This HP PC running Win XP Home had the home page hijacked by a page trying to sell something (and no other address could be typed into the address field and browsed to). I told the customer to run AdAware, Spybot, and Ewido both in normal and in safe mode. He said Ewido cleaned a lot of stuff, but the home page still couldn't be changed.
He wasn't patient enough to wait one more day for me to look at it, so he spent 4 hours on the phone with HP and paid them $45 to upgrade to IE 7 (go figure...I would have done that for free in 15 minutes). Anyway, the home page and browser works now. Is it possible that upgrading the browser cured all of the problem? I'm skeptical because I know that stuff often buries itself in the registry.
So...here's the question. Below is his current Hijack This log. See anything that looks like it's waiting to attack again? Or other problems? What about all of those Winlogon Notify entries and line 018?
Logfile of HijackThis v1.99.1
Scan saved at 10:51:10 PM, on 11/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
c:\program files\cox\applications\app
\CurtainsS
ysSvcNt.ex
e
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\Program Files\Softex\OmniPass\Omni
serv.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Softex\OmniPass\OPXP
App.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\Program Files\Cox\Applications\app
\Prism.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\WINDOWS\Explorer.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv
.exe
C:\WINDOWS\System32\hphmon
05.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.
exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\rundll
32.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hposol08.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EX
E
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EX
E
C:\DOCUME~1\Owner\LOCALS~1
\Temp\Temp
orary Directory 1 for hijackthis (2).zip\HijackThis.exe
C:\WINDOWS\system32\NOTEPA
D.EXE
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://news.google.com/nwshp?ie=UTF-8&oe=UTF-8&hl=en&tab=wn&q=R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system
32\AUserIn
it.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
ll
O2 - BHO: (no name) - {0F8C2B98-1D3D-4FD0-8CAE-F
DB1BC42655
f} - C:\WINDOWS\system32\xwprfa
hb.dll (file missing)
O2 - BHO: (no name) - {192c5b4a-3efd-40c7-9f99-c
472deb8efc
0} - C:\Program Files\Super Codec\isaddon.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0
B5F309A0E6
4} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7
bd156758a3
7} - (no file)
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d
9b138c6a53
b} - C:\Program Files\VideoKeyCodec\isaddo
n.dll (file missing)
O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A
2AB4D9A672
D} - C:\Program Files\Cox\Applications\app
\AuthBHO.d
ll
O2 - BHO: (no name) - {DD1052A2-C2AA-4CAB-9D6A-6
18DD14F09E
c} - C:\WINDOWS\system32\xwprfa
hb.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
09B6AD74AC
C} - (no file)
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-0
5D28BCF79F
5} - c:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9
620D33362C
1} - C:\Program Files\Cox\Applications\app
\AuthBHO.d
ll
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.ex
e
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv
.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B
6180B-DCAB
-4093-8EE8
-616445751
7F0}\hphup
d05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon
05.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.
exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump
rep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpqtra08.exe
O4 - Global Startup: officejet 6100.lnk = ?
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A
9046DEA8A2
1} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {193C772A-87BE-4B19-A7BB-4
45B226FE9A
1} (ewidoOnlineScan Control) -
http://download.ewido.net/ewidoOnlineScan.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109383066156O16 - DPF: {644E432F-49D3-41A1-8DD5-E
099162EEEC
5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153716902859O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-7
43C63F2E5E
6} (IWinAmpActiveX Class) -
http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cabO18 - Protocol: x-excid - {9D6CC632-1337-4A33-9214-2
DA092E776F
4} - c:\WINDOWS\Downloaded Program Files\mimectl.dll
O20 - Winlogon Notify: adbmwdhx - adbmwdhx.dll (file missing)
O20 - Winlogon Notify: ajayiyht - ajayiyht.dll (file missing)
O20 - Winlogon Notify: amvjnpto - C:\WINDOWS\SYSTEM32\amvjnp
to.dll
O20 - Winlogon Notify: aoqoxxoc - aoqoxxoc.dll (file missing)
O20 - Winlogon Notify: bvcoevuo - bvcoevuo.dll (file missing)
