Home page rerouting by something...

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Locked
User avatar
El Moose Monstero
Moose Rebellion Ambassador
Posts: 3743
Joined: 2003-04-30 12:33pm
Location: The Cradle of the Rebellion... Oop Nowrrth, Like...
Contact:

Home page rerouting by something...

Post by El Moose Monstero »

Very briefly here, but it's pissing me off, something is rerouting my home page on IE to various similar search engines, nothing lewd or anything, but it keeps resetting it to these sites, no matter how many times, I've run the updated spyware search and destroy program, emptied all temp files and cookies, done everything I can think of. I ran that Hijackthis! program mentioned in the announcements thread, but it was all greek to me, can anyone help out here? It's slightly annoying.

(And of course, the good mods can lock this after problem solved...)

Ta chaps...
Image
"...a fountain of mirth, issuing forth from the penis of a cupid..." ~ Dalton / Winner of the 'Frank Hipper Most Horrific Drag EVAR' award - 2004 / The artist formerly known as The_Lumberjack.

Evil Brit Conspiracy: Token Moose Obsessed Kebab Munching Semi Geordie
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

Run HijackThis! PRONTO!

Post the log here, and one of us geeks will run through it for you.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
El Moose Monstero
Moose Rebellion Ambassador
Posts: 3743
Joined: 2003-04-30 12:33pm
Location: The Cradle of the Rebellion... Oop Nowrrth, Like...
Contact:

Post by El Moose Monstero »

Hang on, I've spotted the entry on the list, thanks... :) I was looking for the place it was sending me too, not the address listed on the internet options... this should solve it fingers crossed...

EDIT: Well, it didnt, I deleted the relevant entries, but they just reappeared again...

Logfile of HijackThis v1.97.7
Scan saved at 21:02:15, on 08/01/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~2\SYMANT~1\DefWatch.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\WINDOWS\system32\cba\pds.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\SYMANT~2\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cba\xfr.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Kontiki\bin\kontiki.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Games\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http: //81.211.10 5.9/search.php?v=3
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://81.211.105.9/in dex.php?v=3
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http: //81. 211.105.9/ind ex.php?v=3

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus8l.hpwis.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http: //qus8l.hpw is.com/
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh309190.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\PROGRA~1\NORTON~1\Cfgwiz.exe /R
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [cnet] "C:\Program Files\Kontiki\bin\kontiki.exe" -s cnet -q
O4 - HKLM\..\RunOnce: [tlc] C:\WINDOWS\update12.js
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh309190.dll/201
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc ... tor/sw.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwe ... .0.0.6.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/017b344310588e0c6e ... xIE601.cab
O16 - DPF: {59131903-4A33-40D5-80C2-5242DD365AB3} - http://www.swissquake.ch/chumbalum-soft ... werOCX.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E9041F85-3C18-4A7E-A29D-E24F84B79BF1} - http://64.7.220.98/downloads/UGO20.exe
Last edited by El Moose Monstero on 2004-01-09 12:53am, edited 2 times in total.
Image
"...a fountain of mirth, issuing forth from the penis of a cupid..." ~ Dalton / Winner of the 'Frank Hipper Most Horrific Drag EVAR' award - 2004 / The artist formerly known as The_Lumberjack.

Evil Brit Conspiracy: Token Moose Obsessed Kebab Munching Semi Geordie
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

Well, since you seem to have it under control at the moment, here's a better permanent solution to your malware problem.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
El Moose Monstero
Moose Rebellion Ambassador
Posts: 3743
Joined: 2003-04-30 12:33pm
Location: The Cradle of the Rebellion... Oop Nowrrth, Like...
Contact:

Post by El Moose Monstero »

Never a truer word spoken, have been meaning to get round to changing to Mozilla for ages... might as well be now. Just to clarify, malware?
Image
"...a fountain of mirth, issuing forth from the penis of a cupid..." ~ Dalton / Winner of the 'Frank Hipper Most Horrific Drag EVAR' award - 2004 / The artist formerly known as The_Lumberjack.

Evil Brit Conspiracy: Token Moose Obsessed Kebab Munching Semi Geordie
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

The_Lumberjack wrote:Never a truer word spoken, have been meaning to get round to changing to Mozilla for ages... might as well be now. Just to clarify, malware?
MALicious softWARE.

Edit: Here you go, I think you have the CoolWebSearch... uh... trojan. CWShredder should fix it.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
El Moose Monstero
Moose Rebellion Ambassador
Posts: 3743
Joined: 2003-04-30 12:33pm
Location: The Cradle of the Rebellion... Oop Nowrrth, Like...
Contact:

Post by El Moose Monstero »

Ah... :oops: Sorry... :)
Image
"...a fountain of mirth, issuing forth from the penis of a cupid..." ~ Dalton / Winner of the 'Frank Hipper Most Horrific Drag EVAR' award - 2004 / The artist formerly known as The_Lumberjack.

Evil Brit Conspiracy: Token Moose Obsessed Kebab Munching Semi Geordie
User avatar
Shadowhawk
Jedi Knight
Posts: 669
Joined: 2002-07-03 07:19pm
Location: Western Washington
Contact:

Post by Shadowhawk »

The_Lumberjack wrote:Hang on, I've spotted the entry on the list, thanks... :) I was looking for the place it was sending me too, not the address listed on the internet options... this should solve it fingers crossed...

EDIT: Well, it didnt, I deleted the relevant entries, but they just reappeared again...
Check & eliminate these lines:
C:\Program Files\Kontiki\bin\kontiki.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http: //81.211.10 5.9/search.php?v=3
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://81.211.105.9/in dex.php?v=3
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http: //81. 211.105.9/ind ex.php?v=3

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus8l.hpwis.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http: //qus8l.hpw is.com/
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh309190.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL

O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

O4 - HKCU\..\Run: [cnet] "C:\Program Files\Kontiki\bin\kontiki.exe" -s cnet -q
O4 - HKLM\..\RunOnce: [tlc] C:\WINDOWS\update12.js
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh309190.dll/201
O14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.com
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwe ... .0.0.6.cab
O16 - DPF: {E9041F85-3C18-4A7E-A29D-E24F84B79BF1} - http://64.7.220.98/downloads/UGO20.exe
Kontiki's an annoying one.
Go to http://www.spywareinfo.com and download CWShredder, Spybot Search & Destroy, and Ad-Aware 6. All three of these programs compliment each other well.
Shadowhawk
Eric from ASVS
"Sufficiently advanced technology is often indistinguishable from magic." -- Clarke's Third Law
"Then, from sea to shining sea, the God-King sang the praises of teflon, and with his face to the sunshine, he churned lots of butter." -- Body of a pharmacy spam email

Here's my avatar, full-sized (Yoshitoshi ABe's autograph in my Lain: Omnipresence artbook)
User avatar
El Moose Monstero
Moose Rebellion Ambassador
Posts: 3743
Joined: 2003-04-30 12:33pm
Location: The Cradle of the Rebellion... Oop Nowrrth, Like...
Contact:

Post by El Moose Monstero »

Deleted everything on the list but the ones that keep reappearing are the underlined R1 and R0 entries... :(
Image
"...a fountain of mirth, issuing forth from the penis of a cupid..." ~ Dalton / Winner of the 'Frank Hipper Most Horrific Drag EVAR' award - 2004 / The artist formerly known as The_Lumberjack.

Evil Brit Conspiracy: Token Moose Obsessed Kebab Munching Semi Geordie
User avatar
Shadowhawk
Jedi Knight
Posts: 669
Joined: 2002-07-03 07:19pm
Location: Western Washington
Contact:

Post by Shadowhawk »

The_Lumberjack wrote:Deleted everything on the list but the ones that keep reappearing are the underlined R1 and R0 entries... :(
Something that's currently running is re-inserting those entries every time they get deleted. You need to end the processes of the programs doing that, which are probably mwsoemon.exe and kontiki.exe. You may have to go into Safe Mode to do this.
Also, running Ad-Aware will probably kill and get rid of these programs for you; they're well-known hijackers.
Shadowhawk
Eric from ASVS
"Sufficiently advanced technology is often indistinguishable from magic." -- Clarke's Third Law
"Then, from sea to shining sea, the God-King sang the praises of teflon, and with his face to the sunshine, he churned lots of butter." -- Body of a pharmacy spam email

Here's my avatar, full-sized (Yoshitoshi ABe's autograph in my Lain: Omnipresence artbook)
User avatar
El Moose Monstero
Moose Rebellion Ambassador
Posts: 3743
Joined: 2003-04-30 12:33pm
Location: The Cradle of the Rebellion... Oop Nowrrth, Like...
Contact:

Post by El Moose Monstero »

Problem solved, that spywareinfo thing had an online program which seemed to get rid of the program itself, restarting and rereunning the Hackthis! program solved the problem.

Thanks, both of you. :)
Image
"...a fountain of mirth, issuing forth from the penis of a cupid..." ~ Dalton / Winner of the 'Frank Hipper Most Horrific Drag EVAR' award - 2004 / The artist formerly known as The_Lumberjack.

Evil Brit Conspiracy: Token Moose Obsessed Kebab Munching Semi Geordie
User avatar
Xon
Sith Acolyte
Posts: 6206
Joined: 2002-07-16 06:12am
Location: Western Australia

Post by Xon »

Also get SpywareBlaster, it sets a "kill bit" which prevents a wide range of known spyware ActiveX from being run by IE.
"Okay, I'll have the truth with a side order of clarity." ~ Dr. Daniel Jackson.
"Reality has a well-known liberal bias." ~ Stephen Colbert
"One Drive, One Partition, the One True Path" ~ ars technica forums - warrens - on hhd partitioning schemes.
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22637
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Post by Dalton »

Rock on.
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
Locked