Unsolved

This post is more than 5 years old

11308

December 19th, 2003 00:00

HijackThis log file

Hello, My problem is that my browser has been hijacked by fastsearch.cc, which continually makes itself my home page no matter how much I change it back to my normal one. I ran HijackThis, and here is the log file. If anyone has the time, could you tell me what I need to delete? Thank you very much! OBeigleighinn

Logfile of HijackThis v1.97.7
Scan saved at 21:32:24, on 18/12/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\HP DESKJET 610C SERIES\EREG\REMIND32.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://in.webcounter.cc/--/?cxlow (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://in.webcounter.cc/---/?cxlow (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://in.webcounter.cc/--/?cxlow (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://in.webcounter.cc/-/?cxlow (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://in.webcounter.cc/--/?cxlow (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://in.webcounter.cc/---/?cxlow (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://in.webcounter.cc/--/?cxlow (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://in.webcounter.cc/-/?cxlow about:blank (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://in.webcounter.cc/--/?cxlow (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://in.webcounter.cc/--/?cxlow (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://in.webcounter.cc/--/?cxlow (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://in.webcounter.cc/---/?cxlow (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/--/?cxlow (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/--/?cxlow (obfuscated)
F1 - win.ini: run=fntldr.exe hpfsched
O1 - Hosts: 66.40.16.234 auto.search.msn.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.ExE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Soundmx] C:\WINDOWS\SYSTEM\soundmx.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Reminder-hpc41004.lnk = C:\Program Files\HP DeskJet 610C Series\ereg\Remind32.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtw32.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37879.5500578704
O19 - User stylesheet: C:\WINDOWS\Web\tips.ini
O19 - User stylesheet: C:\WINDOWS\hh.htt (HKLM)

5 Posts

December 19th, 2003 05:00

I would first run and delete everything Spybot indicates.

http://hjt.wizardsofwebsites.com/ is a good site for explaining what the entries on you Hijack This log mean.

If I were you I would start be removing all the R0 and R1 references to "webcounters".

Good luck.

2 Intern

 • 

3.9K Posts

December 19th, 2003 07:00

Please xmbs, unless you are a hijackthis knowledgeable person (and I have not seen any post by you along those lines),  do not advise anyone to remove anything with hijackthis, they can hose thier system very easily.

To my knowledge, apart from me only three others are registered at DellTalk with that training, and most of those are not active yet in giving advice, still in training.

OBeigleighinn

Please run cwshedder for this CWS infection. Spybot will not be able to remove that.
Cwshredder
Download it, install (after unzip), run, delete all that it finds.

Then post a new hijackthis log for someone to check
DO NOT FIX ANYTHING WITH HIJACKTHIS WITHOUT EXPERT ADVICE
, most of what it finds you need for normal MS Windows tasks.

December 19th, 2003 16:00

Thanks--I haven't yet done anything with the HijackThis log file. I have downloaded CWShredder, but it didn't want to download from "current location" due to some application problem (?). However I have saved CWShredder to disc. So how do I now run it from the proper location?

Thanks again.

2 Intern

 • 

3.9K Posts

December 19th, 2003 17:00

Your log is now clean, cwshredder got the lot.

Follow the link below to my site, malware section, and install spywareblaster and spywareguard from the links.

Also http://www.staff.uiuc.edu/~ehowes/resource.htm with all those active you will be safer, do update them periodically.

2 Intern

 • 

3.9K Posts

December 19th, 2003 17:00

The location where you run hijackthis last time is OK, leave it there.

2 Intern

 • 

3.9K Posts

December 19th, 2003 17:00

Copy it to any folder on your hard drive and run. The same with hijackthis, just don't leave hijackthis in a temp internet folder, or the desktop.

December 19th, 2003 17:00

OK, will do. HijackThis is currently in a folder on Drive C--should I get it off there? (I have it on disc too.)
Thanks.

December 19th, 2003 17:00

Chris RLG, I've run CWShredder, which did indeed remove some things. I then re-ran Hijack This, and include the current log file. If you or anyone knowledgeable could tell me if there's anything else i need to remove through HijackThis, or could direct me to the proper forum, i'd be very thankful.
Thank you!

Logfile of HijackThis v1.97.7
Scan saved at 19:48:38, on 19/12/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\HP DESKJET 610C SERIES\EREG\REMIND32.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F1 - win.ini: run=hpfsched
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.ExE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Reminder-hpc41004.lnk = C:\Program Files\HP DeskJet 610C Series\ereg\Remind32.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtw32.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37879.5500578704

December 19th, 2003 18:00


First Off, Your Version of IE is very old. That IE 5 is very vulnerable. Download the New Version at http://www.microsoft.com/windows/ie/.

You really need to upgrade your IE version to v6. It fixes a lot of bugs including security bugs.

You can also DL it from this site aswell.  http://www.microsoft.com/windows/ie/default.asp

 



 

December 19th, 2003 18:00

Somewhere here there should be a section specifically for hijack logs..  like at SWI  huh  =)

2 Intern

 • 

3.9K Posts

December 19th, 2003 18:00

Good call misses, I missed that.

December 19th, 2003 20:00

Thanks for the advice. If I DL IE6 will i have to do anything else, re-set my browser settings or connections or anything? Or will DLing it automatically replace IE5 and leave everything else as it was?

December 19th, 2003 20:00

U should be fine, personally, i would rather reset a few things than to run IE5 than to put my puters life at risk!

but you should be ok...  and much better off in the long run  =)

 

December 20th, 2003 16:00

I've downloaded IE6 and everything seems to be fine.  Fingers crossed.  My thanks to everybody involved.

6 Posts

December 23rd, 2003 15:00

Hello forum,

I had the same problem with this adware too. I have spybot installed –it’s a great program- but didn’t removed the adware so I did a little of registry editing by myself to remove the adware. CAUTION !!! If you are unfamiliar with regedit don’t do it unless you are very very sure. Always save your registry before you make any changes.

Symantec helped with the registry until one point but I didn’t remove the adware.

Go to

http://www.symantec.com/avcenter/venc/data/adware.searchcounter.html

and do excactly what they say.

This is how Symantec says the adware will be removed but….. THE ADWARE STILL KEEPS COMING BACK ….

So I did some investigation by myself and came up with this:

I thought that this adware must have an .exe file somewhere and run every time I run my IE so I searched in the registry and my computer and found that it creates an .exe in the windows path like this: (maybe the value changes) 73A08744BE78_4C68_91E8_AE13955031AE.exe

and it was run in the registry:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU

a=

b=tips.ini

c=hh.htt

d=hh.htt

e=hosts

f=fntr*.*

g=*.exe

h=73A08744BE78_4C68_91E8_AE13955031AE.exe

MRUList=hgfaedcb

Just delete the values.

The same in HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU

Write your .exe file which is shown in the registry find it your computer and delete it too.

This worked for me and until now the adware did not come back.

PLEASE BE VERY CAREFUL WITH WHAT YOU ARE DOING. I WILL BE NOT RESPONSIBLE IF YOU DO ANY DAMAGE IN YOUR COMPUTER.

I run WIN98 and have IE6.

Please reply me if it works or not.

No Events found!

Top