Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice

[Solved] My IE has been hijacked.

1818 Views 25 Replies 3 Participants Last post by  Flrman1
My IE has been hijacked by allaboutsearching.com. I have Windows XP and have run SPYBOT, ADAWARE, HIJACKTHIS, and CWSHREDDER with no success. I am attaching my log from HIJACKTHIS and would appreciate any help from anyone.

Logfile of HijackThis v1.97.7
Scan saved at 12:40:31 AM, on 3/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\carpserv.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
C:\PROGRA~1\GridFlawTitle\five log.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\Administrator\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: DartCopyScr - {1C2E914F-C730-1F3C-E1C7-44365588E9C4} - C:\PROGRA~1\MOREHT~1\Bird admin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [fork64] C:\PROGRA~1\GridFlawTitle\five log.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir8d196a.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/install/guidedsolutions.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
See less See more
Status
Not open for further replies.
1 - 11 of 26 Posts
Hi Sandy Jeep

Welcome to TSG! :)

Run Hijack This again and put a check by these. Close all windows except HijackThis and click "Fix checked"

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)

O3 - Toolbar: DartCopyScr - {1C2E914F-C730-1F3C-E1C7-44365588E9C4} - C:\PROGRA~1\MOREHT~1\Bird admin.dll

O4 - HKLM\..\Run: [fork64] C:\PROGRA~1\GridFlawTitle\five log.exe

O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"

O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab


Restart to safe mode and delete:

The C:\Program Files\AutoUpdate folder
The C:\Program Files\GridFlawTitle folder
The C:\Program Files\MOREHT~1 folder

I have no way of knowing the exact name of that last folder, but the first six letters will be MOREHT.

How to start your computer in safe mode.
See less See more
Fix this one:

O4 - HKLM\..\Run: [fork64] C:\PROGRA~1\GRIDFL~1\five log.exe

Boot to safe mode and delete:

The C:\Program Files\GridFlawTitle folder
I don't see anything left in your log.

Do you have any kind of popup blocker?

Are the popups browser window popups or do they look like this?:

See less See more
This is your problem here:

VX2.BetterInternet Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Guardian

VX2.BetterInternet Object recognized!
Type : File
Data : msg121.dll
Object : c:\windows\system32\
FileSize : 301 KB
Created on : 3/19/2004 12:17:54 PM
Last accessed : 3/20/2004 11:38:18 PM
Last modified : 3/19/2004 12:17:54 PM

You have been infected by the Look2Me parasite. Go here and follow the removal instructions for XP/2k:

http://www10.brinkster.com/expl0iter/freeatlast/L2M/Msg121.htm
See less See more
Do you have other user profiles on this computer?
If you are the only user and you are the administrator then proceed with the removal.
Did you wait 15 secs? Try it again and wait a little longer.
I'm lookig into some other options, but for now try running Start.bat in safe mode then if it is successful run clean.bat and the rest in normal.

How to start your computer in safe mode.
You haven't extracted the files from the Zip folder. That's what the problem is. You need to right click on the msg121Fix.zip file and choose "Extract All" and extact the files to their own folder and then click on the Start.bat file. Let it run and then do the rest. That's why it hasn't been running the whole time. The files must be extracted first.
All donations go to the site, not me, but please go ahead and donate if you can. Your gratitude is enough for me.

I assume this means you were able to get everything to work.
Good job! :up:

Happy Surfing! :D
1 - 11 of 26 Posts
Status
Not open for further replies.
Top