Welcome to your place for tech questions! ( Log In or Join today ) Get answers from experts today. (it's 100% free) Virus removal forum
![]() ![]() |
| Guest_janky@adelphia.net_* |
Nov 12 2003, 01:09 PM
Post
#1
|
|
Guests |
Spybot has been run. Here is my hijack log. Logfile of HijackThis v1.97.6 Scan saved at 1:24:42 PM, on 11/12/2003 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\STIMON.EXE C:\PROGRAM FILES\AVG6\AVGSERV9.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SYSTEM\DEVLDR16.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\PROGRAM FILES\AVG6\AVGCC32.EXE C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE C:\WINDOWS\SYSTEM\DDHELP.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE C:\WINDOWS\SYSTEM\PSTORES.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\NOTEPAD.EXE C:\WINDOWS\RUNDLL32.EXE C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\4H6ZK9YN\HIJACKTHIS[1]\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS10 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myfamily.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.insightbb.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Insightbb.com R3 - Default URLSearchHook is missing F1 - win.ini: run=hpfsched O2 - BHO: (no name) - {4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} - C:\PROGRAM FILES\E-BOOK SYSTEMS\FLIPALBUM 4.0\FPLAUNCH.DLL O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\AVG6\avgcc32.exe /STARTUP O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [SAClient] "C:\PROGRAM FILES\INSIGHT\BBCLIENT\Programs\RegCon.exe" /admincheck O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\AVG6\Avgserv9.exe O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM) O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.insightbb.com O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/Template...nloads/outc.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...CAB?37869.34651 62037 O16 - DPF: Yahoo! MahJong - http://download.games.yahoo.com/games/clients/y/ot0_x.cab O16 - DPF: Yahoo! Reversi - http://download.games.yahoo.com/games/clients/y/rt0_x.cab O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/v1503/...ych.com/audit/i ncludes/ContentAuditControl.cab O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://65.82.184.122:83/activex/AxisCamControl.ocx O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as/asinst.cab O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://www.commandondemand.com/eval/cod/cabs/cssweb.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003050...ntivirus.com/ho usecall/xscan53.cab |
|
|
|
Nov 12 2003, 03:37 PM
Post
#2
|
|
![]() Retired Staff-Malware Expert ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,521 Joined: 1-November 03 From: UK Member No.: 668 Operating System: Windows XP |
Whilst I examine your log, could you update IE - your version is hopelessly out of date and probably your biggest security risk, go here and update:
http://www.microsoft.com/windows/ie/default.asp Nothing is immediately jumping out at me - I'll look at it in a bit more detail. This post has been edited by Daemon: Nov 12 2003, 03:38 PM |
|
|
|
Nov 12 2003, 06:28 PM
Post
#3
|
|
![]() - ![]() ![]() ![]() ![]() Group: Visiting Staff Posts: 661 Joined: 10-May 03 Member No.: 4 |
Try this, see if it helps:
Download this .reg file to a temporary place, like Desktop. http://www.spywareinfo.com/downloads/tools/IEFIX.reg Double-click on it and answer Yes. It will restore all the default Search settings for IE. |
|
|
|
Nov 13 2003, 06:48 PM
Post
#4
|
|
|
New Member ![]() Group: New Member Posts: 1 Joined: 12-November 03 Member No.: 847 |
Thanks so much, I just downloaded the registry fix and it worked. Everything seems to be back to normal for now. I am also taking Daemon's advice and updating my IE.
Jan |
|
|
|
Nov 13 2003, 07:42 PM
Post
#5
|
|
![]() - ![]() ![]() ![]() ![]() Group: Visiting Staff Posts: 661 Joined: 10-May 03 Member No.: 4 |
Good work, Jan.
Glad we could help. If you need this topic reopened, please request this by sending Email to Zero or Email to cnm or Email to Coyote Choose only one of the above Include your post user name and detail why you need it reopened with a valid link to your post, any bad links or emails that are not from the original poster will be deleted without response. Others please start a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
5 | -David Worrell- | 4,854 | 10th November 2003 - 07:06 PM Last post by: cnm |
|||
![]() |
17 | NickArnold | 4,349 | 26th March 2005 - 08:47 PM Last post by: LDTate |
|||
![]() |
10 | Biker-T | 2,598 | 16th March 2005 - 08:12 PM Last post by: lethal |
|||
![]() |
2 | SonFlower2002 | 2,226 | 15th October 2006 - 02:58 PM Last post by: SonFlower2002 |
|||
![]() |
7 | tpilk | 1,460 | 27th March 2004 - 04:40 PM Last post by: Daemon |
|||
|
Time is now: 22nd May 2013 - 09:47 PM |