I saw many qustions from users regarding this problem, and I talk about the browser hijack that take control of the home page. All the answers were the same: run AdAware, run spybot, run HijackThis and so on and on... send us the log and we'll tell you what to fix. I've been a good boy and did my homework, downloded all of those programs and execute them. As expected nothing helped, so here is the log from "HijackThis", can you tell me what to fix?
One more question before the log: If there are so many users affected from that hijacks, how come there is still no appropriate solution for this (after all we do have for viruses, worms, blusters and more complicated attackers)?
Thanks
and the log:
Logfile of HijackThis v1.97.7
Scan saved at 22:27:37, on 04/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\cisvc.
exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\System32\snmp.e
xe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\WINDOWS\ipwb.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\PELMIC
ED.EXE
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\BLEHVG~1\Media
Dog.exe
C:\WINDOWS\system32\winhh.
exe
C:\WINDOWS\System32\gsicon
.exe
C:\Program Files\GlobespanVirata\Adsl
\dslagent.
exe
C:\PROGRA~1\MYWEBS~1\bar\2
.bin\mwsoe
mon.exe
C:\Program Files\Babylon\Babylon.exe
D:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\ICQ\ICQ.exe
C:\WINDOWS\System32\mdm.ex
e
C:\WINDOWS\System32\cidaem
on.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Odigo\Bin\Odigo.exe
C:\Program Files\Odigo\Bin\obrw.exe
C:\Documents and Settings\Owner\Desktop\Hij
ackThis.ex
e
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.tapuz.co.il/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.comR1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,Shellnext =
http://messenger.microsoft.com/O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - D:\Program Files\Adobe\Acrobat 5.0 ME\Reader\ActiveX\AcroIEHe
lper.ocx
O2 - BHO: (no name) - {3A3A236D-485F-3BD2-2C16-8
545899F02A
9} - C:\WINDOWS\system32\msdl.d
ll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RunOdigo] C:\Program Files\Odigo\Bin\Odigo.exe -m
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [sizebash] C:\PROGRA~1\BLEHVG~1\Media
Dog.exe
O4 - HKLM\..\Run: [nettp32.exe] C:\WINDOWS\system32\nettp3
2.exe
O4 - HKLM\..\Run: [winhh.exe] C:\WINDOWS\system32\winhh.
exe
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\GlobespanVirata\Adsl
\dslagent.
exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2
.bin\mwsoe
mon.exe
O4 - HKCU\..\Run: [Babylon Translator] C:\Program Files\Babylon\Babylon.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.
exe min
O4 - HKCU\..\Run: [sr64] C:\Documents and Settings\Owner\Application
Data\Microsoft\sr64\cfbpoo
om.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1
.bin\mwsoe
mon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bi
n\MWSOEMON
.EXE
O4 - Global Startup: HotSync Manager.lnk = D:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bi
n\MWSOEMON
.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Program Files\Yahoo!\Common/ycsrch
.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Program Files\Yahoo!\Common/ycdict
.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Program Files\Yahoo!\Common/ycdict
.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: מחק—
2; (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=
http://www.bug.co.il/O16 - DPF: {11111111-1111-1111-1111-1
1111111112
3} - file://c:\Recycled\1.exe
O16 - DPF: {11111111-1111-1111-1111-1
1111111115
7} - ms-its:mhtml:file://c:\nos
uch.mht!
http://hard-virgins.com/sher/x.chm::/load.exeO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
E41684E07B
B} -
http://imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cabO16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) -
http://download.yahoo.com/dl/installs/yinst0401.cabO16 - DPF: {33564D57-0000-0010-8000-0
0AA00389B7
1} -
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CABO16 - DPF: {3E68E405-C6DE-49FF-83AE-4
1EE9F4C36C
E} (Office Update Installation Engine) -
http://office.microsoft.com/officeupdate/content/opuc.cabO16 - DPF: {51C98AC0-31D3-4049-B659-2
4389E0D94E
3} (TCM3Control Control) -
http://video.icellcom.co.il/TCM3Viewer.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-3
98534BB899
9} (YAddBook Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {F59AB0C4-3443-4551-A78F-C
101F9DE021
5} (LauncherV1 Class) -
http://irc.tapuz.co.il/BlogTVU/launcher.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{F
5F714F6-BF
25-4DC6-B8
86-CFF5FD4
91539}: NameServer = 192.115.106.31 62.219.186.7
Thanks again,
pakci