Nemanja
Topic Starter
Hi, i'm posting here for the first time…
Few days ago some sites on my comp seemed to be hijacked.
Symptoms are following: as i was surfing the net i realized that i forgot to turn on ZoneAlarmPro (i have dial-up modem). Everything seemed to
be in order, but the next time i tryed to do a search on google, i was redirected to a new site: http://searchingall.com. I presumed that i got some
kind of virus or spyware so i tryed to find it… After doing a scan with Kaspersky Anti-Virus, and running anti spyware program (Bazooka), i found
nothing… So i decided to see if i could find anything myself (i know pretty well critical files on my comp), but it was obvious that this was way out
of my leage… Furthermore problem became worse: Google stoped showing search results at all (first few time it did show some results), and
searchingall.com was set as my home adress (usually its about:blank)… Links to some sites kept apearing on my desktop and IE (6) started
crashing if i was not online… If i tried to set up my previous home adress (about blank), it wouldn't work - next time there was searchingall again
(well i wasnt hoping that it would be that easy afterall)…
As i was trying to better things somehow (looking on the net for solutions), i came across http://www.tomcoyote.org. So i read all the FAQ i
could find, and did following: I installed Spybot S&D, read Tutuorial, runed it and fixed all the problems that were listed there, but searchingall
was still there… Next i read that 5 step helper (the one that says what i must do if Spybot doesnt help, and before uploading HijackThis log). I
did all i could (except looking through *.js, and *.hta files - cause there are hundreds of those files on my comp, and i m in middle of exams), i
turned on all the things that was off in my msconfig, i restarted computer, did one more update on Spybot, runed it, fixed two more problems
that appeared, restarted comp once again, concluded that that pesky thing is still there and then decided to post hijackthis log…
A minor digresion - i had problems with pop-ups an virus before (and i didnt knew how to deal with them than by myself), so there may still be
something of those left behind in my registry…
I would be very gratefull for any kind of help…
Nemanja
P.S. I didnt knew until few days ago that there is something like hijacking sites, so i mention it to my brother, along with all the symptoms and he said that he knows about it, and that he had hijackers before… I asked: How did you got rid of them (enthusiasticly), and he replied: "Simply…I stop using Internet…"
Comp was scaned by HijackThis few minutes before i made this post:
Logfile of HijackThis v1.98.2
Scan saved at 18:35:42, on 30.10.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Motherboard Monitor 5\MBM5.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
D:\Boinc\boinc_gui.exe
d:\boinc\projects\setiathome.berkeley.edu\setiathome_4.05_windows_intelx86.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\Notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Wincmd\Wincmd32.exe
c:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchingall.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchingall.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchingall.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchingall.com/search/ssearch.php?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: MAcPvCMY1lObj Class - {C13364BC-53C8-43be-8A06-D2F5CFA16E7B} - C:\WINDOWS\System32\drivers\kernel32.dll
F3 - REG:win.ini: run=C:\WINDOWS\inetg\services.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {75483ED2-73AF-480F-AC93-E38B0D02272B} - C:\WINDOWS\System32\lmj.dll (file missing)
O2 - BHO: Deskware Link Catcher - {88F0297D-A046-4942-B6B9-03D8939E92D5} - C:\WINDOWS\DESKWA~1.DLL
O2 - BHO: MAcPvCMY1l - {C13364BC-53C8-43be-8A06-D2F5CFA16E7B} - C:\WINDOWS\System32\drivers\kernel32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MBM 5] "C:\Program Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [OfficeGuard RegChecker] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ogrc.exe"
O4 - HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /wait
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O4 - Global Startup: BOINC.lnk = D:\Boinc\boinc_gui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .exe: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2B5EB099-EB46-435D-9089-23C0DE130704} (IAOCX.HOSTILESPACE) - https://www.hostilespace.com/Portal/bin/IAHSOCX20013.CAB
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {92F02779-6D88-4958-8AD3-83C12D86ADC7} - http://www.searchingall.com/software/get_s…ID=114612&AID=4
O17 - HKLM\System\CCS\Services\Tcpip\..\{25EDF0D0-A06C-409E-9801-C0552D40E7DD}: NameServer = 194.247.192.33 194.247.192.1
O18 - Filter: text/html - {FB4C762A-C09F-4D84-A001-EAB92E4DC227} - C:\WINDOWS\System32\lmj.dll
O18 - Filter: text/plain - {FB4C762A-C09F-4D84-A001-EAB92E4DC227} - C:\WINDOWS\System32\lmj.dll
O21 - SSODL: SystemCheck - {54645654-2225-4455-44A1-9F4543D34544} - C:\WINDOWS\System32\vbsys.dll
Few days ago some sites on my comp seemed to be hijacked.
Symptoms are following: as i was surfing the net i realized that i forgot to turn on ZoneAlarmPro (i have dial-up modem). Everything seemed to
be in order, but the next time i tryed to do a search on google, i was redirected to a new site: http://searchingall.com. I presumed that i got some
kind of virus or spyware so i tryed to find it… After doing a scan with Kaspersky Anti-Virus, and running anti spyware program (Bazooka), i found
nothing… So i decided to see if i could find anything myself (i know pretty well critical files on my comp), but it was obvious that this was way out
of my leage… Furthermore problem became worse: Google stoped showing search results at all (first few time it did show some results), and
searchingall.com was set as my home adress (usually its about:blank)… Links to some sites kept apearing on my desktop and IE (6) started
crashing if i was not online… If i tried to set up my previous home adress (about blank), it wouldn't work - next time there was searchingall again
(well i wasnt hoping that it would be that easy afterall)…
As i was trying to better things somehow (looking on the net for solutions), i came across http://www.tomcoyote.org. So i read all the FAQ i
could find, and did following: I installed Spybot S&D, read Tutuorial, runed it and fixed all the problems that were listed there, but searchingall
was still there… Next i read that 5 step helper (the one that says what i must do if Spybot doesnt help, and before uploading HijackThis log). I
did all i could (except looking through *.js, and *.hta files - cause there are hundreds of those files on my comp, and i m in middle of exams), i
turned on all the things that was off in my msconfig, i restarted computer, did one more update on Spybot, runed it, fixed two more problems
that appeared, restarted comp once again, concluded that that pesky thing is still there and then decided to post hijackthis log…
A minor digresion - i had problems with pop-ups an virus before (and i didnt knew how to deal with them than by myself), so there may still be
something of those left behind in my registry…
I would be very gratefull for any kind of help…
Nemanja
P.S. I didnt knew until few days ago that there is something like hijacking sites, so i mention it to my brother, along with all the symptoms and he said that he knows about it, and that he had hijackers before… I asked: How did you got rid of them (enthusiasticly), and he replied: "Simply…I stop using Internet…"
Comp was scaned by HijackThis few minutes before i made this post:
Logfile of HijackThis v1.98.2
Scan saved at 18:35:42, on 30.10.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Motherboard Monitor 5\MBM5.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
D:\Boinc\boinc_gui.exe
d:\boinc\projects\setiathome.berkeley.edu\setiathome_4.05_windows_intelx86.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\Notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Wincmd\Wincmd32.exe
c:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchingall.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchingall.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchingall.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchingall.com/search/ssearch.php?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: MAcPvCMY1lObj Class - {C13364BC-53C8-43be-8A06-D2F5CFA16E7B} - C:\WINDOWS\System32\drivers\kernel32.dll
F3 - REG:win.ini: run=C:\WINDOWS\inetg\services.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {75483ED2-73AF-480F-AC93-E38B0D02272B} - C:\WINDOWS\System32\lmj.dll (file missing)
O2 - BHO: Deskware Link Catcher - {88F0297D-A046-4942-B6B9-03D8939E92D5} - C:\WINDOWS\DESKWA~1.DLL
O2 - BHO: MAcPvCMY1l - {C13364BC-53C8-43be-8A06-D2F5CFA16E7B} - C:\WINDOWS\System32\drivers\kernel32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MBM 5] "C:\Program Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [OfficeGuard RegChecker] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ogrc.exe"
O4 - HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /wait
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O4 - Global Startup: BOINC.lnk = D:\Boinc\boinc_gui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .exe: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2B5EB099-EB46-435D-9089-23C0DE130704} (IAOCX.HOSTILESPACE) - https://www.hostilespace.com/Portal/bin/IAHSOCX20013.CAB
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {92F02779-6D88-4958-8AD3-83C12D86ADC7} - http://www.searchingall.com/software/get_s…ID=114612&AID=4
O17 - HKLM\System\CCS\Services\Tcpip\..\{25EDF0D0-A06C-409E-9801-C0552D40E7DD}: NameServer = 194.247.192.33 194.247.192.1
O18 - Filter: text/html - {FB4C762A-C09F-4D84-A001-EAB92E4DC227} - C:\WINDOWS\System32\lmj.dll
O18 - Filter: text/plain - {FB4C762A-C09F-4D84-A001-EAB92E4DC227} - C:\WINDOWS\System32\lmj.dll
O21 - SSODL: SystemCheck - {54645654-2225-4455-44A1-9F4543D34544} - C:\WINDOWS\System32\vbsys.dll