Computing.Net > Forums > Windows Me > new browser hijack?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

new browser hijack?

Reply to Message Icon

Name: John Wallace
Date: December 30, 2003 at 14:01:12 Pacific
OS: winME
CPU/Ram: 833AMD 64Ram
Comment:

My browser got hijacked recently - The browser which appeared was called "Smart-Finder", and was enabled by a series of files in my registry called "nkvd.us/s". No searches on the net revealed any info on either.

Hijack this helped me take out the nkvd files, while I cleaned up with Spybot. My (earlier) version of CWShredder showed nothing left after that, yet the next day, back it came - same procedure - next day, same problem.

I found bootconf.exe in HKEY USERS/DEFAULT/Software/Microsoft/Explorer/Explorer Bars/Files named MRU, and took it out.

For good measure I re-downloaded CWShredder and ran it - it found 3 CWS DirectX infected files.

I am now hoping I am clear of this scumware, but wondered if anyone else had come across this one.



Sponsored Link
Ads by Google

Response Number 1
Name: Dog
Date: December 30, 2003 at 15:52:44 Pacific
Reply:

John, check the Security and Virus forums of this site. There are so many different ones.

HTH
Dog


0

Response Number 2
Name: Code One
Date: January 4, 2004 at 11:29:06 Pacific
Reply:

no but i came across this one called web search or something, and what it did was changed all my search keys in reg to that search page, and totally fu...everything up, so I got the address and tracked the ip, and the dude turned out to be a russian, non diplomatic, means diplomatic immunity, which means reformat and move on...lol


0

Response Number 3
Name: eRiC15god
Date: January 5, 2004 at 17:42:03 Pacific
Reply:

Can someone send me a Anti-Virus program that swipes stupid viruses. I really need to take out that nkvd or search for GOOD! If you can send me that program then THANK YOU!!!!!! :D please i need help


0

Response Number 4
Name: Voytek
Date: January 8, 2004 at 19:48:53 Pacific
Reply:

I'm so glad I came across your post. I have the same bloody problem with the nkvd.us take-over, except that I don't have any MRU files in HKEY USERS/DEFAULT/Software/Microsoft/Explorer/Explorer Bars/. How else, than, can I get rid of this malicious trojan? Please help!


0

Response Number 5
Name: Virus Magnet
Date: January 12, 2004 at 22:01:07 Pacific
Reply:

I think I have this too. Can anyone confirm if the virus seems to be restarted after cleaning when they open AOL Instant Messenger?


0

Related Posts

See More



Response Number 6
Name: Girth Blanston
Date: January 13, 2004 at 18:28:25 Pacific
Reply:

I'm so glad I found this post.....I have the same nkvd take over problem, and can't seem to fix it....but I can assure you AOL instant messenger isn't part of the problem, because I never use it, and my problem still exists!....someone help!


0

Response Number 7
Name: garybhoy
Date: January 16, 2004 at 12:24:11 Pacific
Reply:

i had problems with the nkvd.us thing too, and ive been searching in my reg and found parts of it here that HT, CWS or AV never found. I just deleted them so hopefully in a few hours it wont come back:

hkey current user/software/microsoft/internetexplorer/explorerbars/C4ee...../filesnamedMRU

same as above: "ContaingtaxtMRU"

and not sure if this affects it or if its from an older trojan


hkey_users/software/microsoft/windows/currentversion/telephone/handoffproperties

had dialer.exe in there and deleted it.

hope this helps guys.

gary


0

Response Number 8
Name: garybhoy
Date: January 16, 2004 at 12:44:39 Pacific
Reply:

oh yeah, sorry John, I didnt see you posted that already.

and I found a myway folder too.

under hkey_user/software/myway

looks like a search redirect so i got rid of that too

and also check out
hkey_current_user/software/microsoft/internetexplorer/search and search properties

i found 2 more redirects in there and erased the default name instead of deleting it


hope this helps too guys.

g*


0

Response Number 9
Name: neovelocity
Date: January 19, 2004 at 11:54:09 Pacific
Reply:

I have the same problem and cannot get rid of nkvd.us.

I have updated spybot S&D, Hijack this, and cwshredder to the latest versions and includes.

Hijack this catches it and I have deleted EVERYTHING it catches, shredded the backups, ran spybot s&d, and ran CW shredder, as well as uninstalled myway websearch and cleaned up all of the regestries, all with no luck.It still comes back in about 6-8 hours.

I have run Norton, Mcaffee, Avast, and a few other AV programs, all updated, and all with no luck.

I have also deleted (shredded)any files that were created after I received this hijack, including mserv.exe which was coming back as a possible trojan during one of my many virus scans, and anything I didn't recognise as being a needed file.

I have also uninstalled any programs that are not necessary to the basic OS to function (ie, office 2000, print drivers, etc), and completely cleaned out the system reg.

I have a reg edit program which catches any new registery entries and lables them as new when they are added after the last date I checked them, and it did not catch any new registry entries around the time this started happening.

I am out of ideas and reformatting my HDD is not an option. They really got us on this one, them B@#tards...


0

Response Number 10
Name: neovelocity
Date: January 20, 2004 at 11:47:37 Pacific
Reply:

This info was obtained from http://www.merijn.org/cwschronicles.htm (cwshredder)

Regarding nkvd.us:

Approx date first sighted: January 11, 2004
Log reference: http://forums.spywareinfo.com/index.php?showtopic=27673&hl=nkvd\.us
Symptoms: IE hijacked to nkvd.us and smart-finder.biz, redirections to nkvd.us and smart-finder.biz when typing incomplete URLs into address bar.
Cleverness: 10/10
Manual removal difficulty: Involves some registry editing, and renaming the trojan file, restarting, and deleting it
Identifying lines in HijackThis log:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.nkvd.us/s.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.nkvd.us/s.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nkvd.us/s.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nkvd.us/1507/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nkvd.us/s.htm
O13 - DefaultPrefix: http://www.nkvd.us/1507/
O13 - WWW Prefix: http://www.nkvd.us/1507/
O13 - Home Prefix: http://www.nkvd.us/1507/
O13 - Mosaic Prefix: http://www.nkvd.us/1507/

Additional line in StartupList log:

Enumerating ShellServiceObjectDelayLoad items:

DDE Control Module: C:\WINDOWS\SYSTEM\mtwirl32.dll


This variant was surprisingly smart: it used two startup methods (ShellServiceObjectDelayLoad and SharedTaskScheduler) that have to be the absolutely rarely used ones seen ever - and it used them differently on Windows 9x/ME and Windows NT/2k/XP. On top of that, both methods ensure that the file is loaded when Explorer is loaded, making it always in memory like CWS.Msconfd. Additionally, the actual responsible files are invisible in HijackThis, and only one shows in a StartupList logfile (ShellServiceObjectDelayLoad). The responsible file is mtwirl32.dll, and to delete it manually you need to rename it (deleting is impossible since it is in use), restart the system, and then delete the file and its Registry key.


Thanks to cwshredder for the info,
hope this helps

Neo


0

Response Number 11
Name: jegaz
Date: January 20, 2004 at 21:44:57 Pacific
Reply:


To remove this browser tak over you need to do as follows…

Click on start
Open Run
Type “regedit” and click ok

Then Click on the following pluses:

HKEY_LOCAL_MACHINE
SOFTWARE
MICROSOFT
WINDOWS
CURRENT VERSION
SHELLSERVICEOBJECTDELAYLOAD

Double click on

SHELL SERVICE OBJECT DELAY LOAD
And delete the following file

(DDE CONTROL MODULE)

Once you’ve done this open

C:\Windows\System

And delete the following two files

MTWIRL32.DLL
MTWCNL32.DLL

Once you’ve done this run CWShredder

AND URE DONE =p


0

Response Number 12
Name: jegaz
Date: January 20, 2004 at 23:03:32 Pacific
Reply:

hey guyz

da above works for Windows Me...dats what im running so if ure running something else im not a hundred percent dat it will work...but giv it a go and tell me what happens

jegz


0

Response Number 13
Name: jegaz
Date: January 20, 2004 at 23:29:00 Pacific
Reply:

hey guyz

if when you try delete

MTWIRL32.DLL
MTWCNL32.DLL

i suggest you reboot ure system and try if there are any problems plz post up..thx


0

Response Number 14
Name: John Wallace
Date: January 21, 2004 at 12:36:14 Pacific
Reply:

Try going here:

http://www.smart-finder.biz/uninstall.htm

but remain sceptical - scan again to make sure


0

Response Number 15
Name: John Wallace
Date: January 21, 2004 at 12:49:18 Pacific
Reply:

"This info was obtained from http://www.merijn.org/cwschronicles.htm (cwshredder)
Regarding nkvd.us:

Approx date first sighted: January 11, 2004"

This thread was started December 30, 2003

Deleted files show my computer picked up the infection October 25, 2003

This little sucker has been around for a while now - glad to see folks have picked up on it.



0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Me Forum Home


Sponsored links

Ads by Google


Results for: new browser hijack?

Browser hijacked - www.computing.net/answers/windows-me/browser-hijacked-/43256.html

Lunching new browser from desktop www.computing.net/answers/windows-me/lunching-new-browser-from-desktop/23684.html

Browser Hijacking....... www.computing.net/answers/windows-me/browser-hijacking/25561.html