Hijacked Browser!! Help!

Memory's Flame

Smile <img src="http://www3.christianforums.com/im
Dec 6, 2002
620
7
41
Somewhere North of Here...
✟837.00
Faith
Lutheran
I think my browser has been "hijacked"!!

Everytime I pull up the EXPLORER page it sends me to a site that won't go away!! It's a res:// address!!

I have ad-aware, Norton Antivirus and Norton Firewall, and still can't seem to get rid of it!!

Any thoughts as to what I can do?? I'm worried this may be causing my computer more harm!
 

rwl

Insert witty comment here
Nov 21, 2003
789
31
47
W. Hartford, CT
Visit site
✟1,123.00
Faith
Christian
run ad-aware and spybot, and your anti-virus software Remove all the bad stuff. Then see what your homepage is set to. tools>internet options> home page.

Change the homepage there. If that doesnt work then down load hijackthis ( http://www.spychecker.com/program/hijackthis.html) . Run that and post what your output is.
 
Upvote 0

Memory's Flame

Smile <img src="http://www3.christianforums.com/im
Dec 6, 2002
620
7
41
Somewhere North of Here...
✟837.00
Faith
Lutheran
Here is my logfile; although i'm not sure what to delete!

ogfile of HijackThis v1.97.7
Scan saved at 7:33:57 PM, on 7/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\javauu.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\EarthLink TotalAccess\Accelerator\PropelAC.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\d3dd.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\EarthLink TotalAccess\FastLane\IPClient.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Ryan and Jacque\My Documents\Downloads\HijackThis.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\pranz.dll/sp.html#37794
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://pranz.dll/index.html#37794
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://pranz.dll/index.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\pranz.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://pranz.dll/index.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\pranz.dll/sp.html#37794
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
O2 - BHO: (no name) - {5C8F854E-7CEA-C523-244D-78543DBCC516} - C:\WINDOWS\system32\netem32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Propel Accelerator] C:\Program Files\EarthLink TotalAccess\Accelerator\PropelAC.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [d3dd.exe] C:\WINDOWS\d3dd.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - HKLM\..\RunOnce: [javauu.exe] C:\WINDOWS\system32\javauu.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZS
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-image.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O16 - DPF: {10000000-1000-0000-1000-000000000000} -
file://C:\Program Files\Internet Explorer\zgohcpny.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{045D7AB7-55D0-4DE8-9255-6FF843536A46}: NameServer = 207.69.188.187 207.69.188.186
O17 - HKLM\System\CS1\Services\Tcpip\..\{045D7AB7-55D0-4DE8-9255-6FF843536A46}: NameServer = 207.69.188.187 207.69.188.186


 
Upvote 0

rwl

Insert witty comment here
Nov 21, 2003
789
31
47
W. Hartford, CT
Visit site
✟1,123.00
Faith
Christian
Try removing the following entries...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\pranz.dll/sp.html#37794
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://pranz.dll/index.html#37794
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://pranz.dll/index.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\pranz.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://pranz.dll/index.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\pranz.dll/sp.html#37794

O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE

***Make sure you keep the backup of those files***

Try removing those then start IE again. What happenes.
 
Upvote 0

SAPguy

Mad cow
Jun 24, 2003
5,424
44
46
Bay Area, Cali
✟5,805.00
Faith
Christian
You need to delete MWSOEMON.EXE

You will most likely need to go into running processes and halt that first, but once you stop it, you should be able to delete it. That should take care of your problem.

It is the program which tells your computer to do all that other stuff including res://C:\WINDOWS\system32\pranz.dll/sp.html#37794 and other such lines.

Do a search on google for MWSOEMON.EXE if you need more detailed instructions.

Also make sure that you always download the latest update file for adaware.
 
Upvote 0

SirKenin

Contributor
Jun 26, 2003
6,518
526
from the deepest inner mind to the outer limits
✟9,370.00
Faith
Baptist
Marital Status
Married
Actually, I believe that C:\windows\system32\javauu.exe and C:\windows\d3dd.exe are the culprits. It sounds like the malicious files that are changing your registry settings every time you reboot. You can change them as much as you want, but until you get rid of those files, they'll keep coming back.

Here's how:

Go to the task manager by pressing CTRL > ALT > Delete and end the tasks.. Go to the folders and delete the files..

Then go to the registry by clicking on Start > Run and typing in regedit (click ok) and look for this key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and Run Once

Expand those keys and look in the right pane. You should see the registry entries there.

You might want to export the keys first, just until you make sure that I am right. After that you can delete the reg keys from your harddrive safely.

Reboot your computer, then edit those keys to set your homepage back to normal.. Or do it in your browser.

Get rid of that Mywebsearch nonsense while you're at it.
 
Upvote 0
This site stays free and accessible to all because of donations from people like you.
Consider making a one-time or monthly donation. We appreciate your support!
- Dan Doughty and Team Christian Forums

tekwerx

Active Member
Aug 1, 2004
140
15
✟364.00
Faith
Protestant
Marital Status
Married
SnickerDoodle said:
Thank you all!! Is there some way that I can prevent this from happening again?? (I had a firewall and antivirus when it happened)
Yeah, get a Mac (lol I love saying that...)
Anyways, if you dont want to change your OS, then I have to concur with others - switch your web browser. Firefox is the best at the moment. Its easy, its fast, and its free.

Another solution is to avoid the problems altogether and switch your OS to Linux. I recommend Xandros, or Lindows (well, Linspire now). You keep your same hardware, and can get the whole OS for free, just burn it to a CD and write over Macroshaft's ...er, I mean Microsoft's bloated OS.

The third and most easily accomplished answer is get a Mac. Simple, elegant and powerful. Yeah, they cost a little more than PCs, but thats because you pay for style, and a computer with almost every conceivable extra you would want in it.

Just my 2 cents. I imagine youll go get firefox. ^_^
 
Upvote 0
This site stays free and accessible to all because of donations from people like you.
Consider making a one-time or monthly donation. We appreciate your support!
- Dan Doughty and Team Christian Forums

Athanasian Creed

Sola Scriptura, Sola Fide, Solus Christus !!!
Aug 3, 2003
2,368
154
Toronto
Visit site
✟18,484.00
Faith
Christian
Politics
CA-Conservatives
Download a program called "CW Shredder" - run it, it will get rid of any lingering spyware~trojans on your system. Make sure to run an update on the program before starting. I had to use this program as a last resort on a coworker's computer - his unsavoury viewing habits left him open to all sorts of wild & wonderful entities ! :eek:

Also look for a program called "Browser Hijack Blaster" - it will prevent future attempts to change your home page without your consent. ;)

Do a google search to find the sites for the above mentioned programs.

Hope that helps some,


Ray :wave:
 
Upvote 0

Memory's Flame

Smile <img src="http://www3.christianforums.com/im
Dec 6, 2002
620
7
41
Somewhere North of Here...
✟837.00
Faith
Lutheran
I reformatted and it's gone... however, firefox is still not working very well, and so I'm still on IE...

I've downloaded Ad Aware and SpyBot and CWShredder and HijackThis in hopes that I can control the problem from here on out...
 
Upvote 0

rdale

Well-Known Member
Feb 5, 2004
1,381
53
65
Oregon
✟16,820.00
Faith
Christian
Marital Status
Married
You know what... I've installed Firefox on a few different computers at work and at home, and have to agree that it loads pages slower. I think that the main draw to it is that it's free and functional. Have also installed Opera on all of the previously mentioned comps, it's noticeably quicker. Think it costs $40 to register it to avoid having ads, but other than that, it's the exact same browser as the ad version. Both home and work have fast internet connections, T1 and DSL, but some of the comps at work are relatively slow CPUwise - 600 Celeron, 450 Celeron...

If you haven't tried Opera yet, give it a go, it's at : http://www.opera.com

Tabbed browsing, different skins, etc, etc... ya, I like it :)
 
Upvote 0
This site stays free and accessible to all because of donations from people like you.
Consider making a one-time or monthly donation. We appreciate your support!
- Dan Doughty and Team Christian Forums