start page hijack

  1. #1
    pooly is offline Newbie

    start page hijack

    Hi,

    my start page and blank page are hijacked. Here is the log :


    Logfile of HijackThis v1.99.1
    Scan saved at 1236, on 18/07/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\System32\mgabg.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\PDesk.exe
    C:\WINNT\system32\rundll32.exe
    C:\WINNT\system32\internat.exe
    C:\Program Files\Sky Alerts\skinkers.exe
    C:\WINNT\system32\wuauclt.exe
    C:\Program Files\ClamWin\bin\ClamTray.exe
    C:\PROGRA~1\WinZip\winzip32.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {0F286208-E541-4D5C-9628-8DAA670350E2} - C:\WINNT\system32\kgfd.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\System32\PDesk.exe /Autolaunch
    O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
    O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInsta ll
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - HKCU\..\Run: [Sky Alerts] C:\Program Files\Sky Alerts\skinkers.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {08F04139-8DFC-11D2-80E9-006008B066EE} (ConfigChkr Class) - https://onsite.trustwise.com/service...V/vscnfchk.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F53A2AAD-9CC1-4B14-AF30-33231A1DB224}: NameServer = 217.15.170.221
    O18 - Filter: text/html - {0B0887D9-3B5D-48D5-B879-3FD5DC8DF77B} - C:\WINNT\system32\kgfd.dll
    O18 - Filter: text/plain - {0B0887D9-3B5D-48D5-B879-3FD5DC8DF77B} - C:\WINNT\system32\kgfd.dll
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\System32\mgabg.exe


    can someone help me ? thanks very much in advance.


  2. #2
    HJThis is offline Senior Member
    Hello,Pooly & Welcome

    The first thing we need from you is to move HijackThis from the
    Temp folder it's in to a folder in C:\Drive like so C:\HJT
    once you do that do this here

    Download CW-Shredder at the link below:
    http://www.isecurity.org.uk/downloads/cwshredder.exe

    Download SpSeHjfix here:
    http://www.derbilk.de/SpSeHjfix112.zip
    Save it to the desktop and then right click a blank part of desktop & select new folder, call it spfix. Unzip the file into that folder

    Disconnect from the net and Close ALL OPEN PROGRAMS.
    Run 'SpSeHjfix'. and click on "Start Disinfection".
    When it's finished it will reboot your machine to finish the cleaning process.
    The tool creates a log of the fix which will appear in the folder.

    If it doesn't find any of the SE files or any hidden reinstallers it will say system clean and not go on to next stage

    Now run the CWShredder - Hit The FIX button!

    i also need you to do this

    click start->settings->control panel->internet options->programs tab->RESET WEB SETTINGS

    That will change everything back to defaults (M$)......

    Change your homepage and search engines to whatever you wish and reset your pc.

    When it boots back up, open IE and see if the page stays the way that you set it.

    & get this here out of the way

    Make your Internet Explorer more secure - This can be done by following these simple instructions:

    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
    1. Change the Download signed ActiveX controls to Prompt
    2. Change the Download unsigned ActiveX controls to Disable
    3. Change the Initialize and script ActiveX controls not marked as safe to Disable
    4. Change the Installation of desktop items to Prompt
    5. Change the Launching programs and files in an IFRAME to Prompt
    6. Change the Navigate sub-frames across different domains to Prompt
    7. When all these settings have been made, click on the OK button.
    8. If it prompts you as to whether or not you want to save the settings, press the Yes button.
    5. Next press the Apply button and then the OK to exit the Internet Properties page.

    Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.

    HGD
    Last edited by HJThis; 18-07-2005 at 01:45 PM.

  3. #3
    pooly is offline Newbie
    Hi,

    it worked like a charm !
    thank you very much.

  4. #4
    HJThis is offline Senior Member
    Hi,pooly

    Hold on now lit's not start jumping just yet i need to see one more
    logfile there maybe more work to do here & i may need you to download
    some progs here to help keep this stuff away.

    so get back here

    HGD

  5. #5
    pooly is offline Newbie
    Hi, here is the HJT log :

    Logfile of HijackThis v1.99.1
    Scan saved at 09:43:46, on 22/07/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\System32\mgabg.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\PDesk.exe
    C:\Program Files\ClamWin\bin\ClamTray.exe
    C:\WINNT\system32\internat.exe
    C:\Program Files\Sky Alerts\skinkers.exe
    C:\WINNT\system32\wuauclt.exe
    C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
    C:\Program Files\ClamWin\bin\OlAddin.exe
    C:\Program Files\FutureSource\Workstation\AvalancheUI.exe
    C:\PROGRA~1\MOZILL~1\firefox.exe
    C:\hjt\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\System32\PDesk.exe /Autolaunch
    O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - HKCU\..\Run: [Sky Alerts] C:\Program Files\Sky Alerts\skinkers.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {08F04139-8DFC-11D2-80E9-006008B066EE} (ConfigChkr Class) - https://onsite.trustwise.com/service...V/vscnfchk.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F53A2AAD-9CC1-4B14-AF30-33231A1DB224}: NameServer = 217.15.170.221
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\System32\mgabg.exe


    And the SPsehjfix log :




    (7/18/05 14:15:02) SPSeHjFix started v1.1.2
    (7/18/05 14:15:02) OS: Win2000 Service Pack 4 (5.0.2195)
    (7/18/05 14:15:02) Language: english
    (7/18/05 14:15:02) Win-Path: C:\WINNT
    (7/18/05 14:15:02) System-Path: C:\WINNT\system32
    (7/18/05 14:15:02) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
    (7/18/05 14:15:12) Disinfection started
    (7/18/05 14:15:12) Bad-Dll(IEP): c:\docume~1\admini~1\locals~1\temp\se.dll
    (7/18/05 14:15:12) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINNT\system32\kgfd.dll
    (7/18/05 14:15:12) Searchassistant Uninstaller - Keys Deleted
    (7/18/05 14:15:12) UBF: 9 - UBB: 3 - UBR: 5
    (7/18/05 14:15:12) FilterKey: HKCR\text/html (deleted)
    (7/18/05 14:15:12) FilterKey: HKCR\CLSID\{0B0887D9-3B5D-48D5-B879-3FD5DC8DF77B} (deleted)
    (7/18/05 14:15:12) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
    (7/18/05 14:15:12) FilterKey: HKCR\text/plain (deleted)
    (7/18/05 14:15:12) FilterKey: HKCR\CLSID\{0B0887D9-3B5D-48D5-B879-3FD5DC8DF77B} (error while deleting)
    (7/18/05 14:15:12) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
    (7/18/05 14:15:12) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{0F286208-E541-4D5C-9628-8DAA670350E2} (deleted)
    (7/18/05 14:15:12) BHO-Key: HKCR\CLSID\{0F286208-E541-4D5C-9628-8DAA670350E2} (deleted)
    (7/18/05 14:15:12) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run \sp=rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInsta ll (deleted)
    (7/18/05 14:15:12) UBF: 7 - UBB: 2 - UBR: 4
    (7/18/05 14:15:12) Bad IE-pages:
    deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\admini~1\locals~1\temp\se.dll/spage.html
    deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
    deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
    deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
    deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
    deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\admini~1\locals~1\temp\se.dll/spage.html
    deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
    deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
    deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
    deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
    (7/18/05 14:15:12) Stealth-String not found
    (7/18/05 14:15:12) File added to delete: c:\winnt\system32\kgfd.dll
    (7/18/05 14:15:12) File added to delete: c:\docume~1\admini~1\locals~1\temp\se.dll
    (7/18/05 14:15:12) Reboot


    (7/18/05 14:17:03) SPSeHjFix started v1.1.2
    (7/18/05 14:17:03) OS: Win2000 Service Pack 4 (5.0.2195)
    (7/18/05 14:17:03) Language: english
    (7/18/05 14:17:03) Win-Path: C:\WINNT
    (7/18/05 14:17:03) System-Path: C:\WINNT\system32
    (7/18/05 14:17:03) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\

    and the pop-up didn't reappear since monday. (even when i launch IE)

  6. #6
    HJThis is offline Senior Member
    Hi,pooly

    Sorry for this late reply eye's not doing to well today
    now as for the logfile looks good but for this item here.

    C:\Program Files\FutureSource\Workstation\AvalancheUI.exe<--This file here you have any background on it that can help me out what is it
    did you install???

    do this please

    Go here and click in the little box that has browse beside it and paste this line into it,

    C:\Program Files\FutureSource\Workstation\AvalancheUI.exe

    then press submit.
    That sends a copy of the file to their virus checker to see if it is infected.
    If you are not sure then please post back the report.

    other then that you are Gold now for some progs get them update
    all the ones you download & just keep them updated

    SpywareBlaster - Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests.
    http://www.javacoolsoftware.com/spywareblaster.html

    SpywareGuard - An anti-virus program scans files before you open them and prevents execution if a virus is detected - SpywareGuard does the same thing, but for spyware!
    http://www.javacoolsoftware.com/spywareguard.html

    IE-SPYAD is a Registry file (IE-ADS.REG) that adds a long list of sites and domains associated with known advertisers, marketers, and crapware pushers to the Restricted sites zone of Internet Explorer.
    https://netfiles.uiuc.edu/ehowes/www/resource.htm

    Blocking Unwanted Parasites with a Hosts File
    http://www.mvps.org/winhelp2002/hosts.htm

    and this prog here will help keep your PC clean.

    popular programs for doing this, is a freeware program Called Crap Cleaner. Crap Cleaner is a single utility that lets you clear your Cookies, Internet Explorer History, Empty the Recycle Bin, Uninstall Programs, Clear Usage Tracks and much more. As well as this, it has an Advanced Registry Scanner. Using a program like this is one of the easiest methods.

    You should also think about using Firefox & Mozilla & us IE for updates

    Get your Firefox here

    Mo who

    HGD

  7. #7
    pooly is offline Newbie
    The AvalancheUI is a software we use to get quotes from financial markets.
    And, we use Firefox most of the time, but some websites require IE, so we still need it ;-)
    Thanks for the help !

  8. #8
    HJThis is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    Hi,pooly

    Ok no problem just making sure & thanks for the info
    take care.

    HGD

+ Reply to Thread