|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
#31
|
|||
|
|||
|
As always, a pleasure working with you!
Tom
__________________
HijackThis Ad-aware Spybot Search & Destroy SpywareBlaster SpywareGuard Housecall Online A/V Scan Please read the stickys at the top of the forum before posting! |
|
#32
|
|||
|
|||
|
Tom,I just looked at my daughter's pc.I spoke too soon!It's loaded again with Ibis toolbar etc. Here's her Hijackthis log. It won't even let me finish Adaware! Help!Want a new thread?
teacher4u/Jerry Logfile of HijackThis v1.98.2 Scan saved at 8:01:59 PM, on 10/1/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\windows\taskmgr.com C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe C:\Progra~1\WinMX\WinMX.exe C:\Program Files\AIM\aim.exe C:\Program Files\Java\j2re1.4.2\bin\javaw.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\System32\CTsvcCDA.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Common Files\WinTools\WToolsS.exe C:\WINDOWS\System32\MsPMSPSv.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\WINDOWS\System32\wuauclt.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\PROGRA~1\INTERN~3\inetmgr.exe C:\Program Files\Winad Client\Winad.exe C:\PROGRA~1\INTERN~3\inetsvc.exe C:\Program Files\Winad Client\WinClt.exe C:\Program Files\Common Files\WinTools\WSup.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\explorer.exe C:\WINDOWS\System32\jscript.exe C:\Documents and Settings\Lisa Giberti\Local Settings\Temp\Temporary Directory 3 for hijackthis[1].zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.dell.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is missing O2 - BHO: Browser - {046D6EA4-15E3-4b27-8010-45BD78A9219E} - C:\PROGRA~1\INTERN~3\inetkw.dll O2 - BHO: PopThis BHO - {0549E6CB-9985-42F6-8FD6-4EC017E6AAE1} - C:\Program Files\Surfapps.com\PopThis! Free Version\PopThis.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - (no file) O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - (no file) O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Lisa Giberti\Local Settings\Temp\Act.dll O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe O4 - HKLM\..\Run: [LimeShop] javaw -cp "C:\Program Files\LimeShop\System\Code" Main lp: "C:\Program Files\LimeShop" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Nyjw1Wb1.exe O4 - HKLM\..\Run: [Dsi] C:\WINDOWS\System32\dp-him.exe O4 - HKLM\..\Run: [p4mU37j] tfttclog.exe O4 - HKLM\..\Run: [wmplayer] C:\Program Files\Windows Media Player\wmplayer.exe -invisible O4 - HKLM\..\Run: [taskmanager] c:\windows\taskmgr.com O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe" O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe O4 - HKLM\..\Run: [6QZFR] C:\documents and settings\danielle giberti\local settings\temp\6QZFR.exe O4 - HKLM\..\Run: [BymJjQU] C:\documents and settings\lisa giberti\local settings\temp\BymJjQU.exe O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~3\inetmgr.exe O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\RunServices: [Bazooka Spyware Scanner] C:\windows\Bazooka Spyware Scanner.exe O4 - HKLM\..\RunServices: [ArcSoft] C:\windows\ArcSoft.exe O4 - HKLM\..\RunServices: [AOD] C:\windows\AOD.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Bazooka Spyware Scanner] C:\windows\Bazooka Spyware Scanner.exe O4 - HKCU\..\Run: [WinMX] C:\Progra~1\WinMX\WinMX.exe -m O4 - HKCU\..\Run: [ArcSoft] C:\windows\ArcSoft.exe O4 - HKCU\..\Run: [tapi] C:\WINDOWS\System32\tapi.exe O4 - HKCU\..\Run: [jscript] C:\WINDOWS\System32\jscript.exe O4 - HKCU\..\Run: [AOD] C:\windows\AOD.exe O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.EXE 1 O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: LimeWire 3.6.15.lnk = C:\Program Files\LimeWire\3.6.15\LimeWire.exe O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra button: (no name) - {91663649-416A-42A5-8E54-B63C1ECA0548} - C:\Program Files\Surfapps.com\PopThis! Free Version\PopThis.dll O9 - Extra 'Tools' menuitem: PopThis! Options... - {91663649-416A-42A5-8E54-B63C1ECA0548} - C:\Program Files\Surfapps.com\PopThis! Free Version\PopThis.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=d5ce257857a083868c1f4672b0407c8b9379fe5496c0e7d74dd5b79e931ad6d6d9b0f3669e53e51b8fba848fa8088c3fc6 4cb0edfedca287d6c4c1b056f368:c05c8ac2b23f939ff11a0351cafa03db O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v5.cab O20 - AppInit_DLLs: C:\WINDOWS\System32\DINPUT516w.dll Last edited by teacher4u : October 1st, 2004 at 10:39 PM. Reason: typo |
|
#33
|
|||
|
|||
|
Yes, a new thread would be best.
Tom |
|
#34
|
|||
|
|||
|
I'll start a new thread.Can yoou recommend a good freeware firewall download? Thanks ! teacher4u
|
|
#35
|
|||
|
|||
|
ZoneAlarm free edition:
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp Tom |
|
#36
|
|||
|
|||
|
Hey Tom,I just installed the freeware(Zonealarm) and it went right to work for me! Thank You.You can see the posrt about Lisa's pc in a new thread under Windows in the forums.Teacher4u/jerry
|
|
#37
|
|||
|
|||
|
Yes, ZoneAlarm is a good firewall. Always download the new updates when available.
Will check your other log today. Tom |
|
#38
|
|||
|
|||
|
Tom,Bad news ! I just started my own pc and start page has been hijacked again! This time by something called New Word! Here's my newest hijacck this log.Can we nip this in the bud?
Logfile of HijackThis v1.98.2 Scan saved at 10:16:19 PM, on 10/7/2004 Platform: Windows 2000 SP5 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\winnt\System32\smss.exe C:\winnt\system32\winlogon.exe C:\winnt\system32\services.exe C:\winnt\system32\lsass.exe C:\winnt\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\winnt\system32\spoolsv.exe C:\WINNT\System32\msdtc.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINNT\system32\cisvc.exe C:\WINNT\System32\svchost.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\winnt\System32\pctspk.exe C:\winnt\system32\regsvc.exe C:\winnt\system32\MSTask.exe C:\winnt\system32\tcpsvcs.exe C:\winnt\system32\slserv.exe C:\winnt\System32\snmp.exe C:\winnt\system32\stisvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINNT\system32\ZONELABS\vsmon.exe C:\winnt\System32\WBEM\WinMgmt.exe C:\winnt\system32\svchost.exe C:\WINNT\system32\inetsrv\inetinfo.exe C:\WINNT\system32\mqsvc.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINNT\system32\P2P Networking\P2P Networking.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\WINNT\system32\cidaemon.exe C:\WINNT\system32\cidaemon.exe C:\winnt\explorer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Outlook Express\msimn.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\unzipped\hijackthis[1]\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://neword.com?s R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://neword.com?s R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://neword.com?s R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://neword.com?s R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neword.com?m R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://neword.com?s R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://neword.com?s R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://neword.com?m R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://neword.com?s R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://neword.com?s R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://neword.com?s R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://neword.com?s R3 - Default URLSearchHook is missing N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\user1\Application Data\Mozilla\Profiles\default\pnupqyfd.slt\prefs.js) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\system32\P2P Networking\P2P Networking.exe /AUTOSTART O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Adult - http://listdating.com/se/se10.htm O8 - Extra context menu item: Business - http://listdating.com/se/se5.htm O8 - Extra context menu item: Car Insurance - http://listdating.com/se/se3.htm O8 - Extra context menu item: Escorts - http://listdating.com/se/se9.htm O8 - Extra context menu item: Finance - http://listdating.com/se/se6.htm O8 - Extra context menu item: Games - http://listdating.com/se/se12.htm O8 - Extra context menu item: Health Insurance - http://listdating.com/se/se4.htm O8 - Extra context menu item: Loans - http://listdating.com/se/se7.htm O8 - Extra context menu item: Online Casino - http://listdating.com/se/se2.htm O8 - Extra context menu item: Porn - http://listdating.com/se/se11.htm O8 - Extra context menu item: Sport Betting - http://listdating.com/se/se1.htm O8 - Extra context menu item: Viagra - http://listdating.com/se/se8.htm O8 - Extra context menu item: >> DATING >> - http://listdating.com/dt.htm O8 - Extra context menu item: >> SEARCH >> - http://listdating.com/se.htm O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll O9 - Extra button: (no name) - {91663649-416A-42A5-8E54-B63C1ECA0548} - C:\Program Files\mathies.com\PopThis!\PopThis.dll O9 - Extra 'Tools' menuitem: PopThis! Options... - {91663649-416A-42A5-8E54-B63C1ECA0548} - C:\Program Files\mathies.com\PopThis!\PopThis.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{3D6686F2-1D4C-405E-8D00-4C23C7F08FB4}: Domain = earthlink.net O17 - HKLM\System\CS1\Services\Tcpip\..\{3D6686F2-1D4C-405E-8D00-4C23C7F08FB4}: Domain = earthlink.net O17 - HKLM\System\CS2\Services\Tcpip\..\{3D6686F2-1D4C-405E-8D00-4C23C7F08FB4}: Domain = earthlink.net |
|
#39
|
|||
|
|||
|
Ok you know the rules, one log per thread.... but here goes.
This could be a tough one. I don't see spywareblaster running..... should be! You might want to print these instructions for reference, as you will be off the internet while using HijackThis. P2P Networking is a totally useless Kazaa add-on, and it's been reported to be responsible for serious system slowdowns. Go to Start > Control Panel > Add/Remove programs Uninstall P2P networking. If asked whether you also want to remove Altnet components, say 'Yes'. Then... Please move or unzip HijackThis to a permanent folder such as C:\HJT It is important that it is in it's own folder as it will make important backups of what we will fix. Please open My Computer > double-click your C:\ drive > File > New > Folder > name it HJT and put HijackThis into that folder. Boot into Safe Mode. Reboot your computer, start tapping F8 when it first starts booting, select Safe Mode. Run HijackThis, click scan, place a checkmark next to the following items. Close all browsers and any other windows or the fix may not work! Click "fix checked". It is OK if some of these items are no longer listed. R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://neword.com?s R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://neword.com?s R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://neword.com?s R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://neword.com?s R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neword.com?m R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://neword.com?s R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://neword.com?s R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://neword.com?m R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://neword.com?s R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://neword.com?s R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://neword.com?s R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://neword.com?s R3 - Default URLSearchHook is missing O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\system32\P2P Networking\P2P Networking.exe /AUTOSTART O8 - Extra context menu item: Adult - http://listdating.com/se/se10.htm O8 - Extra context menu item: Business - http://listdating.com/se/se5.htm O8 - Extra context menu item: Car Insurance - http://listdating.com/se/se3.htm O8 - Extra context menu item: Escorts - http://listdating.com/se/se9.htm O8 - Extra context menu item: Finance - http://listdating.com/se/se6.htm O8 - Extra context menu item: Games - http://listdating.com/se/se12.htm O8 - Extra context menu item: Health Insurance - http://listdating.com/se/se4.htm O8 - Extra context menu item: Loans - http://listdating.com/se/se7.htm O8 - Extra context menu item: Online Casino - http://listdating.com/se/se2.htm O8 - Extra context menu item: Porn - http://listdating.com/se/se11.htm O8 - Extra context menu item: Sport Betting - http://listdating.com/se/se1.htm O8 - Extra context menu item: Viagra - http://listdating.com/se/se8.htm O8 - Extra context menu item: >> DATING >> - http://listdating.com/dt.htm O8 - Extra context menu item: >> SEARCH >> - http://listdating.com/se.htm Unless you have the Spybot Search & Destroy option 'Lock homepage from changes' active, or your system administrator put this into place, have HijackThis fix this: O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present Then.... Open My Computer, browse to C:\documents and settings\User Name(repeat for all users)\local settings\temp folder and delete all files and folders in it. Open My Computer, browse to C:\Windows\Temp folder and delete all files and folders in it. Open Internet Explorer click Tools > Internet Options > General. Check "delete all offline content", click "Delete Files" then Click OK. Empty your Recycle Bin. Reboot normally and post a fresh HijackThis log. Tom |
|
#40
|
|||
|
|||
|
Tom, I posted an almost immediate follow up last nite ,but it's not here! My Zone alarm kicked them out! I love Zonealarm! We don't have to do anything! False alarm, thanks to Zone alarm. I'm thinking about buying it now! Thanks Tom.
|
|
#41
|
|||
|
|||
|
OK but this was a CWS infection. you sure you don't want to post a follow-up log?
Tom |
|
#42
|
|||
|
|||
|
Ok Tom,I understand . You're 100% correct! I'm asleep at the wheel. I'll do it and post a log back here. Thank you1 teacher4u/Jerry
|
|
|