This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Hijacked

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Upon entering IE I am forced to a search site that is not my home page. Additionally when attempting to log onto Yahoo I am forced back to the same site even though the url states yahoo.com. When entering a zip code on the weatherchannel website I am forced back to the same malicious site. I have tried Adware and spybot.

Here is my Hijackthis file

Help would be greatly appreciated. Thank you!

Steve

Logfile of HijackThis v1.99.1
Scan saved at 5:35:53 PM, on 2/19/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\America Online 7.0\aoltray.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Stephen\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
C:\Documents and Settings\Stephen\Local Settings\Temp\Temporary Directory 4 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Nothing is jumping out of the log. Do this for me. Click here to download eScan's mwav application. Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.
Daemon, Thank you for your reply. It looks like I may have corrected my virus by conducting a “System Restore” (start, all programs, accessories, system tools, system restore) to a date prior to the virus infection. Is this a safe and acceptable method to eradicate viruses? Do you recommend any particular firewall/virus protection software to help protect my system? Additionally, how often do you suggest running an entire system virus check? I did take your suggestion and run escan. Here are the results of the lower panel. Do I need to remove any of these? Thank you!!!!! File C:\PROGRA~1\Save\Save.exe infected by "not-a-virus:AdWare.SaveNow.bc" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\Save\Save.exe infected by "not-a-virus:AdWare.SaveNow.bc" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\cd_clint.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\cd_htm.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\Program Files\Save\extra.exe infected by "not-a-virus:AdWare.SaveNow.al" Virus. Action Taken: No Action Taken. File C:\Program Files\Save\SaveUninst.exe infected by "not-a-virus:AdWare.SaveNow.bc" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP152\A0024961.exe infected by "not-a-virus:AdWare.SaveNow.ah" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP152\A0024962.exe infected by "not-a-virus:AdWare.SaveNow.m" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP161\A0025535.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP161\A0025552.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP165\A0025822.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP165\A0025823.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP166\A0025839.exe infected by "not-a-virus:AdWare.SaveNow.bc" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP166\A0025840.exe infected by "not-a-virus:AdWare.SaveNow.bc" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP166\A0025841.exe infected by "not-a-virus:AdWare.SaveNow.al" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP172\A0026177.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP174\A0026621.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035372.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035373.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035374.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035375.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035376.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035377.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035378.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035379.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035380.exe infected by "Virus.Win32.Implinker.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035382.dll infected by "not-a-virus:AdWare.Visiter" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035483.exe infected by "not-a-virus:AdWare.SaveNow.ah" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\A0035484.exe infected by "not-a-virus:AdWare.SaveNow.m" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\cd_clint.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\cd_htm.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken.
Hmm.. do something for me. Download klwk.zip from here:
ftp://ftp.kaspersky.ru/utils/klwk/klwk.zip

Extract from the zip file and run the klwl application - let me know if it removes anything.
OK good. Do this: 1. Right-click My Computer>Click Properties>Click the System Restore tab>Check the box next to 'Turn off System Restore on all drives'>Click Apply>Click OK. 2. Reboot. 3. Repeat the process but this time remove the check from the box. Post a new mwav scan when done.
I have completed the process you listed. Thank you. Here is the new bottom portion of the mwav. File C:\PROGRA~1\Save\Save.exe infected by "not-a-virus:AdWare.SaveNow.bc" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\Save\Save.exe infected by "not-a-virus:AdWare.SaveNow.bc" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\cd_clint.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\cd_htm.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\Program Files\Save\extra.exe infected by "not-a-virus:AdWare.SaveNow.al" Virus. Action Taken: No Action Taken. File C:\Program Files\Save\SaveUninst.exe infected by "not-a-virus:AdWare.SaveNow.bc" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\cd_clint.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\cd_htm.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken.
Meaning these type produts? (Quicken, TurboTax, QuickBooks) No. Looks like I have a Microsoft Money application but I do not use it.
Thank you for your help, seems my system is back to normal. Is there anything else that needs to be done? Do you suggest protection software like Zonealarm?
Apologies - missed your earlier reply. Find and delete these:

C:\Program Files\Save\ <– folder
C:\WINDOWS\System32\cd_clint.dll
C:\WINDOWS\System32\cd_htm.dll

Zone alarm is good if you don't already use a firewall. To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?

Let me know if it's running OK and I will close the topic.
I have deleted the files you listed. Thank you for all your assistance and information. This has been extremely helpful. I have contributed a donation to the site. Thanks!
You're welcome - glad to help :D And thanks for your support.

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI