Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security

General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Closed Thread
 
LinkBack Thread Tools
Old 15th July 2004   #1
Inactive
 
Profile:
Join Date: Jan 2003
Location: Belfast, Ireland
Posts: 58
Computer Experience:
Intermediate
gerdcurli Reputation Level


Hijacking

HI THERE, Even after I use SpyBot, Ad-Aware, Hi-jack this etc, I'm still having my home page hi-jacked. Can someone tell me please, how to stop this. Also, can you tell me the quickest way to post a logfile here, which I'm sure you'll be asking for.
Many Thnaks..
GPS. is this the logfile?...
Started deep registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Pagetemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\WINDOWS\TEMP\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "file://C:\WINDOWS\TEMP\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bartemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\WINDOWS\TEMP\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "file://C:\WINDOWS\TEMP\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistanttemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\WINDOWS\TEMP\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "file://C:\WINDOWS\TEMP\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Pagetemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\WINDOWS\TEMP\sp.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "file://C:\WINDOWS\TEMP\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bartemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\WINDOWS\TEMP\sp.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "file://C:\WINDOWS\TEMP\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistanttemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\WINDOWS\TEMP\sp.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "file://C:\WINDOWS\TEMP\sp.html"

Possible browser hijack attempt : .Default\Software\Microsoft\Internet Explorer\MainSearch Pagetemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\WINDOWS\TEMP\sp.html"
Rootkey : HKEY_USERS
Object : .Default\Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "file://C:\WINDOWS\TEMP\sp.html"

Possible browser hijack attempt : .Default\Software\Microsoft\Internet Explorer\MainSearch Bartemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\WINDOWS\TEMP\sp.html"
Rootkey : HKEY_USERS
Object : .Default\Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "file://C:\WINDOWS\TEMP\sp.html"

Possible browser hijack attempt : .Default\Software\Microsoft\Internet Explorer\SearchSearchAssistanttemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\WINDOWS\TEMP\sp.html"
Rootkey : HKEY_USERS
Object : .Default\Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "file://C:\WINDOWS\TEMP\sp.html"


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{0FC099C1-D4D6-11D8-AAD8-5254431985A1}


CoolWebSearch Object recognized!
Type : File
Data : hphla.dll
Object : c:\windows\system\
FileSize : 30 KB
Created on : 13/07/04 13:08:16
Last accessed : 14/07/04 23:00:00
Last modified : 13/07/04 13:08:18



CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{0FC099C2-D4D6-11D8-AAD8-5254B3CB1BD6}


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : PROTOCOLS\Filter\text/html


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : PROTOCOLS\Filter\text/plain


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FC099C2-D4D6-11D8-AAD8-5254B3CB1BD6}


Deep registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 15
Objects found so far: 16


ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Tracking Cookie Object recognized!
Type : File
Data : gerdcurli@counter7.sextracker[1].txt
Object : C:\WINDOWS\Cookies\

Created on : 15/07/04 07:00:05
Last accessed : 14/07/04 23:00:00
Last modified : 15/07/04 07:00:06



Tracking Cookie Object recognized!
Type : File
Data : gerdcurli@paycounter[1].txt
Object : C:\WINDOWS\Cookies\

Created on : 15/07/04 06:55:19
Last accessed : 14/07/04 23:00:00
Last modified : 15/07/04 06:55:20



Tracking Cookie Object recognized!
Type : File
Data : gerdcurli@sexlist[2].txt
Object : C:\WINDOWS\Cookies\

Created on : 15/07/04 07:24:43
Last accessed : 14/07/04 23:00:00
Last modified : 15/07/04 07:24:44



Tracking Cookie Object recognized!
Type : File
Data : gerdcurli@counter2.sextracker[1].txt
Object : C:\WINDOWS\Cookies\

Created on : 15/07/04 07:00:05
Last accessed : 14/07/04 23:00:00
Last modified : 15/07/04 07:00:06



Tracking Cookie Object recognized!
Type : File
Data : gerdcurli@sextracker[2].txt
Object : C:\WINDOWS\Cookies\

Created on : 15/07/04 07:00:05
Last accessed : 14/07/04 23:00:00
Last modified : 15/07/04 07:00:06