O20 - Winlogon Notify: cfcsppjt - cfcsppjt.dll (file missing)
O20 - Winlogon Notify: cqvyymul - cqvyymul.dll (file missing)
O20 - Winlogon Notify: dejnpxhl - dejnpxhl.dll (file missing)
O20 - Winlogon Notify: dhqdgsid - dhqdgsid.dll (file missing)
O20 - Winlogon Notify: dosrilqn - C:\WINDOWS\SYSTEM32\dosril
qn.dll
O20 - Winlogon Notify: dqljymii - dqljymii.dll (file missing)
O20 - Winlogon Notify: dtfgsewc - dtfgsewc.dll (file missing)
O20 - Winlogon Notify: dxkfmcgs - C:\WINDOWS\SYSTEM32\dxkfmc
gs.dll
O20 - Winlogon Notify: ekjmfslj - ekjmfslj.dll (file missing)
O20 - Winlogon Notify: eluwojqj - eluwojqj.dll (file missing)
O20 - Winlogon Notify: esoguvkl - esoguvkl.dll (file missing)
O20 - Winlogon Notify: etyqydbu - etyqydbu.dll (file missing)
O20 - Winlogon Notify: fckqftrg - fckqftrg.dll (file missing)
O20 - Winlogon Notify: fgxtlwav - fgxtlwav.dll (file missing)
O20 - Winlogon Notify: fyvgrcjd - fyvgrcjd.dll (file missing)
O20 - Winlogon Notify: gspyygll - gspyygll.dll (file missing)
O20 - Winlogon Notify: hjjajbeg - hjjajbeg.dll (file missing)
O20 - Winlogon Notify: hlupqjqi - hlupqjqi.dll (file missing)
O20 - Winlogon Notify: holdapi - holdapi.dll (file missing)
O20 - Winlogon Notify: hurifkpx - hurifkpx.dll (file missing)
O20 - Winlogon Notify: ifawbwfd - C:\WINDOWS\SYSTEM32\ifawbw
fd.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsr
vc.dll
O20 - Winlogon Notify: igohsshu - C:\WINDOWS\SYSTEM32\igohss
hu.dll
O20 - Winlogon Notify: ilpduymh - C:\WINDOWS\SYSTEM32\ilpduy
mh.dll
O20 - Winlogon Notify: inlmsrww - inlmsrww.dll (file missing)
O20 - Winlogon Notify: iuqickvp - iuqickvp.dll (file missing)
O20 - Winlogon Notify: kcaxcqqc - kcaxcqqc.dll (file missing)
O20 - Winlogon Notify: lrxvnkrk - lrxvnkrk.dll (file missing)
O20 - Winlogon Notify: lxmdthbi - lxmdthbi.dll (file missing)
O20 - Winlogon Notify: mdsqhtig - mdsqhtig.dll (file missing)
O20 - Winlogon Notify: nabqahaj - C:\WINDOWS\SYSTEM32\nabqah
aj.dll
O20 - Winlogon Notify: ndthxlqj - ndthxlqj.dll (file missing)
O20 - Winlogon Notify: ntvobhhf - ntvobhhf.dll (file missing)
O20 - Winlogon Notify: ojamixbh - ojamixbh.dll (file missing)
O20 - Winlogon Notify: oofxvmkk - C:\WINDOWS\SYSTEM32\oofxvm
kk.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxp
gina.dll
O20 - Winlogon Notify: pexqvlre - pexqvlre.dll (file missing)
O20 - Winlogon Notify: prsrodok - prsrodok.dll (file missing)
O20 - Winlogon Notify: prvikebw - prvikebw.dll (file missing)
O20 - Winlogon Notify: pupsgbvo - pupsgbvo.dll (file missing)
O20 - Winlogon Notify: pxagfodv - pxagfodv.dll (file missing)
O20 - Winlogon Notify: qdqwnhqn - qdqwnhqn.dll (file missing)
O20 - Winlogon Notify: qlteavwu - qlteavwu.dll (file missing)
O20 - Winlogon Notify: qqlecywk - qqlecywk.dll (file missing)
O20 - Winlogon Notify: qxkyqctr - qxkyqctr.dll (file missing)
O20 - Winlogon Notify: rjpmnuly - C:\WINDOWS\SYSTEM32\rjpmnu
ly.dll
O20 - Winlogon Notify: saivwfwt - saivwfwt.dll (file missing)
O20 - Winlogon Notify: sgdxpsrs - sgdxpsrs.dll (file missing)
O20 - Winlogon Notify: taavjddp - taavjddp.dll (file missing)
O20 - Winlogon Notify: tgyiojiq - tgyiojiq.dll (file missing)
O20 - Winlogon Notify: tuvrokar - tuvrokar.dll (file missing)
O20 - Winlogon Notify: uaebqpcu - uaebqpcu.dll (file missing)
O20 - Winlogon Notify: ugdfsjrw - ugdfsjrw.dll (file missing)
O20 - Winlogon Notify: ujueocal - ujueocal.dll (file missing)
O20 - Winlogon Notify: vujrvwyw - vujrvwyw.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLog
on.dll
O20 - Winlogon Notify: whvjwbpo - whvjwbpo.dll (file missing)
O20 - Winlogon Notify: wkjyvbpr - wkjyvbpr.dll (file missing)
O20 - Winlogon Notify: wyutxqiw - wyutxqiw.dll (file missing)
O20 - Winlogon Notify: xtghgcrb - xtghgcrb.dll (file missing)
O20 - Winlogon Notify: xtsktirc - xtsktirc.dll (file missing)
O20 - Winlogon Notify: xvlubhsv - xvlubhsv.dll (file missing)
O20 - Winlogon Notify: ycdisrub - ycdisrub.dll (file missing)
O20 - Winlogon Notify: ymnanwrc - ymnanwrc.dll (file missing)
O20 - Winlogon Notify: yuaauqnb - yuaauqnb.dll (file missing)
O20 - Winlogon Notify: yuudkaha - yuudkaha.dll (file missing)
O20 - Winlogon Notify: yxpsmafm - yxpsmafm.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-9
4D524869DB
5} - C:\WINDOWS\system32\WPDShS
erviceObj.
dll
O21 - SSODL: cussers - {ff170564-36c8-43f7-9100-5
59e166405c
f} - (no file)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Curtains for Windows System Service (CurtainsSysSvc) - Authentium, Inc. - c:\program files\cox\applications\app
\CurtainsS
ysSvcNt.ex
e
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc3
2.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omni
serv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe