What the Tech logo

What the Tech? It's as easy as 1,2,3! ( Log In | Register )
Easy as 1,2,3!

 
Reply to this topicStart new topic
> Please Help!, My laptop is Hijacked.
johnblaz2000
post Dec 20 2007, 08:00 PM
Post #1


New Member
*

Group: New Member
Posts: 3
Joined: 20-December 07
Member No.: 75,342
Operating System: Windows XP Pro SP2



I thought I fixed it. I ran the ficwareout tool and I still have the same conditions. I have three icons that pop up on the desktop everytime I start the computer. The are also fixed into my IE Favorties. They are in this order; Error Cleaner, Privacy Protector, and Spyware & Malware Protection. In addition to these three, My IE web page opens this website http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2 . Can anyone please help me fix my computer??? ohmy.gif

Below is the report after running the fixwareout tool.
Username "Owner" - 12/20/2007 19:56:35 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check

Successfully flushed the DNS Resolver Cache.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WorksFUD"="C:\\Program Files\\Microsoft Works\\wkfud.exe"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"RemoteControl"="\"C:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"GWMDMpi"="C:\\WINDOWS\\GWMDMpi.exe"
"GWMDMMSG"="GWMDMMSG.exe"
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"HP Software Update"="\"C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb12.exe"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"Linksys Wireless-N Notebook Adapter"="C:\\Program Files\\Linksys\\Wireless-N Network Monitor\\WPC300N.exe"
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"=""
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"Microsoft Works Update Detection"="C:\\Program Files\\Microsoft Works\\WkDetect.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"AFProg"="C:\\Program Files\\Hotspot Shield\\AnchorFree\\ctrl\\AFController.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
Go to the top of the page
 
+Quote Post
Doug
post Dec 21 2007, 01:53 AM
Post #2


Tech Team
Group Icon

Group: Administrator
Posts: 6,240
Joined: 15-May 05
From: California
Member No.: 32,477
Operating System: Win98, Win2k Pro, XP Pro, XP Home



Hi johnblaz2000,

Please run HiJackThis and post a Log over in our Malware Removal Forum for expert assistance.
Post in Malware Forum, here.

Do not post the HJT Log here in this Forum, since they are only analyzed in the Malware Forum.

Best Regards,
Doug
Go to the top of the page
 
+Quote Post
LDTate
post Dec 24 2007, 06:27 AM
Post #3


Forum God
Group Icon

Group: Root Admin
Posts: 45,797
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




Replied to HJT log thumbup.gif
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 21st November 2009 - 10:04 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy