What OS is running on this/these systems?
Also, do you have a hijack this log handy?
Main Topics
Browse All TopicsIt started with one PC in my network with the IE Homepage stuck on http://213.159.117.132/red
I have also cleared the RUN, and RUN ONCE folders in the registry. A preculiar command comes back calling to run either Lykopex.exe or P99EU.exe which I have replaced in the C:\WINNT\SYSTEM32 directory with other files. When logging in sometimes a small box appears called "Installer" but it locks up with "Not Responding" in the Task Manager - Applications Tab. One of these PC's will suck to have to rebuild - I have spent so much time on this problem this morning - I have techs rebuilding the other two.
I need the big brains on this. ComputerCops.biz has a help request for it too as I noticed but no resolution. The winner of this also gets shipped a couple of autographed books as well.
Sean Odom, CCIE, MCSE, CCNX
Sybex/Que Cisco Author
<email address removed by sirbounty, ref http:help.jsp#hi99 for furhter information.>
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
All Are running 2000 Pro and here is the HiJackThis log File
Logfile of HijackThis v1.97.7
Scan saved at 12:36:23 PM, on 5/28/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\winnt\System32\smss.exe
C:\winnt\system32\winlogon
C:\winnt\system32\services
C:\winnt\system32\lsass.ex
C:\winnt\system32\svchost.
C:\winnt\System32\svchost.
C:\winnt\system32\spoolsv.
C:\Program Files\Intel\Alert on LAN\winnt\proxy\aolnsrvr.e
C:\winnt\System32\Ati2evxx
C:\Program Files\Symantec_Client_Secu
C:\winnt\Program Files\Executive Software\Diskeeper\DkServi
C:\winnt\system32\hidserv.
C:\Program Files\Intel\LDCM\bin\IIDS.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr
C:\Program Files\Symantec_Client_Secu
C:\winnt\system32\regsvc.e
C:\PROGRA~1\Dantz\RETROS~1
C:\winnt\system32\MSTask.e
C:\winnt\System32\snmp.exe
C:\Program Files\HP\Insight Manager 7 SP2\WebDmi\WebDmi.exe
C:\winnt\System32\WBEM\Win
C:\winnt\System32\CPQNiMgt
C:\winnt\system32\cpqmgmt\
C:\winnt\system32\cpqmgmt\
C:\Program Files\Intel\LDCM\bin\ssm.e
C:\winnt\system32\cpqmgmt\
C:\winnt\System32\CPQMGMT\
C:\winnt\system32\MsgSys.E
C:\winnt\Explorer.EXE
C:\Program Files\Symantec_Client_Secu
C:\winnt\system32\wlanSTA.
C:\winnt\system32\sccmgr.e
C:\Program Files\Washer\washer.exe
C:\PROGRA~1\AWS\WEATHE~1\W
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\
C:\WINNT\Plaxo\1.4.2.25\In
C:\Documents and Settings\smo\Desktop\Hijac
C:\winnt\system32\notepad.
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Unified Messaging Client\LINEMGR.EXE
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Secu
O4 - HKLM\..\Run: [wlanSTA.EXE] wlanSTA.EXE START
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\W
O4 - HKCU\..\Run: [PlaxoUpdate] C:\WINNT\Plaxo\1.4.2.25\In
I would check the boxes for these registry entries,
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
and remove these keys from the registry -- backup the reg first though
They are calling the app. I'll look through it and see what else I can find in the log.
1. Update your Anti-Virus software
2. Download Ad-Aware from www.lavasoftusa.com
3. Update Ad-Aware
4. Run WindowsUpdate and apply all security fixes
5. Disconnect your PC from the Internet
6. Run Ad-Aware, remove all suspicious items.
7. Run your AV software.
8. Open Internet Explorer and modify settings as required.
Hopefully that will solve your problem.
RJ-Smith - I have done all that.
Munkyxtc - IE 6 was installed when we first started and reinstalled. We decided to try and downgrade to the earlier version. As for patches we use SUS here so all the latest patches are installed once per day.
Munkyxtc - There was one process to eliminiate on a reboot and I am running it again to see what the process is.
Whatever is doing it probably has 213.159.117.132 encoded as a string in the application. If all else fails, go to command line: cmd.exe and navigate to the root and search for applications with that address. It will take awhile but it should find it (and this method is more reliable than using 'Find Files or Folders'.
Start->Run->cmd.exe
cd /d c:\
findstr /i /s /m 213.159.117.132 *.*
And then investigate any files it finds. If that doesn't work, you may want to try searching for redir.php since the address could possibly automatically generated.
munkyxtc - The identical keys return redirecting to http://213.159.117.132/red
Hey there :)
Read this article:
http://computercops.biz/po
They had the same problem.
in the end:
"Ok Grift, that did it... If you don't have it working yet, goto safemode and search for the files 'system.exe' and 'system32.dll' delete both restart and all should be working normal again."
"well, i deleted system32.dll and all registry thingies that were associated
my spyguard caught the thing once when i rebooted (i had to delete in safe mode) but... since then it hasnt' tried to set itself up
soooooo, we'll see how long this lasts, i was getting popups every few seconds before saying that it has tried to change my homepage"
Hope it works for you. :)
~~Vaporz
I haven't looked at vpstyle's link, but another option would be to do the following:
1) download regmon from sysinternals
2) start it and setup up the filter for 'redir.php'
3) delete the keys
4) see what process adds them
(I'm not into the brute force method of downloading every damned anti-spyware thing there is and running it).
VPSTYLE - Was almost technically correct. Delete the c:\winnt\system32\system32
Business Accounts
Answer for Membership
by: sirbountyPosted on 2004-05-28 at 12:25:37ID: 11183426
Check these links for online virus scanners. It's recommended to run at least two of these.
Norton/Symantec --> http://security.symantec.c
Trend Micro --> http://housecall.antivirus
Panda ActiveScan--> http://www.pandasoftware.c
McAfee Security --> http://us.mcafee.com/root/
Stinger --> http://download.nai.com/pr
These links Check for Spyware:
Spybot-S&D --> http://www.safer-networkin
HijackThis --> http://www.spychecker.com/
Ad-Aware --> http://www.netsecurity.abo
Web Shredder--> http://www.spywareinfo.com
Pest Patrol --> http://www.pestpatrol.com/
PCHell removal->http://www.pchell
Make sure that after downloading these, that you update them. It helps to try at least two of these.
If all else fails, download HijackThis and post the log that is generated after running it on your system.