Jump to content


Photo

Google trojan I guess.


  • This topic is locked This topic is locked
3 replies to this topic

#1 OmEgAx03

OmEgAx03

    Member

  • New Member
  • Pip
  • 3 posts

Posted 02 July 2004 - 11:03 PM

Usually I am good at removing spyware/adware/trojans but this one has totally got me stumped. Whenever I search on google the page instantly changes to only one result for what i searched. All I have to do is press 'refresh' and it will go normal but it is so irritating. Here's my hijack log if it helps at all..

Logfile of HijackThis v1.98.0
Scan saved at 12:02:53 AM, on 7/3/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner.ABSINTHE\Desktop\KillBox\HijackThis.exe

F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
O2 - BHO: (no name) - {2DDF179F-F565-2D05-DC33-666A90225106} - C:\WINDOWS\System32\nageltyf.dll
O2 - BHO: (no name) - {A052B160-3C3F-B16A-D0F5-240E53230ECE} - C:\WINDOWS\System32\ocsrvizm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {E829A886-BD9D-BEEE-DE9E-C41FE03F47DE} - C:\WINDOWS\System32\kayzedhs.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [bcray] C:\DOCUME~1\OWNER~1.ABS\LOCALS~1\Temp\SFX3.tmp\svchost.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Do&wnload by ReGet Deluxe - C:\Program Files\Common Files\ReGet Shared\CC_Link.htm
O8 - Extra context menu item: Download A&ll by ReGet Deluxe - C:\Program Files\Common Files\ReGet Shared\CC_All.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

Thanks in advance.

#2 dave38

dave38

    Devout Murphyite!

  • Emeritus
  • PipPipPipPipPip
  • 8,508 posts

Posted 03 July 2004 - 06:40 AM

That log seems to be missing the lower part.

Have Hijack This fix all of the following by placing a check in the appropriate boxes and hitting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.

O2 - BHO: (no name) - {2DDF179F-F565-2D05-DC33-666A90225106} - C:\WINDOWS\System32\nageltyf.dll
O2 - BHO: (no name) - {A052B160-3C3F-B16A-D0F5-240E53230ECE} - C:\WINDOWS\System32\ocsrvizm.dll
O2 - BHO: (no name) - {E829A886-BD9D-BEEE-DE9E-C41FE03F47DE} - C:\WINDOWS\System32\kayzedhs.dll

O4 - HKLM\..\Run: [bcray] C:\DOCUME~1\OWNER~1.ABS\LOCALS~1\Temp\SFX3.tmp\svchost.exe

Reboot and delete

All files in the folder C:\DOCUME~1\OWNER~1.ABS\LOCALS~1\Temp
These may be hidden files. See HERE for how to show hidden files.

Please post a followup Hijack this log, and say if your problems persist. Please ensure tha the entire log is included.
Be wary of strong drink. It may make you shoot at tax collectors, and miss!
Please support SWI forum

#3 OmEgAx03

OmEgAx03

    Member

  • New Member
  • Pip
  • 3 posts

Posted 03 July 2004 - 09:05 AM

Thanks alot, that did it.

#4 dave38

dave38

    Devout Murphyite!

  • Emeritus
  • PipPipPipPipPip
  • 8,508 posts

Posted 03 July 2004 - 10:02 AM

Glad to help!

If you need this topic reopened, please request this by sending the moderating team an email with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.
Be wary of strong drink. It may make you shoot at tax collectors, and miss!
Please support SWI forum




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button