Tracking Cookie Object recognized!
Type : File
Data : gerdcurli@hg1.hitbox[1].txt
Object : C:\WINDOWS\Cookies\

Created on : 15/07/04 07:33:21
Last accessed : 14/07/04 23:00:00
Last modified : 15/07/04 07:33:22



Tracking Cookie Object recognized!
Type : File
Data : gerdcurli@hitbox[2].txt
Object : C:\WINDOWS\Cookies\

Created on : 15/07/04 07:33:21
Last accessed : 14/07/04 23:00:00
Last modified : 15/07/04 07:33:22



Tracking Cookie Object recognized!
Type : File
Data : gerdcurli@xxxcounter[1].txt
Object : C:\WINDOWS\Cookies\

Created on : 15/07/04 07:34:53
Last accessed : 14/07/04 23:00:00
Last modified : 15/07/04 07:34:54


ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

gerdcurli is offline  
Didn't find the information you thought to find?
Check out these Similar Threads
Old 15th July 2004   #2
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 21,699
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

HijackThis fixes nothing unless instructed to - best you don't either without advice from here

First download the latest version 1.98 through Quicklinks in my signature and save it to a folder on your HD.

Run the exe file and hit the Scan button. When the scan has finished the Scan button changes to Save log. Hit this and a Save dialogue box opens defaulting (in XP at least) to My Documents. Accept the default name for the log - or change it if you like and save. The log opens in Notepad. Edit > Select all, copy and paste into a post here.

PeteC is offline  
Old 15th July 2004   #3
Inactive
 
Profile:
Join Date: Jan 2003
Location: Belfast, Ireland
Posts: 58
Computer Experience:
Intermediate
gerdcurli Reputation Level


LogFile

Hi Pete, thanks for such a swift reply, as usual.
Here is the logfile you asked me to paste:-

Logfile of HijackThis v1.98.0
Scan saved at 13:06:27, on 15/07/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\ADOBE\PHOTOSHOP 7.0\PHOTOSHOP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {B2F2DA9C-D635-11D8-AAD8-52542B7B1603} - C:\WINDOWS\SYSTEM\HPHLA.DLL
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN TOOLBAR\01.01.1601.0\MSGR.EN-US.EN-GB\MSNTB.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\RunOnce: [Ad-aware] "C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\AD-AWARE.EXE" "+b1"
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: Outlook Express.lnk = C:\Program Files\Outlook Express\msimn.exe
O18 - Filter: text/html - {B2F2DA9B-D635-11D8-AAD8-5254A4928E77} - C:\WINDOWS\SYSTEM\HPHLA.DLL
O18 - Filter: text/plain - {B2F2DA9B-D635-11D8-AAD8-5254A4928E77} - C:\WINDOWS\SYSTEM\HPHLA.DLL

regards,
G

gerdcurli is offline  
Old 15th July 2004   #4
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,524
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

First, download and install Reglite. Open and copy/paste the following string in the address window then click go.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

Double click on the AppInit_DLLs entry to open a "Data Editor" properties window. If the Value line contains a .dll filename, copy/paste it here.

Additionally, download the current version of CWShredder, v1.59.1. You'll need it later.

noahdfear is offline  
Old 15th July 2004   #5
SuperGeek
 
Profile:
Join Date: Dec 2002
Location: Washington state USA
Posts: 2,310
Computer Experience:
Typeos-are-Us
Lonny Jones Reputation Level


Try cwsredder first
Fist Download, then close all open windows and run CWShredder 1.59.1
http://www.net-integration.net/tools...tml#cwshredder <<from there
Click Fix, don't just scan. You have several CoolWebSearch components which it should remove.
If you already have it, just download another copy and overwrite the old one..To ensure its the latest version. currently its ver 1.59.1 as of 6/28/2004

Then restart the PC

come back then scan and repost another Hijackthis Log

Lonny Jones is offline  
Closed Thread

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
IE Browser Hijacking Johanna General Security 7 4th June 2004 13:34
IE Hijacking mwelch's post mwelch General Security 7 27th May 2004 07:19
Do I have a virus? byron General Security 9 17th February 2002 20:16


All times are GMT +1. The time now is 10:40.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright İ 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]