Jump to content


Photo

help with removal of hijack program


  • Please log in to reply
1 reply to this topic

#1 barefoot67

barefoot67

    Member

  • New Member
  • Pip
  • 1 posts

Posted 10 July 2004 - 10:49 AM

I am a novice here but I do need some help. My 21 year old son has infected my 15 year olds computer with a hijack program. the start page resets to

about:blank or http://mypoisk.com/index.htm

there are bookmarks I can not delete. plus I am getting all kinds of pop ups.


in addition when I try to shut the computer down I get a window saying the program is not working. I have run a virus checker (mcaffee) and it says no virus.

I have run ad aware, spybot and spyvest. I have tried running hickjack this but I am not sure what to delete. in addition , when I have deleted some files they come right back.

I have saved the hijack this to a log file but I am not sure about how to attach it to this post.

anyhelp would be appreciated.

thanks

barefoot67

here is the log file[code=auto:0]
Logfile of HijackThis v1.98.0
Scan saved at 10:36:19 AM, on 7/10/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\2Wire\Gateway\2PortalMon.exe
C:\Program Files\Winamp\Winampa.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\WINDOWS\System32\wnlfbya.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlgn.exe
C:\Program Files\Executive Software\Diskeeper Home Edition\DKService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Cameron\Local Settings\Temp\Temporary Directory 10 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Cameron\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Cameron\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Cameron\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Cameron\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Cameron\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Cameron\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://mypoisk.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_19_0.dll
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {63C02894-B39E-4809-A3EF-FE8A069EF246} - C:\WINDOWS\System32\dfbna.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_19_0.dll
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\Gateway\2PortalMon.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [xjgndhkjwjlx] C:\WINDOWS\System32\wnlfbya.exe
O4 - HKLM\..\Run: [imurl] C:\WINDOWS\addins\imurl.exe
O4 - HKLM\..\Run: [tapireg] C:\WINDOWS\tapireg.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [IEengine] C:\Program Files\Internet Explorer\IEeng.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: winlgn.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PD - {F448B999-E842-4DB1-9F7C-F0ECFA43337F} - C:\Program Files\Pop up Blocker\pd.exe
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...372/mcfscan.cab
O18 - Filter: text/html - {138D60C1-CE7B-43F5-98CC-1BC36C0F6177} - C:\WINDOWS\System32\dfbna.dll
O18 - Filter: text/plain - {138D60C1-CE7B-43F5-98CC-1BC36C0F6177} - C:\WINDOWS\System32\dfbna.dll

Edited by barefoot67, 10 July 2004 - 11:05 AM.


#2 BriosCometfyre

BriosCometfyre

    Member

  • Full Member
  • Pip
  • 55 posts

Posted 10 July 2004 - 10:53 AM

As far as attaching it to a post goes there is nothing special you need to do, run the scan and the same button that said scan should now say save log or something along the lines of that, save it and it will be a notepad document. open it (should open automatically when you save it anyway), hit ctrl + a to select all of it, copy (ctrl c) and than past it at the bottom of your post. To edit your post there should be a little tab at the top right of your post saying edit and one next to it saying quote




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button