hypoteches hijacked my desktop and shuts down my anti virus

Started by burnout_goddess · 9 posts · 2,025 views

  1. #1
    Sorry I am making my return with a plea for help, but I couldn't think of another place with all the smartest people in the world in one location.

    ok now that I have the ass kissing started...

    Short probelm background - Browsing things I shouldn't at work - Symantec (my anti virus) went insane. My desktop has been hijacked to a html saying "Warning! Spyware threat detected! System error #1752" with links to hypoteches site. My home page has also been wiped out - I just get about:blank now. Did AdAware and Symantec scan - nothing found. Spybot wouldn't update. Reboot in safe mode - ran anti virus nothing found. Run spybot 23 things found, but no SpyQuake, or hypoteches. Fix problems spybot found. Run AdAware, nothing found.

    Got HijackThis and scaned


    Logfile of HijackThis v1.99.1
    Scan saved at 9:45:32 AM, on 5/16/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:WINDOWSSystem32smss.exe
    C:WINDOWSsystem32winlogon.exe
    C:WINDOWSsystem32services.exe
    C:WINDOWSsystem32lsass.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSSystem32svchost.exe
    C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
    C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
    C:WINDOWSsystem32spoolsv.exe
    C:WINDOWSExplorer.EXE
    C:Program FilesCommon FilesSymantec SharedccApp.exe
    C:PROGRA~1SYMANT~1VPTray.exe
    C:Program FilesQuickTimeqttask.exe
    C:Program FilesSymantec AntiVirusDefWatch.exe
    C:Program FilesSymantec AntiVirusSavRoam.exe
    C:Program FilesSymantec AntiVirusRtvscan.exe
    C:Program FilesTrilliantrillian.exe
    C:hijackthis_199HijackThis.exe

    R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.dell.com
    R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 207.184.73.111:80
    R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = 207.184.73.110;<local>
    O1 - Hosts: 206.93.252.1 C132517
    O2 - BHO: HPOVASMD.BrowserSensor - {04047354-D353-11D2-B3EB-0060B03C5581} - C:WINDOWSDownloaded Program FileshpBrSn24.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
    O4 - HKLM..Run: [ccApp] \"C:Program FilesCommon FilesSymantec SharedccApp.exe\"
    O4 - HKLM..Run: [vptray] C:PROGRA~1SYMANT~1VPTray.exe
    O4 - HKLM..Run: [QuickTime Task] \"C:Program FilesQuickTimeqttask.exe\" -atboottime
    O4 - HKCU..Run: [msnmsgr] \"C:Program FilesMSN Messengermsnmsgr.exe\" /background
    O8 - Extra context menu item: &ieSpell Options - res://C:Program FilesieSpelliespell.dll/SPELLOPTION.HTM
    O8 - Extra context menu item: Check &Spelling - res://C:Program FilesieSpelliespell.dll/SPELLCHECK.HTM
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavaj2re1.4.2_03binnpjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavaj2re1.4.2_03binnpjpi142_03.dll
    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:Program FilesieSpelliespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:Program FilesieSpelliespell.dll
    O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:Program FilesieSpelliespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:Program FilesieSpelliespell.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
    O9 - Extra button: @C:Program FilesMessengerMsgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:Program FilesMessengerMsgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
    O16 - DPF: {04047354-D353-11D2-B3EB-0060B03C5581} (HPOVASMD.BrowserSensor) - https://dealerconnect.chrysler.com/w...gin/hpBrSn.cab
    O16 - DPF: {171B10C1-475C-11D4-8E21-005004718DC0} (Project1.UserControl1) - https://www.suzukidcs.com/cab/Prjaos.CAB
    O16 - DPF: {194129C5-CA7D-11D3-8E1F-005004718DC0} (wsndctl.ctlWsnd) - https://www.suzukidcs.com/cab/wsndctl.CAB
    O16 - DPF: {1A1965EB-2653-11D4-8E21-005004718DC0} (support.UserControl1) - https://www.suzukidcs.com/cab/suzsup.CAB
    O16 - DPF: {2345F907-F5CF-11D3-8E1F-005004718DC0} (scatdp2a.clsSuzuki) - https://www.suzukidcs.com/cab/scatdp2a.CAB
    O16 - DPF: {2D361311-74CA-11D2-B3F4-0060083BE8BF} (scatdp2.clsSuzuki) - https://www.suzukidcs.com/Cab/scatdp2.CAB
    O16 - DPF: {399548B6-253E-11D2-BE13-000000000000} (VPEngine ActiveX Control Class) - https://www.suzukidcs.com/cab/vpectrl3.cab
    O16 - DPF: {43241AD9-3A89-4815-9A9C-7D9B549AA13A} (prjEmptyRegular.ctlatRegular) - https://www.suzukidcs.com/cab/prj481E.CAB
    O16 - DPF: {4772479E-D3FB-11D3-9261-00104B6943CA} (w481.ctlatRegular) - https://www.suzukidcs.com/CAB/w481.CAB
    O16 - DPF: {477247AA-D3FB-11D3-9261-00104B6943CA} (w4831.ctlatCampaignShort) - https://www.suzukidcs.com/CAB/w4831.CAB
    O16 - DPF: {4EA5AA95-5B42-11DA-A56E-0003FFDCDC17} (SuzukiDiagnostic.CheckDB) - https://www.suzukidcs.com/cab/sd.cab
    O16 - DPF: {531CD468-D7BF-11D3-9261-00104B6943CA} (Scatdp4.clsSuzuki) - https://www.suzukidcs.com/cab/scatdp4.cab
    O16 - DPF: {55E14374-97C6-11D1-BF85-0060083BE8BF} (prjTitlebar2.TitleBar2) - https://www.suzukidcs.com/cab/prjTitlebar2.CAB
    O16 - DPF: {71E098B7-728F-11D2-B3F4-0060083BE8BF} (Scatdp1.clsSuzuki) - https://www.suzukidcs.com/cab/Scatdp1.CAB
    O16 - DPF: {7FE4F4D9-141D-11D6-9FC3-00010262094C} (w489.ctlatPDI) - https://www.suzukidcs.com/cab/w489.CAB
    O16 - DPF: {87FA653D-4C13-11D3-8E1F-005004718DC0} (ScatUpdater.Updater) - https://www.suzukidcs.com/cab/ScatUpdater.CAB
    O16 - DPF: {8EBAC640-ECA5-404C-AFD9-18D61BE4AF82} (ctlepc.scatepc) - https://www.suzukidcs.com/cab/ctlepc.CAB
    O16 - DPF: {915DB736-2591-11D3-8E1F-005004718DC0} (Scatdp3.clsSuzuki) - https://www.suzukidcs.com/cab/scatdp3.cab
    O16 - DPF: {BDC217C5-ED16-11CD-956C-0000C04E4C0A} (Microsoft Tabbed Dialog Control 6.0 (SP5)) - https://www.suzukidcs.com/cab/tabctl32.CAB
    O16 - DPF: {CBCF1FEA-4905-11D4-8E21-005004718DC0} (w281ctlE.ctlW281E) - https://www.suzukidcs.com/cab/w281ctlE.CAB
    O16 - DPF: {D4C4A875-FD4E-11D4-AC39-00010262094C} (Scatdp1a.clsSuzuki) - https://www.suzukidcs.com/cab/Scatdp1a.cab
    O16 - DPF: {EA712BDB-7FE5-11D3-8E1F-005004718DC0} (Project1.login) - https://www.suzukidcs.com/cab/login.CAB
    O16 - DPF: {F25620FB-9C81-11D1-BF85-0060083BE8BF} (Project1.ctlStatusBox) - https://www.suzukidcs.com/cab/priStatusBox.cab
    O16 - DPF: {F789E003-CC28-11CF-AEF7-444553540000} (VPEngine Control) - https://www.suzukidcs.com/cab/vpectrl.cab
    O16 - DPF: {FDC1DAA5-BC3E-11D2-B3F6-0060083BE8BF} (Scatchk1.ScatChk) - https://www.suzukidcs.com/cab/Scatchk1.CAB
    O17 - HKLMSystemCCSServicesTcpip..{411F045B-B5C7-4452-AE93-99A609E2A6A5}: NameServer = 216.67.192.3,216.67.192.2
    O17 - HKLMSystemCS1ServicesTcpip..{411F045B-B5C7-4452-AE93-99A609E2A6A5}: NameServer = 216.67.192.3,216.67.192.2
    O20 - Winlogon Notify: igfxcui - C:WINDOWSSYSTEM32igfxsrvc.dll
    O20 - Winlogon Notify: NavLogon - C:WINDOWSsystem32NavLogon.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:Program FilesSymantec AntiVirusDefWatch.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:Program FilesSymantec AntiVirusSavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:Program FilesSymantec AntiVirusRtvscan.exe


    Im at a total loss. I can't reload windows either because I'd have to own up to messing around at work in order to get my software back.

    Thank you in advance for any light you can shed on my problem.
  2. #2
    Hey BG, long time no hear. Sorry your having issues, but that will teach you to be reading pr0n at work 😉

    Found this on the Spybot forums. Hope it helps.

    Spybot forums wrote:Hi

    Start Hijackthis and place a check next to these items If there.
    F2 - REG:system.ini: Shell=explorer.exe \"C:Program FilesCommon FilesMicrosoft SharedWeb Foldersibm00005.exe\"
    O4 - HKLM..Run: [mshtb.exe] C:WINDOWSSystem32mshtb.exe.exe
    O4 - HKLM..Run: [4f88f82b.exe] C:WINDOWSSystem324f88f82b.exe
    O4 - HKLM..Run: [sndraw32] C:WINDOWSSystem32sndraw32.exe
    O4 - HKLM..RunServices: [mshtb.exe] C:WINDOWSSystem32mshtb.exe.exe
    O4 - HKLM..RunServices: [sndraw32] C:WINDOWSSystem32sndraw32.exe
    O4 - HKCU..Run: [mshtb.exe] C:WINDOWSSystem32mshtb.exe.exe
    O4 - HKCU..Run: [4f88f82b.exe] C:Documents and SettingsDO NOT ENTER!!!Local SettingsApplication Data4f88f82b.exe
    O4 - HKCU..Run: [sndraw32] C:WINDOWSSystem32sndraw32.exe
    O4 - HKCU..Run: [shell] \"C:Program FilesCommon FilesMicrosoft SharedWeb Foldersibm00005.exe\"
    ====================================
    Hit fix checked and close Hijackthis.
    Restart the PC
  3. #3
    That thread on spybot is what prompted me to get HijackThis, as you can see I don't have any of those thingys; but thank you very much for looking into it!

    and its not p0rn....I prefer to refer to them as my 'special cartoons'

    I have been busy in my away time, got my CO charater to lvl 112 and have 2 noobs named lackey to do my bidding 🙂 oh yeah - and I went and got married. Hopefully I won't be away for so long this time - I know I am more of a troller than a poster here - but I actually miss yous guys.
  4. #5
    Congrats burnout_goddess..... :thumbup2:
  5. #6
    This is why you should always run multiple protections. I run win patrol that won't let stuff take over your start ups and registry.
    I also like to run Ad Watch that comes with the pro version of AdAware. It is nice for blocking anything weird. Just disable it before software installs or it will drive you nuts 😉 It always scans attempts to do anything to your registry.

    Now one thing you could try to repair your computer is a system restore. If it is tuned on, which it always should be, you could restore back to the day before you had a problem, that would fix it.

    I have never had a major hijack but then again I never, EVER, go to "bad" web sites.

    BTW nice to meet you.
  6. #7
    BG wrote:I went and got married


    Congrats!!!1 :nanaman: :nanaman: :nanaman:
  7. #8
    Sarge wrote:
    BG wrote:I went and got married


    Congrats!!!1 :nanaman: :nanaman: :nanaman:


    :rotfl2:
  8. #9
    Thanks for the link everclear, I shall check it out when Im at that pc again.

    Paladin thanks for the info - our stores 'computer guy' is an ass hat. He keeps deleting AdAware, spybot and trilian on me. I finally just burried trillian in a My docs folder named 'required work files'. So I think trying to do anything to actually protect the pc will just esult in me getting more pissed at the retard they have taking care of the pc's. I almost wish we had websence now so I wouldn't be as tempted to screw off at work.

    I have never had a major hijack but then again I never, EVER, go to \"bad\" web sites.  


    Riiiiiiiiiight 😉

    Thanks for the greetings and congrats all.....I should be - uh - getting back to work now.