|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
Stay one step ahead of the competition. Evaluate and give feedback
on some of the hottest web development tools on the market today.
Make your opinion heard! Click
Here
|
|
#1
|
|||
|
|||
|
My IE has been hijacked. Adaware, Spybot, HijackThis all find it in safe mode and cleans it but it keeps coming back. I tried deleting the qnuvy.dll file, editing the registry, etc., to no avail (although I don't think I tried it doing this part in safe mode.)
It. Keeps. Coming. Back. PLEASE HELP ME, IT'S DRIVING ME MAD!!! Here's my hijackthis log: Logfile of HijackThis v1.97.7 Scan saved at 9:59:48 PM, on 7/20/2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton Personal Firewall\NISUM.EXE C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE C:\WINDOWS\System32\nvsvc32.exe C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Norton Personal Firewall\SymProxySvc.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe C:\Program Files\Norton Personal Firewall\IAMAPP.EXE C:\WINDOWS\System32\taskswitch.exe C:\WINDOWS\addoj.exe C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Microsoft Hardware\Mouse\point32.exe C:\Program Files\Logitech\iTouch\iTouch.exe C:\WINDOWS\d3xw.exe C:\Program Files\Norton Personal Firewall\NISSERV.EXE C:\WINDOWS\System32\wuauclt.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\mozilla.org\Mozilla\mozilla.exe C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe C:\Documents and Settings\Marty\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qnuvy.dll/sp.html#28129 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://qnuvy.dll/index.html#28129 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://qnuvy.dll/index.html#28129 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qnuvy.dll/sp.html#28129 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://qnuvy.dll/index.html#28129 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\qnuvy.dll/sp.html#28129 O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {F9AF5432-D772-27F1-F0D5-22A8325BB3F3} - C:\WINDOWS\system32\d3vn.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Personal Firewall\IAMAPP.EXE O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [d3xw.exe] C:\WINDOWS\d3xw.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe" /startup O4 - Global Startup: Adobe Gamma Loader.lnk = ? O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - URL O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - URL O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - URL O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\vdvujscu.exe O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - URL O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - URL O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - URL O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - URL O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - URL O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - URL O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - URL O17 - HKLM\System\CCS\Services\Tcpip\..\{636EA540-D2CC-47BF-8A29-37EC8FF96F8E}: NameServer = 24.52.223.219,24.52.223.218 Thanks for any help! ![]() |
|
#2
|
|||
|
|||
|
I gave up...
I'm now a Firefox user. ![]() |
|
#3
|
||||
|
||||
|
yay! nice decision
![]() |
|
#4
|
|||
|
|||
|
Even tho' I'm now a Firefox user, do I need to worry about leaving those registry entries, dll file, etc., on my pc? Or are they pretty much benign unless I'm using IE?
![]() |
|
#5
|
||||
|
||||
|
Well, I think I'd be inclined to get the hijack solved, as you don't really want them on your computer. Just wait and you someone who can help should be along to check your log.
|
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > IE Hijacked and can't clean it. |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|