New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 939
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

[FIXED]Myexexex.com Hijackings

 
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Hijackthis - Spyware, Viruses, Worms, Trojans Oh My!
View previous topic :: View next topic  
Author Message
bjc210
Warnings : 1

Cadet
Cadet



Joined: Apr 25, 2004
Posts: 8
Location: Birmingham, UK

PostPosted: Wed Jun 02, 2004 2:18 pm    Post subject: Myexexex.com Hijackings
Reply with quote

Hi all. Recently I've been having homepage hijackings and address bar hijackings. As you will see in the attached HijackThis log, they link to www.myexexex.com. Let me explain some of the effects.
Arrow My homepage changes to C:\spad\start.htm - it contains porn links and when you delete it it comes back again a few days later.
Arrow If you don't put http:// in the web address, the computer adds it in for you, this has been changed to http://www.myexexex.com/search= or something like that so that unless you put http:// in every time you get redirected.
Arrow Obviously when you search using the address bar (although I don't very often due to having the Google Toolbar) it goes to myexexex.com too. Occasionally a link on my desktop appears with an X on it. The latest one links to http://www.casinopalazzo.com/index.php?sourceid=101969.
This whole hijacking just used to affect my user settings (I use WinXP) but now it has spread.
I have tried using Ad-Aware 6.0 and HijackThis in combination -- sometimes you can't "Fix" the items using HijackThis. Mostly eventually you can but it will re-appear a few days later. I believe there is some type of spyware on my system but I don't know.
Here is my HijackThis log:
--------------------------------
Logfile of HijackThis v1.97.7
Scan saved at 19:16:20, on 02/06/2004 **that's 2nd June for you Americans**
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\Launcher.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Norton Utilities\SYSDOC32.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\WINDOWS\system32\RDSHOST.exe
C:\WINDOWS\system32\sessmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\AKT\My Documents\Downloaded\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.myexexex.com/searchbar.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.myexexex.com/search.php?said=spage&qq=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/spad/start.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/spad/start.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.myexexex.com/searchbar.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.myexexex.com/search.php?said=spage&qq=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/spad/start.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.myexexex.com/search.php?said=spage&qq=%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.myexexex.com/search.php?said=spage
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.myexexex.com/search.php?said=spage
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [PrimaLauncher] C:\WINDOWS\System32\Launcher.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O13 - DefaultPrefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - WWW Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - Home Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - Mosaic Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - FTP Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - Gopher Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/broadband
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.ipswitch.com/_installs/wsftp_le/setup.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14e5dbf25d2...xIE601.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me...Client.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C...6449537037
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/softwa...Plugin.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by17fd.bay17.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF300152-0CAF-465C-B301-754FA5D7D88E}: NameServer = 212.74.114.129 212.74.114.193
-------------------
Hoping someone out there can help......
Adam T
Birmingham, UK


Last edited by bjc210 on Wed Jun 02, 2004 2:44 pm, edited 1 time in total
Back to top
View users profile Send private message
Homeboy

Trooper
Trooper



Joined: May 29, 2004
Posts: 21
Location: USA

PostPosted: Wed Jun 02, 2004 2:30 pm    Post subject:
Reply with quote

Shocked

This is Homeboy...I have experienced the same problem. These guys have been great help! One question: Did you get a desktop shorcut entitled "default" ?
Back to top
View users profile Send private message
bjc210
Warnings : 1

Cadet
Cadet



Joined: Apr 25, 2004
Posts: 8
Location: Birmingham, UK

PostPosted: Wed Jun 02, 2004 2:32 pm    Post subject: Re: Default icon
Reply with quote

hey Homeboy

Yes i did - it has an X on it

-- Adam
Back to top
View users profile Send private message
Homeboy

Trooper
Trooper



Joined: May 29, 2004
Posts: 21
Location: USA

PostPosted: Wed Jun 02, 2004 2:49 pm    Post subject:
Reply with quote

That's the one... You can see my post thread entitled: "Another New Browser Page Change? Sad

I can tell you that this is a newer hijack and they are working on it... We got to hang in and give them some time...

Shocked
Back to top
View users profile Send private message
bjc210
Warnings : 1

Cadet
Cadet



Joined: Apr 25, 2004
Posts: 8
Location: Birmingham, UK

PostPosted: Wed Jun 02, 2004 2:56 pm    Post subject:
Reply with quote

OK - thanks,
I'll have to hope for the best. Were they able to cure you completely?

