|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
Generate data entry and reporting .NET Web apps in minutes, straight from your database. Read our FREE whitepaper “Build Web 2.0 Applications Without Hand-Coding” Download now! |
|
#1
|
|||
|
|||
|
My homepage changed to http://a-search.biz.
Hi,
My homepage has changed to a-search.biz.I tried changing it but can't.Also try using spyware removers but useless.Scan with hiijackthis which shows the following: R1 - HKCU\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = c:\searchpage.html R1 - HKLM\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = c:\searchpage.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file) O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file) O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\flashget\FlashGet\Jccatch.dll O2 - BHO: (no name) - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\flashget\FlashGet\fgiebar.dll O3 - Toolbar: (no name) - {777D0B4C-75C9-4874-ABFF-80B4BE8DC532} - (no file) O4 - HKLM\..\Run: [QuickTime Task] "C:\program files\quicktime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE O4 - HKLM\..\Run: [DSLAGENTEXE] DSLAGENT.EXE O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP O4 - HKLM\..\Run: [MSNSysRestore] C:\WINDOWS\System32\pc32.exe bg O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background O4 - HKCU\..\Run: [StartPage] C:\rundll32.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Download with &DAP - .\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DOWNLO~1\DAP\dapextie2.htm O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\flashget\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\flashget\FlashGet\jc_link.htm O9 - Extra button: °Ù¶ÈËÑË÷°é - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file) O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\flashget\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\flashget\FlashGet\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O11 - Options group: [!IESearch] !IESearch O16 - DPF: {094642C4-4FC4-4EE9-ECCC-33B52AAB2D67} - http://209.8.161.54/1/gdnSG1022.exe O16 - DPF: {11111111-1111-1111-1111-111111111237} - http://64.237.41.215/1/deaSG386.exe O16 - DPF: {262BD617-7236-1785-BE4C-2C601EE6A737} - http://209.8.161.54/1/gdnSG1022.exe O16 - DPF: {405F4E7C-5609-66DF-8D80-653F785855CF} - http://209.8.161.54/1/gdnSG1022.exe O16 - DPF: {408FB830-E333-3200-F9D5-5887680B5610} - http://63.219.176.203/1/gdnSG778.exe O16 - DPF: {49F845F7-4972-6231-E289-39367D2549C1} - http://209.8.161.54/1/gdnSG1022.exe O16 - DPF: {563EEB9A-C876-5FD3-6F2F-121A0396D9EC} - http://209.8.161.54/1/gdnSG1022.exe O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx O16 - DPF: {6B86666E-B405-15AC-5260-298E2FCE9F1E} - http://209.8.161.54/1/gdnSG1022.exe O16 - DPF: {7276DE9A-19FE-3158-68FE-37275317F274} - http://64.237.60.5/1/rdgSG1210.exe O16 - DPF: {8135EF31-FE8C-4C6E-A18A-F59944C3A488} - http://ddddl.dudu.com/ddd/channel/spockx-channel.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://mirror.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-intl/sg/games3.cab O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab O16 - DPF: {F08555B0-9CC3-11D2-AA8E-000000000000} - http://www.pornmail.com/cglbar.cab O18 - Protocol: mp3 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file) My operating sys:winXP Please provide assistance.Thank you! |
|
#2
|
||||
|
||||
|
You posted the same thread yesterday. Please wait longer than a day before reposting.
|
|
#3
|
|||
|
|||
|
You only have a partial log there. PLease re run hijack this, click scan, then when the scan is finished, click the button that says Save Log. Then post the entire contents of the log file that pops up.
|
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > My homepage changed to http://a-search.biz. |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|