This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser being Hijacked

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help, my family computer is being hijacked with inappropiate material. When I login to the Internet, the home page is changed to wazzupnet.com and an Adult_Chat program is installed and a XXX_dialer is connected. I have tried unsuccessfully to eliminate the problem.

Here is the log.

Logfile of HijackThis v1.99.1
Scan saved at 10:49:03 PM, on 12/05/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Documents and Settings\Paul\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.daewoointernational.ca
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CDllBho Object - {5A5B6916-ED71-4531-8018-E792DD44156E} - C:\WINDOWS\sdasa.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {c3a92a2e-b3ee-4b3b-b50a-9b41a11086f0} - (no file)
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\PROGRA~1\iolo\SYSTEM~1\PopupStopper.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.daewoointernational.ca
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: W2k PCtel speaker phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe

Thank you in advance.
Hi Paul, Welcome to TomCoyote forum. You do have some nasties onboard, please follow these directions in the order they are posted:

1) Use this link to download, update and run CWShredder. Allow it to run and remove anything it locates. Please let me know the results in your next post.

2) Follow the instructions in this link to run Stinger: http://vil.nai.com/vil/stinger/

3) Download CCleaner from this link: http://www.ccleaner.com/ Take the time to review the instructions on the download page so that when I ask you to run it you will know what you are doing.

4) You are running TeaTimer, and it is a great program but it will prevent the fix we must make with HijackThis. Follow the instructions in the following link to turn TT off until you are done with HJT.
http://russelltexas.com/malware/teatimer.htm

5) WinPatrol will also prevent the changes we must make try right clicking the running icon, and exit. Make sure it is off.

5) We need a folder so HJT can store HJT.exe logs and backups for safety. Please use this information to create that folder.
http://www.bleepingcomputer.com/forums/tutorial94.html

6) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: CDllBho Object - {5A5B6916-ED71-4531-8018-E792DD44156E} - C:\WINDOWS\sdasa.dll
Hijacker, identified by McAfee as Trj/Agent.NE
O3 - Toolbar: (no name) - {c3a92a2e-b3ee-4b3b-b50a-9b41a11086f0} - (no file)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Let's check for trojans in case any are hiding, run this free online scan, scan the whole system and set it to clean or fix anything it locates. Let me know what it finds and the exact name and location of anything it locates but can't remove. You may be asked to install an ActiveX, please do so as this program is safe and it can not run without it.
http://www.windowsecurity.com/trojanscan/

Run CCleaner then restart the computer and post a new log in this same thread along with any feedback you have. Let us know how you are running.

Thanks…pskelley
TomCoyote forum
Slyware Warrior

PURGE SYSTEM RESTORE
When you are completely finished with the removal procedure and are satisfied that the threat has been removed follow these instruction:

http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam
pskelly. Thank you so very much. I was finally able to download the required software from another computer and go through the action steps last night. Everything looked good but I will do further testing this weekend and will post a reply here again. The only step I could not do was the windowsecurity trojenscan. My security setting and my ActiveX option buttons matched the recommended set-up from the site however I kept getting a "my security setting would not allow the software to load because of the ActiveX setting" message. I have also had similiar results when I have tried to get Windows XP updates from the Microsoft site (because of this I am still at update pack 1, I will try to load update pack 2 by disk). I will be completing the service1.symantec.com step shortly. Again many thanks, the virus caused some charges to my phone bill ( a 900 psychic line or something for which Bell has canceled the charges) and much frustration. You guys are the best. Paul, thankful dad.
Hi Paul, A couple of things off the top of my head:

1) I would not put Windows Xp Service Pack 2 on your computer until you are sure you are clean of all malware. See this information: http://www.microsoft.com/windowsxp/sp2/sp2_whattoknow.mspx

2) What firewall are you running? SP1's ICF does not do it, but if you are running say Zone Alarm free firewall, you can set it to block all internet activity, both in and out, probably too late to mention this :(

3) These instruction I usually give when the computer is clean, but Grinler at BleepingComputer has a good tutorial about how to set your ActiceX controls so you would get a prompt and be able to allow something you know is valid like a trojan scan.
http://www.bleepingcomputer.com/forums/topict2520.html

4) Here is a free trial period download of a good trojan tool:
http://www.misec.net/trojanhunter/ It will at least let you know the computer is clean of trojans prior to considering the SP2 download.
A couple of more free scans for your toolbox:
http://housecall.trendmicro.com/housecall/start_corp.asp
http://www.pandasoftware.com/activescan/co…n_principal.htm
http://www.bitdefender.com/scan/license.php
http://www.kaspersky.com/scanforvirus.html
http://www.ravantivirus.com/scan/

5) Post a log…I am here to help, I can watch and give you feedback about your log so you will know that new has not gotten onboard and the progress you are making at removing the bad stuff.

6) If you are talking about this step: When you are completely finished with the removal procedure and are satisfied that the threat has been removed follow these instruction:

http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

It will be better if you wait until you know you are clean to do this. This step will wipe clean System Restore and give you a fresh start. Paul, if there are any questions I may be able to help with, please do not hesitate to post them. Thanks…Phil :wavey:
Hello Paul, I have not heard from you in ten days. I will assume you are through with our services and close this thread in 24 hours. Thanks…pskelley
I apoligize for not replying earlier but I am still stuck on action item 6 of your first post (running Trojanscan). I have followed the instructions provided on the website but no luck. I have also tried to set up the ActiveX controls as per item 3 of your last post (bleeping computer topic 2520) however I was able to set up the Internet Security level for items 1.4 a,b,and c (from topic 2520) but options d)e) and f) do not appear on my computer. I have the following options d) Run ActiveX controls and plug ins, and e) Script AX controls marked safe for scripting. After several tries, I have not yet figured out a combination that lets me use trojanscan without the message poping up about not being allowed do to security controls and Active X. I am presently only running the Windows SP1 Firewall and will have to install one. Last night the process was slow as I only have dial-up at home and evertime I went onto a website (tomcoyote, windowsecurity.com) I would get a pop-up box asking me for a password. I do not know what program is generating this. Also I had problems logging on as paulthomson to tomcoyote last night. I am assuming this is a problem with my home computer as I had no problems from work today. Thank you very much for your assistance pskelly. Having a home computer with internet access is getting to be so difficult to maintain and keep clean as malware and pop-ups get even more aggressive.
Hi Paul, A lot of time has passed since I have seen a HJT log. Please post a new log, include any additional thoughts you have. I will review all of the information to date then make a suggestion as to how to proceed based on the condition of this new HJT log. Thanks for your post. Phil
Logfile of HijackThis v1.99.1
Scan saved at 7:46:09 PM, on 02/06/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Documents and Settings\Paul\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daewoointernational.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.daewoointernational.ca
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.daewoointernational.ca
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: W2k PCtel speaker phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I believe the malware is gone as my browser is no longer being hijacked. However I have not been able to do a trojan scan as my computer does not allow the scan from zonelabs.com or windowsecurity.com. A message pops up that the ActiveX setings do not allow the download. I have tried the suggested settings from the website but no good (detailed in May 31st post). I also get an anoying message box every time I visit a webpage saying the content advisor will not allow me to see this site. I put in a password to continue. I do not know what program is generating it. I did install Zone Alarm last night. I do not wish to update to XP2 until the problems are cleared.

I also have trouble loging into the internet. Last night I kept getting Error 31 messages and today my wife was able to get in but not to view any webpages. We can connect to the email service by our interner provider (295.ca) from a libary computer but not our home computer. We connect to the net about 1 in every 6 tries.

Thank you very much for your time in this matter Phil. If you are ever in Ottawa give me a call. :wavey:
Hello Paul, Let's start with ActiveX controls. First, understand that it is you, not your computer that controls this. You have the same operating sytem and the same version of Internet Explorer that I do. My settings are the same as Grinler suggests in the link to Bleeping Computer I posted for you and I can download these spyware scans with no problem. We are severely limited because we can't use programs that require ActiveX plugins in order to run. Here are Grinler's suggested settings. The one in red is key as these are signed ActiveX. Please note that I said suggested, it is your computer and you are the final word. Contols can be set so tight that you can't do anything online. In this case it seems something is set too tight and you should be getting asked if you wish to allow ActiveX when it is safe to do so.

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Perhaps this tutorial will help: http://support.real-time.com/browsers/secu…ie/activex.html Something in the way your browser settings are make is causing you not to be able to download these valid security programs, you will need to find out what that is, I can only provide you the information, you have to apply it.

I also get an anoying message box every time I visit a webpage saying the content advisor will not allow me to see this site.

This sounds like some kind a parental control setting, look in help then locate parental controls (search for it) and change the settings to what you wish them to be. This is for IE 5.5 but try looking here:
http://www.searchengines.com/kids/safe_searching_ie.html

I also have trouble loging into the internet. Last night I kept getting Error 31 messages and today my wife was able to get in but not to view any webpages. We can connect to the email service by our interner provider (295.ca) from a libary computer but not our home computer. We connect to the net about 1 in every 6 tries.

Use Googe to search for Error 31…lots of info and most of it seems to deal with your internet connections. I suggest you you get with your internet provider, with dialup it does not take much to cause a problem. It can also have to do with your phone lines. If you hear any static when you listen to the phone it can cause a problem, the connection not to be made or dropped. This can be tricky to troubleshoot. Here are some ideas that might help:
http://www.google.com/search?hl=en&q=inter…G=Google+Search

Tell you a quick story, I had MSN dialup and had a heck of a time with my connection and of course blamed MSN. Well, after months on the issue, here in Florida we have small reptiles called Anoles (little lizards), I finally narrowed the problem to line static being picked up as a command for the modem to disconnect and got my phone company involved. Seemed one of these Anoles had crawed in the box on the pole and electrocuted itself and it was laying across the wires causing just enough static to make this happen. My point is, do not rule out the possibliity the phone lines, either outside or in the house are causing the issue.

Did I tell you this log you posted is clean. Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Good luck and safe surfing…Phil

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Phil, I have made the changes suggested. I get a message prompting me if I wish to allow the ActiveX plugin. I respond yes. After a couple of minutes the computer is still poping up with the message about my security settings not allowing for the ActiveX plugin to work. I will continue to read all of the information you have sent and run what I am able to to try to resolve this. I was able to download trojanscan from another computer and scan my hard drive. It was clean, so that is very good news. Since I have some internet capabilitys I am wondering if I should complete the final step and purge system restore? Thank you for all your help. Paul.
Hi Paul, Good to hear from you. You said this:

I get a message prompting me if I wish to allow the ActiveX plugin. I respond yes.

I wish to be sure that you know only to say yes IF it is a Downloaded Program File you are aware of and want to download. It appears that before this change bad DPF's could download and install without your permission. If you did not initiate the download block it. Glancing at your most recent log I do not see Spybot TeaTimer activated and that will give you some additional realtime protection. http://www.washington.edu/computing/securi…pybot_inst.html
also both Ad-aware and Spybot just released upgrades and you should make sure you are up to date here: http://tomcoyote.org/aawsb.php Here is some Google information that may help: http://www.google.com/search?sourceid=navc…weaking+activeX
And YES I would purge all old System Restores files, make sure you reboot after turning it off, then turn it back on right away. The SR files will be clean of malware at that point.

Thanks, Phil
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI