Jump to content


Photo

Hijacked By (smart-security.info/?affid=DNN-1)


  • Please log in to reply
3 replies to this topic

#1 990n

990n

    Member

  • Full Member
  • Pip
  • 7 posts

Posted 29 July 2004 - 04:32 PM

Here's a screenshot (scroll down a bit) it covers the wallpaper/desktop and the active desktop/customize/web only provides temporary relief.

http://www.dslreport...30270~mode=flat

Has anyone figured out a fix for this yet as any help would be greatly appreciated, regards....

(btw, i've tried cws shredder, adaware, spybot, safe mode removal using aboutbuster, regedit etc)

Logfile of HijackThis v1.98.0
Scan saved at 5:27:01 PM, on 7/29/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\WINNT\system32\control.exe
C:\Program Files\Deepnet Explorer\Deepnet.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {DD51EF9D-DEE9-44FC-905B-65ABB7F748CF} - C:\WINNT\system32\njhno.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O18 - Filter: text/html - {9EE69BF7-064B-4285-8041-C5D60639D1DA} - C:\WINNT\system32\njhno.dll
O18 - Filter: text/plain - {9EE69BF7-064B-4285-8041-C5D60639D1DA} - C:\WINNT\system32\njhno.dll

#2 990n

990n

    Member

  • Full Member
  • Pip
  • 7 posts

Posted 30 July 2004 - 11:44 AM

Bump

#3 990n

990n

    Member

  • Full Member
  • Pip
  • 7 posts

Posted 06 August 2004 - 08:20 PM

Bump

#4 990n

990n

    Member

  • Full Member
  • Pip
  • 7 posts

Posted 23 August 2004 - 09:05 PM

Bump




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button