Unsolved
This post is more than 5 years old
26 Posts
0
32026
July 13th, 2004 01:00
Hijacked Homepage called Home Search
My default homepage was hijacked and changed to "Home Search." Tools>internet options will not change it back to the default homepage. The address bar is res://nfwen.dll/index.html#12802. NortonAntiVirus lists the file names: apiok32.exe, javaxx32.exe, javaxx32.exe, niscvfs.dat, qvvviv.dat (all Adware.Iefeats), but does not delete them. Ad-aware 6, and Spybot would not delete these. When Internet Explorer is opened the homepage is the hijacked "Home Search" with a microsoft flag logo and has an index list and says Search the Web with a Search box. My Favorites are the same (in Dell there is a gigabuys.com?). When I click Start>Control Panel>Add or remove programs (currently installed programs) there is a "Home Search Assistent" (with a clue: Assistent is spelled wrong 'ent' instead of 'ant'), a Search Extender, and a Shopping Wizard. Were Home Search Assistent, Search Extender, and Shopping Wizard pre-installed or part of the problem? Another issue besides the hijacked homepage called "Home Search" is on web sites some words are highlighted to click on that go to a search page for that word. The words are not even highlighted on other computers. For example, on a web page the word contacts is highlighted and when clicked on goes to
www.runsearch.com/top/go.php?qq=contacts and says looking for contact lenses, search the web:contacts. Also, on microsoft.com (spyware is highlighted), and on tomcoyote.com the word computer is clickable, bottom left of the screen says goto:computer and goes to a search page for computers. I will attempt to run and when done, post the HijackThis results here and go from there. Thanks.
No Events found!


Life27
26 Posts
0
July 14th, 2004 04:00
Logfile of HijackThis v1.98.0
Scan saved at 12:46:39 AM, on 7/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\ipcm32.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\apiok32.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mlkgy.dll/sp.html#12802
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://mlkgy.dll/index.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mlkgy.dll/index.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\mlkgy.dll/sp.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mlkgy.dll/sp.html#12802
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://mlkgy.dll/index.html#12802
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {B1E7A707-24E5-6544-421B-A738C2B36E3A} - C:\WINDOWS\system32\ipkp.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [apiok32.exe] C:\WINDOWS\system32\apiok32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll
Texruss
2 Intern
•
3.4K Posts
0
July 14th, 2004 05:00
As requested:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mlkgy.dll/sp.html#12802
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://mlkgy.dll/index.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mlkgy.dll/index.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\mlkgy.dll/sp.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mlkgy.dll/sp.html#12802
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://mlkgy.dll/index.html#12802
O2 - BHO: (no name) - {B1E7A707-24E5-6544-421B-A738C2B36E3A} - C:\WINDOWS\system32\ipkp.dll
O4 - HKLM\..\Run: [apiok32.exe] C:\WINDOWS\system32\apiok32.exe
Also this hostile file in Running Processes:
C:\WINDOWS\ipcm32.exe
HTH,
Texruss
Life27
26 Posts
0
July 14th, 2004 12:00
About:Buster Version 1.27
Removed! : C:\WINDOWS\lhxin.dll
Removed! : C:\WINDOWS\mlkgy.dll
Removed! : C:\WINDOWS\pxxow.dll
Removed! : C:\WINDOWS\xdlqnq.dat
Error Removing! : C:\WINDOWS\System32\apiok32.exe
Removed! : C:\WINDOWS\System32\hipvv.dat
Removed! : C:\WINDOWS\System32\jxhnr.dat
Removed! : C:\WINDOWS\System32\liskm.dat
Removed! : C:\WINDOWS\System32\sdkdf32.exe
Removed! : C:\WINDOWS\System32\tyobd.dat
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
Life27
26 Posts
0
July 14th, 2004 12:00
Above is the second Buster Report. I ran HJT again and FC the 2 O's. Then ran About:Buster again. The AB Report still said, Error Removing!:C:\WINDOWS\System32\apiok32.exe. When I opened Internet Explorer to get back to this forum there was google.com, a pleasure to see, and would be nice to have a familiar default homepage again. I will now follow the advice from the two Texruss messages above regarding trying to delete apiok and ipcm in the task manager before continuing the Fix 2 directions to Restart and post a new HJT to this DELL Forum. The knowledge,skill, and advice has been really appreciated. Have a happy day.
Life27
26 Posts
0
July 14th, 2004 15:00
Texruss
2 Intern
•
3.4K Posts
0
July 14th, 2004 19:00
>Went to Task Manager. There was nothing in the Applications tab. In the Proccesses tab(Running Processes) there is ipcm32.exe System 00 1,248k. In Processes there is a 'End Process' button on the botom of Task Manager, but no Delete. Also, by right clicking there is no delete. Because there was no Delete I did not do anything with ipcm32.exe there. In Task Manager, Processes, there was no apiok. Next, I will try Safe Mode and see if I notice these there and see if there is a Delete there to Delete them.
You can't delete in Task Manager....it stops processes. You must delete using Windows Explorer. When you reboot the hostile files may mutate and you are back where you started.
Texruss
Life27
26 Posts
0
July 14th, 2004 22:00
Logfile of HijackThis v1.98.0
Scan saved at 7:51:24 PM, on 7/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\ipcm32.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\apiok32.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nnclg.dll/sp.html#12802
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://nnclg.dll/index.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://nnclg.dll/index.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\nnclg.dll/sp.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nnclg.dll/sp.html#12802
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://nnclg.dll/index.html#12802
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {271363C4-4477-FB41-7906-D3C2C7F0D6BE} - C:\WINDOWS\system32\sdkdf32.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [apiok32.exe] C:\WINDOWS\system32\apiok32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll
Life27
26 Posts
0
July 14th, 2004 22:00
Texruss
2 Intern
•
3.4K Posts
0
July 15th, 2004 00:00
Whether in Safe or Normal Mode...you have a Start button.
Open Windows Explorer: type the word explorer at Start/Run box and click OK:
Navigate down the folder structure in left hand window and then in the right window delete the bad files.
HTH,
Texruss
Texruss
2 Intern
•
3.4K Posts
0
July 15th, 2004 00:00
You know the bad R1 and R0 lines by heart now...the bad files otherwise in current Windows session:
C:\WINDOWS\system32\sdkdf32.dll
C:\WINDOWS\system32\apiok32.exe
C:\WINDOWS\msopt.dll
Life27
26 Posts
0
July 15th, 2004 02:00
About:Buster Version 1.27
Removed! : C:\WINDOWS\lhxin.dll
Removed! : C:\WINDOWS\nnclg.dll
Removed! : C:\WINDOWS\pyzyl.dat
Removed! : C:\WINDOWS\sdpbi.dat
Removed! : C:\WINDOWS\xdlqnq.dat
Removed! : C:\WINDOWS\System32\apiok32.exe
Removed! : C:\WINDOWS\System32\mkjpl.dat
Removed! : C:\WINDOWS\System32\sdkdf32.exe
Removed! : C:\WINDOWS\System32\svddk.dll
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
Life27
26 Posts
0
July 15th, 2004 02:00
Life27
26 Posts
0
July 15th, 2004 16:00
Enabled viewing of hidden files (bleepingcomputer). Opened Windows Explorer (Start>Run>explorer,ok). Went to My Documents, looked through folders, (C:), etc, saw in Offline web pages About:Home 0 bytes ? looked in System 32 saw nothing. In Windows>Prefetch> I saw a APIOK32.E...,IPCM32.EXE-3442EDFC.pf, JAVAXX32.E, and SDKDF), and thought that all of these except IPCM was deleted by About:Buster? A side question (not expected to be answered), Does About:Buster remove the _NS_Service if it exists in the registry, should it be checked in (Start>Run>REGEDIT)to make sure it did. I read that the _NS_Service_ if it exists may be removed by About:Buster anyway. Another side, I noticed there is a faded desktop . ini icon there now (probibly from showing hidden things). My question for this post is stlll how to find and delete C:\WINDOWS\ipcm32.exe that is a bad file in Task Manager(Running Processes). Even after viewing hidden files I still did not see C:\WINDOWS\ipcm32.exe using the folder structure. How do I delete ipcm32 from Task Manager in Windows Explorer?? Is there a folder for files in Task Manager, didn't see any. Can ipcm32 be typed into a search there to find it? What to do to find ipcm in TaskManager using Windows Explorer? Thanks.
Life27
26 Posts
0
July 15th, 2004 18:00
For my information, in rerular mode went to My Computer-Manage-Network Security Service and saw
path to executable:
C:\WINDOWS\ipcm32.exe/s
startup type: Automatic
Life27
26 Posts
0
July 15th, 2004 21:00