--Adam
Back to top
View users profile Send private message
Mosaic1

Site Moderator
Site Moderator



Joined: Jan 15, 2004
Posts: 4760
Location: USA

PostPosted: Wed Jun 02, 2004 2:58 pm    Post subject:
Reply with quote

Copy the contents of the quote box to notepad. Name as Spad.reg
save as type all files.

Quote:

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B}]
[-HKEY_CLASSES_ROOT\CLSID\{BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B}]
[-HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{869EE607-5376-486d-8DAC-EDC8E239AD5F}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{237AA178-C3BC-4f67-A8BB-D8BC14BA0B89}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{237AA178-C3BC-4f67-A8BB-D8BC14BA0B89}]
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\{237AA178-C3BC-4f67-A8BB-D8BC14BA0B89}]


Restart into Safe mode.

Directions here if you need help:
http://service1.symantec.com/SUPPORT/ts...2409420406
Double click on spad.reg to enter into the registry.


Look in System32 and in
%Userprofile%\Local Settings\Temp
folder for this file and delete it.

HPCMDTY.DLL

Delete this folder:
C:\spad

Look for these files and delete them if found:
C:\WINDOWS\System32\c_10230.dll
C:\WINDOWS\System32\crt32_v2.dll
C:\WINDOWS\System32\crt2_v32.dll
---------
Close All Windows and Folders. Select the following items and press Fix checked:[b]



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.myexexex.com/searchbar.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.myexexex.com/search.php?said=spage&qq=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/spad/start.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/spad/start.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.myexexex.com/searchbar.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.myexexex.com/search.php?said=spage&qq=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/spad/start.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.myexexex.com/search.php?said=spage&qq=%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.myexexex.com/search.php?said=spage
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.myexexex.com/search.php?said=spage

O13 - DefaultPrefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - WWW Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - Home Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - Mosaic Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - FTP Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
O13 - Gopher Prefix: http://www.myexexex.com/search.php?said=pfxp&qq=
------------

Empty your Temporary Internet Files and history in Internet Options. And clean out your
%Userprofile%\Local Settings\Temp
folder. It's a good idea to do that regularly.

---------------
Restart into Regular Windows Mode.
Run HijackThis again and post the new log in your next reply in this same topic.
--------------------
Back to top
View users profile Send private message
bjc210
Warnings : 1

Cadet
Cadet



Joined: Apr 25, 2004
Posts: 8
Location: Birmingham, UK

PostPosted: Wed Jun 02, 2004 5:25 pm    Post subject: Re: Myexexex - Hijack This Log
Reply with quote

OK, I did as much as I could but
Quote:
Look in System32 and in
%Userprofile%\Local Settings\Temp
folder for this file and delete it
HPCMDTY.DLL

wasn't there. Confused
Attached is the HijackThis log I've done now
-------------
Logfile of HijackThis v1.97.7
Scan saved at 22:19:33, on 02/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\Launcher.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Norton Utilities\SYSDOC32.EXE
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\AKT\My Documents\Downloaded\hijackthis\HijackThis.exe

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [PrimaLauncher] C:\WINDOWS\System32\Launcher.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/broadband
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.ipswitch.com/_installs/wsftp_le/setup.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14e5dbf25d2...xIE601.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me...Client.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C...6449537037
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/softwa...Plugin.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by17fd.bay17.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF300152-0CAF-465C-B301-754FA5D7D88E}: NameServer = 212.74.114.129 212.74.114.193
------------------
I haven't had any problems since this - thanks - although I'm not sure that it's totally gone yet Confused
Can you tell me exactly what your fix did Question
--Adam
P.S. As I live in the UK, my next response will be tomorrow
Back to top
View users profile Send private message
Mosaic1

Site Moderator
Site Moderator



Joined: Jan 15, 2004
Posts: 4760
Location: USA

PostPosted: Wed Jun 02, 2004 7:14 pm    Post subject:
Reply with quote

I tremoved the loading point for this and stopped the auto reinstall it had set up.

Go ahead and reset your Home and search pages and then see how it goes.

This entry should be fixed using Hijackthis as well:

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14e5dbf25d2...xIE601.cab
Back to top
View users profile Send private message
bjc210
Warnings : 1

Cadet
Cadet



Joined: Apr 25, 2004
Posts: 8
Location: Birmingham, UK

PostPosted: Thu Jun 03, 2004 5:33 am    Post subject:
Reply with quote

OK - done that. It doesn't appear to be reoccurring yet (as of 10:30 GMT) so thanks and I'll get back to you if it reoccurs again

--Adam Smile
Back to top
View users profile Send private message
Mosaic1

Site Moderator
Site Moderator



Joined: Jan 15, 2004
Posts: 4760
Location: USA

PostPosted: Thu Jun 03, 2004 5:40 am    Post subject:
Reply with quote

After something like this it is a good idea to Flush the Restore Points and start fresh.
To flush the XP system Restore Points.

Go to Start>Run and type msconfig Press enter.

When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.

Check the box labeled Turn off System restore.


Reboot. Go back in and Turn System Restore Back on. A new Restore Point will be created.
----------------------------
Also here is an excellent source for tips to tighten security. Follow the advice and get the free downloads to help avoid some of these problems in the future.
http://www.computercops.biz/postt7736.html
Back to top
View users profile Send private message
Mosaic1

Site Moderator
Site Moderator



Joined: Jan 15, 2004
Posts: 4760
Location: USA

PostPosted: Fri Jun 04, 2004 1:38 pm    Post subject:
Reply with quote

Sandog,

We can only help one person at a time in any topic. I have split off your question to its own thread. Please work there until your problem has been resolved.


Here's a link to it:
http://computercops.biz/postt47195.html
Mosaic1
Back to top
View users profile Send private message
wadeige

Cadet
Cadet



Joined: Jun 05, 2004
Posts: 1
Location: Japan

PostPosted: Sat Jun 05, 2004 2:40 am    Post subject:
Reply with quote

Mosaic1,

Since a few days my pc was showing the same symptoms as bjc210's so I tried to follow the instructions you gave him. Several files were not on my system, but as far as I can see ... it worked!

One thing, could you give a short explanation of what the registry changes (Spad.reg) are for? I mean, what exactly was "infected" on my machine?

Thanks for all your help.

-- Peter
Back to top
View users profile Send private message
Mosaic1

Site Moderator
Site Moderator



Joined: Jan 15, 2004
Posts: 4760
Location: USA

PostPosted: Sat Jun 05, 2004 2:49 am    Post subject:
Reply with quote

wadeige,

Please start your own topic if you need more help. The registry changes removed the hijack by removing the exporer extensions and Class ID's which were responsible.

Mo
Back to top
View users profile Send private message
azn_gamer2003

Cadet
Cadet



Joined: Jun 05, 2004
Posts: 6
Location: USA

PostPosted: Sat Jun 05, 2004 12:16 pm    Post subject:
Reply with quote

[quote="Mosaic1"]Copy the contents of the quote box to notepad. Name as Spad.reg
save as type all files.

Quote:

Restart into Safe mode.

Look in System32 and in
%Userprofile%\Local Settings\Temp
folder for this file and delete it.


Coupla questions (I'm kinda new here, so don't flame me plz.

1)What is the difference between doing this in safe mode and normal mode? Will one save changes and the other won't? W
2)here is the %Userprofile%\Local Settings\Temp folder? I have tried searching for it and I can't find it.
3)When I tried to run Spad.reg in safe mode, I ran into an error saying that only vertain file types can go into the registry. I copied it verbatim, but still it didn't work. Can anyone tell me why?
Back to top
View users profile Send private message
Mosaic1

Site Moderator
Site Moderator



Joined: Jan 15, 2004
Posts: 4760
Location: USA

PostPosted: Sat Jun 05, 2004 11:05 pm    Post subject:
Reply with quote

azn_gamer2003,

We can only help one person at a time in any thread. It is too confusing otherwise. Please start your own topic and ask your questions there. Post your hijackthis log. That reg file was for 2k and XP. Not for ME or 98.

The newest CWShredder now removes this hijack,so try that first.
Here's a link to it:

http://www.spywareinfo.com/downloads/tools/CWShredder.exe


--------------------------

We have had several people add their logs and questions here. The original Poster seems to have been repaired. I am going to lock this now. Anyone who needs help, please start your own topic.

Mosaic1
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Hijackthis - Spyware, Viruses, Worms, Trojans Oh My! All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops