Mensaje
por caito » 29 Sep 2004, 05:31
Esto encontré :
Variant 31: - CWS.Msconfig - Payload plus one
Approx date first sighted: February 5, 2004 (also a nice example of how frustrating these things can be to people)
Symptoms: IE pages being hijacked to http://www.31234.com on system startup and when changing homepage back, continuous errors about an invalid Registry script in temp2.txt, extra item in right-click menu of webpages named '??????'
Cleverness: 2/10
Manual removal difficulty: Involves a process killer, some Registry editing and restoring a Windows system file from CD
Identifying lines in HijackThis log:
Running processes:
C:\WINDOWS\SYSTEM\MSCONFIG.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.31234.com/www/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.31234.com/www/homepage.html
O4 - HKLM\..\Run: [msconfig] C:\WINDOWS\SYSTEM\msconfig.exe
O4 - HKCU\..\Run: [msconfig] C:\WINDOWS\SYSTEM\msconfig.exe
O8 - Extra context menu item: ?????? - C:\WINDOWS\system32\openme.htm
This variant uses the filename msconfig.exe which overwrites the real Windows file in Windows 98/98SE/ME. The temp2.txt file it drops is actually a Registry script, but since it's in the wrong format, Windows 9x/ME will throw up an error about an invalid Registry script. Windows 2000/XP will import it without complaining, creating the '??????' item in the IE right-click menu. The msconfig.exe file will always stay in memory, reinstalling the hijack every 5 seconds. Killing the process, deleting the file and restoring the IE homepages/search pages fixes this hijack.
The real Windows file msconfig.exe can be download here, if you can't restore it from your Windows Setup CD for some reason :
http://209.133.47.200/~merijn/winfiles.html#msconfig
Salu2
Caito