Unsolved

This post is more than 5 years old

2 Intern

 • 

15 Posts

35669

April 24th, 2004 22:00

mk:@MSITStore:C:\WINDOWS\start.chm::/start.html

I was infected with the mk:@MSITStore:C:\WINDOWS\start.chm::/start.html hijack a few days ago and have been trying to get rid of this pesky thing. There's a lot of help on various BBs but I haven't yet found a full solution for eradicating this beast from my PC.  No one seems to know where this hacker hides itself but it's on my PC waiting for my start.chm file to be removed so it can write a new one and fill it with it's garbage to redirect me to a useless website.  Here's the story so far:

I run NAV with latest updates as a matter of course (not that this will touch this type of critter).  I've been running CWShredder, Ad-aware, and SpyBot for several months since I previously contracted CWS.  Yesterday I downloaded SpyBlaster and SpyGuard.

Like many other before me the usual signs were there. NOTEPAD.exe was gone but there was a NOTEPAD.exe.bak in it's place. I've sorted that out.   START.chm was there with it's payload. I tried deleting the contents yesterday and setting the file to read only. But at some point the file as deleted - I think it may be as a result of running one of the many pieces of Spyware software above but can't say for sure.   Deleted the R0 entries that show within HijackThis.

Ad-Aware showed some other registry entries so I got rid of them.

I rebooted the PC several times yesterday evening and each time all was well. I went to bed thinking maybe it's sorted. When my wife used the PC this morning she fired up Outlook, which connects automaticlly to our hotmail account and SpyGuard popped up the warning that the IE homepage was being changed. From the SpyGurad messge alert, I opted to revert to my previous homepage, and notice that start.chm is back. Again I have deleted it's contents and made the file read only.

I'm not sure if this will help you guys but here's the SpyGuard log from this morning when the attempt occurred to change my homepage:
--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 09:39:36 04/24/2004 a browser page change was detected.
Registry Location: HKCU\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value:
http://www.msn.com/
New Value: mk:@MSITStore:C:\WINDOWS\start.chm::/start.html
User Action Taken: RESTORE OLD VALUE
--------------------------------------------------------------------------------
BROWSER HIJACK ALERT - BROWSER PAGE CHANGED
On 09:39:41 04/24/2004 a browser page change was detected.
Registry Location: HKLM\Software\Microsoft\Internet Explorer\Main\
Value Name: Start Page
Old Value:
http://www.msn.com/
New Value: mk:@MSITStore:C:\WINDOWS\start.chm::/start.html
User Action Taken: RESTORE OLD VALUE


On further investigation I found that CWShredder removes the start.chm file to the recycle bin. Even though CWS reports no infection it is deleting my start.chm file. I can watch it delete from the Windows directory and appear in my recycle bin when CWS is run. So CWS appears to present only a part solution and by deleting my start.chm file, which I have marked as read only, it's opening the door for this hijacker to set-up a new start.chm.

I have been advised of the workaround to remove the file association in Windows that allows CHM files to be executable but the problem with this is that you will be disabling all CHM files so Windows Help will be effectively disabled. It also doesn't remove the thing from my PC just hides the symptoms.

I may have this thing under control but who knows what else it's trying to do or waiting to do on my machine and I am peeved that it's still there. Something is on the PC waitig for it to connect to the internet before resetting the homepage and changing files etc. on my PC

Here's the HJT log to get the ball rolling:

Logfile of HijackThis v1.97.7
Scan saved at 12:18:03, on 24/04/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SpywareGuard\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext =
http://www.euro.dell.com/countries/uk/enu/gen/default.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\SpywareGuard\dlprotect.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) -
http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1072824130971
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) -
https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) -
http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab

No Responses!
No Events found!

Top