Jump to content


Photo

Hijacked Homepage/Searches


  • Please log in to reply
1 reply to this topic

#1 Friar

Friar

    Member

  • New Member
  • Pip
  • 1 posts

Posted 23 July 2004 - 11:04 PM

My fiances pc has her homepage/searches being hijacked...no matter how many times i fix them in the HT program they keep coming back everytime we close IE. Anyways here is my HT log after a fresh restart...
and I have read/tried the FAQ with some, but no major success.

------------------------------------------------------------------------------------------------
Logfile of HijackThis v1.98.0
Scan saved at 8:51:26 PM, on 7/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\ntal.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\sdkng32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\PROGRA~1\CheckIt\86\CHECKI~1.EXE
D:\Hijack This Software\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ibwjz.dll/sp.html#12802
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ibwjz.dll/index.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ibwjz.dll/index.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ibwjz.dll/sp.html#12802
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ibwjz.dll/sp.html#12802
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ibwjz.dll/index.html#12802
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {EDA47566-FF22-C6CB-022E-9E5BA4649C49} - C:\WINDOWS\iexc32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [sdkng32.exe] C:\WINDOWS\sdkng32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe
O4 - HKLM\..\RunOnce: [javazs.exe] C:\WINDOWS\system32\javazs.exe
O4 - HKLM\..\RunOnce: [ntal.exe] C:\WINDOWS\ntal.exe
O4 - HKLM\..\RunOnce: [netpb.exe] C:\WINDOWS\system32\netpb.exe
O4 - HKLM\..\RunOnce: [winwh.exe] C:\WINDOWS\winwh.exe
O4 - HKLM\..\RunOnce: [msdd32.exe] C:\WINDOWS\system32\msdd32.exe
O4 - HKLM\..\RunOnce: [atlpl32.exe] C:\WINDOWS\system32\atlpl32.exe
O4 - HKLM\..\RunOnce: [addlt.exe] C:\WINDOWS\addlt.exe
O4 - HKLM\..\RunOnce: [d3sm.exe] C:\WINDOWS\d3sm.exe
O4 - HKLM\..\RunOnce: [iels32.exe] C:\WINDOWS\iels32.exe
O4 - HKLM\..\RunOnce: [mswa32.exe] C:\WINDOWS\mswa32.exe
O4 - HKLM\..\RunOnce: [sysew.exe] C:\WINDOWS\system32\sysew.exe
O4 - HKLM\..\RunOnce: [javanb.exe] C:\WINDOWS\system32\javanb.exe
O4 - HKLM\..\RunOnce: [msbz32.exe] C:\WINDOWS\system32\msbz32.exe
O4 - HKLM\..\RunOnce: [neton32.exe] C:\WINDOWS\system32\neton32.exe
O4 - HKLM\..\RunOnce: [apiwi.exe] C:\WINDOWS\system32\apiwi.exe
O4 - HKLM\..\RunOnce: [sdkbk.exe] C:\WINDOWS\sdkbk.exe
O4 - HKLM\..\RunOnce: [adduv32.exe] C:\WINDOWS\adduv32.exe
O4 - HKLM\..\RunOnce: [ipva32.exe] C:\WINDOWS\ipva32.exe
O4 - HKLM\..\RunOnce: [javafn32.exe] C:\WINDOWS\javafn32.exe
O4 - HKLM\..\RunOnce: [atlwm.exe] C:\WINDOWS\atlwm.exe
O4 - HKLM\..\RunOnce: [crvp32.exe] C:\WINDOWS\crvp32.exe
O4 - HKLM\..\RunOnce: [addyr.exe] C:\WINDOWS\system32\addyr.exe
O4 - HKLM\..\RunOnce: [sdksa32.exe] C:\WINDOWS\system32\sdksa32.exe
O4 - HKLM\..\RunOnce: [croa32.exe] C:\WINDOWS\system32\croa32.exe
O4 - HKLM\..\RunOnce: [d3ju32.exe] C:\WINDOWS\d3ju32.exe
O4 - HKLM\..\RunOnce: [appqu.exe] C:\WINDOWS\appqu.exe
O4 - HKLM\..\RunOnce: [addba32.exe] C:\WINDOWS\addba32.exe
O4 - HKLM\..\RunOnce: [msmd.exe] C:\WINDOWS\msmd.exe
O4 - HKLM\..\RunOnce: [netkp.exe] C:\WINDOWS\system32\netkp.exe
O4 - HKLM\..\RunOnce: [atlmh32.exe] C:\WINDOWS\system32\atlmh32.exe
O4 - HKLM\..\RunOnce: [netco32.exe] C:\WINDOWS\system32\netco32.exe
O4 - HKLM\..\RunOnce: [ipnh.exe] C:\WINDOWS\ipnh.exe
O4 - HKLM\..\RunOnce: [ierm.exe] C:\WINDOWS\ierm.exe
O4 - HKLM\..\RunOnce: [sdkwo32.exe] C:\WINDOWS\sdkwo32.exe
O4 - HKLM\..\RunOnce: [sdkkd32.exe] C:\WINDOWS\system32\sdkkd32.exe
O4 - HKLM\..\RunOnce: [sdklx32.exe] C:\WINDOWS\system32\sdklx32.exe
O4 - HKLM\..\RunOnce: [winhf32.exe] C:\WINDOWS\system32\winhf32.exe
O4 - HKLM\..\RunOnce: [iphy.exe] C:\WINDOWS\iphy.exe
O4 - HKLM\..\RunOnce: [javapc32.exe] C:\WINDOWS\system32\javapc32.exe
O4 - HKLM\..\RunOnce: [mfcue.exe] C:\WINDOWS\system32\mfcue.exe
O4 - HKLM\..\RunOnce: [ipci32.exe] C:\WINDOWS\ipci32.exe
O4 - HKLM\..\RunOnce: [ipzf.exe] C:\WINDOWS\ipzf.exe
O4 - HKLM\..\RunOnce: [crro32.exe] C:\WINDOWS\crro32.exe
O4 - HKLM\..\RunOnce: [addsr32.exe] C:\WINDOWS\addsr32.exe
O4 - HKLM\..\RunOnce: [sysna32.exe] C:\WINDOWS\sysna32.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ClockSync] "C:\Program Files\ClockSync\Sync.exe" /q
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: CheckIt 86.lnk = C:\Program Files\CheckIt\86\CheckIt86.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add To CheckIt &86 Trust List - C:\PROGRA~1\CheckIt\86\AddToTrustList.js
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CheckIt\86\CheckIt86.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v5.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
------------------------------------------------------------------------------------------------

Thx for the help guys

Friar

#2 pomp

pomp

    Forum Deity

  • Helper
  • PipPipPipPipPip
  • 1,163 posts

Posted 24 July 2004 - 01:18 AM

hello

download about buster here and unzip it to the desktop http://www.downloads...AboutBuster.zip

Can you please boot into safe mode by tapping F8 while it boots.

While in safe mode, run about buster 3 or 4 times at the most. If it just says "attempted clean of temp folder" on the second, thats fine, copy and paste the log it makes somewhere and save them for each scan....

boot back into normal mode, post the about:buster logs along with a new hijackthis log.




PLEASE DON'T PM ME OR EMAIL ME WITH HELP ON LOGS :). POST IN THE FORUM INSTEAD




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button