, I get redirected to res://mshp.dll/


  • Please log in to reply
19 replies to this topic

#1 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 08 June 2004 - 11:34 PM

I need help with my computer, it has been taken over with pop-up ads and my homepage keeps changing. I have read the FAQ section and I have also used SpyBot. It has worked for me in the past but now after SpyBot fixes the problems, they come back.

Sometimes the homepage is: res://mshp.dll/index.html#37049 Other times it is about:blank.

Ive pasted my Hijackthis log below. Thank you very much for anybody that can help me!




Logfile of HijackThis v1.97.7
Scan saved at 12:20:46 AM, on 6/9/2004
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINNT\Explorer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\wndcmd32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://mshp.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINNT\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://mshp.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\secure.html
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll
O2 - BHO: . - {D34F08C5-4F18-477c-86CB-1A9BEECFE37B} - C:\Documents and Settings\Administrator\Application Data\winch\winch.dll
O2 - BHO: ShowSearch module - {E2DDF680-9905-4dee-8C64-0A5DE7FE133C} - C:\Documents and Settings\Administrator\Application Data\winch\ntkd32.dll
O2 - BHO: (no name) - {FD9BC004-8331-4457-B830-4759FF704C22} - C:\Documents and Settings\Administrator\Application Data\winch\msiesh.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Image] rundll32 C:\WINNT\sdkqh32.dll,Install
O4 - HKCU\..\Run: [tm] wndcmd32.exe
O4 - HKCU\..\RunServices: [Image] rundll32 C:\WINNT\sdkqh32.dll,Install
O4 - Global Startup: America Online Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .nsf/GetResource: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.micr...922/wmv9VCM.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8090.3056018519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macrom...abs/swflash.cab

#2 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 09 June 2004 - 10:01 AM

Bump

Additional info:

Ive also used CWS shredder and I think it fixes part of the problem but the problem keeps coming back.

#3 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 09 June 2004 - 08:29 PM

Bump

#4 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 10 June 2004 - 10:52 AM

Bump

#5 bcollins

bcollins

    Member

  • Full Member
  • Pip
  • 8 posts

Posted 10 June 2004 - 11:32 AM

Got the exact same problem but it doesn't appear anyone knows what to do about it. If you get a repliy could you please let me know? :wave:

#6 bcollins

bcollins

    Member

  • Full Member
  • Pip
  • 8 posts

Posted 10 June 2004 - 11:37 AM

Just searched the file on Yahoo and came up with this: http://www.pchell.co...t/lookfor.shtml
Looks like it might help :bounce:

#7 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 10 June 2004 - 12:33 PM

Looking into it, thanks for the help!

#8 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 10 June 2004 - 01:57 PM

YAY!!!! I think I fixed it! That website helped alot! I just followed their steps except instead of iefeatsl.dll I think mine was winch.dll I also got rid a few .dll's that I saw was recent and had the same dates that were lurking in C://WINNT It seems to be running smoothly.

Id appreciate it if someone can take a look at my new HijackThis log and assure me that everything is okay. Thanks!


Logfile of HijackThis v1.97.7
Scan saved at 2:52:59 PM, on 6/10/2004
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\WINNT\Explorer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\wndcmd32.exe
C:\Documents and Settings\Administrator\Desktop\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINNT\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\secure.html
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: . - {D34F08C5-4F18-477c-86CB-1A9BEECFE37B} - C:\Documents and Settings\Administrator\Application Data\winch\winch.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [tm] wndcmd32.exe
O4 - HKCU\..\RunServices: [Image] rundll32 C:\WINNT\sdkqh32.dll,Install
O4 - Global Startup: America Online Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .nsf/GetResource: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.micr...922/wmv9VCM.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8090.3056018519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macrom...abs/swflash.cab

#9 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 10 June 2004 - 11:43 PM

Bump

#10 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 12 June 2004 - 10:15 AM

Bump

#11 salvation

salvation

    Member

  • Full Member
  • Pip
  • 28 posts

Posted 12 June 2004 - 10:25 AM

are you still having problems or did that website fix it? it doesn't seem like anyone on this site is replying to this problem. i posted a similar issue.

#12 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 12 June 2004 - 10:33 AM

I think the website helped me to fix it. Its running fine but I just wanted to make sure there arent any problems lurking that I cant see.

#13 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 12 June 2004 - 10:04 PM

Bump

#14 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 13 June 2004 - 11:06 AM

Bump

#15 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 13 June 2004 - 11:48 PM

Bump

#16 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 15 June 2004 - 12:23 PM

Bump

#17 ComputerTroubles

ComputerTroubles

    Member

  • Full Member
  • Pip
  • 14 posts

Posted 16 June 2004 - 11:58 AM

Bump

#18 rd_syringe

rd_syringe

    Member

  • Full Member
  • Pip
  • 20 posts

Posted 16 June 2004 - 12:11 PM

We're trying to figure it out in the other threads. There are like, 10 posted.

#19 zimmer

zimmer

    Member

  • New Member
  • Pip
  • 1 posts

Posted 16 June 2004 - 12:17 PM

I had the same problem and tried all the suggestions to no avail.

A co-worker suggested the following:

one is to download and run http://www.ad25.com/Uninstall.exe - apparently it's an uninstall program from the company that makes the pop-up

seemed to work for me.

#20 BREDDICK

BREDDICK

    Member

  • Full Member
  • Pip
  • 5 posts

Posted 16 June 2004 - 12:31 PM

I had the same problem and tried all the suggestions to no avail.

A co-worker suggested the following:

one is to download and run http://www.ad25.com/Uninstall.exe - apparently it's an uninstall program from the company that makes the pop-up

seemed to work for me.

I tried to download but it says my settings will not allow to download.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button