|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
|
|
#1
|
|||
|
|||
|
Home Page keeps changing
Everytime I log on my home page is different, there are about 3 or 4 that it keeps switching between. Could someone read this log file and tell me what I can do or delete?
Logfile of HijackThis v1.97.7 Scan saved at 9:51:35 PM, on 6/25/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\WINDOWS\System32\rundll32.exe C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe C:\Program Files\EarthLink TotalAccess\TaskPanl.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Owner\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = URL R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = URL R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = URL R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by EarthLink R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = URL R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080 O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_2_3_0.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_2_3_0.dll O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart O4 - HKLM\..\RunOnce: [SpyBotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-page.html O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-image.html O9 - Extra button: Real.com (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: Fortune Bingo by pogo - URL O16 - DPF: JT's Blocks - URL O16 - DPF: Pop Fu by pogo - URL O16 - DPF: Poppit TM by pogo - URL O16 - DPF: Tornado 21 - URL O16 - DPF: Tri-Peaks by pogo - URL O16 - DPF: World Class Solitaire by pogo - URL O16 - DPF: Yahoo! Dots - URL O16 - DPF: Yahoo! Literati - URL O16 - DPF: Yahoo! Pyramids - URL O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - URL O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - URL O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - URL O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - URL O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - URL O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - URL O16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) - URL O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - URL O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - URL O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - URL O17 - HKLM\System\CCS\Services\Tcpip\..\{072A8B54-6B08-4BFD-A5C5-114D35CB9B52}: NameServer = 207.69.188.187 207.69.188.186 O17 - HKLM\System\CS1\Services\Tcpip\..\{072A8B54-6B08-4BFD-A5C5-114D35CB9B52}: NameServer = 207.69.188.187 207.69.188.186[/SIZE] |
|
#2
|
||||
|
||||
|
Moved to Antivirus Protection.
|
|
#3
|
|||
|
|||
|
Here is how to read the hijackthis logfile .
Compare it with yours . http://homepage.ntlworld.com/dvk01uk/tutorial.htm http://www.spywareinfo.com/~merijn/htlogtutorial.html http://www.help2go.com/article153.html http://hjt.wizardsofwebsites.com/ http://www.spywareinfo.com/bhos/ http://www.spychecker.com/program/bholist.html http://www.spywareinfo.com/~merijn/htlogtutorial.html#r http://www.computercops.biz/postt6393.html http://www.google.com/search?q=spyware+list Beginners Guides: Browser Hijacking & How to Stop It http://www.pcstats.com/articleview.cfm?articleID=1579 |
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > Home Page keeps changing |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|