This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My desktop is now a web page that says, "Warning, You're in danger…secure yourself right now!". At the bottom is a button that says, "removal instructions". I tried adaware and spybot and norton antivirus and nothing helps. Here is my hijack log:

Logfile of HijackThis v1.98.2
Scan saved at 11:55:29 AM, on 12/6/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O15 - Trusted Zone: *.crazywinnings.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.tl81.com
O15 - Trusted Zone: *.windupdates.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094500064514
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotion…ctor/WebSWK.cab
O16 - DPF: {ED5BE7F4-9C97-4013-8838-48C20128D73A} (dmsProMaxOnLine Control) - http://www.promaxonline.net/ProMaxOnLine.ocx

I appreciate any help!
Thanks,
Steve
Hi Slaser,

You need to update both Windows XP and Internet Explorer as they are both well behind in updates. They are both missing Service Pack 1 which is leaving you open to all kinds of problems.

I DO NOT suggest you update to Service Pack 2, at this time.

Service Pack 1 for XP
http://www.microsoft.com/windowsxp/downloa…p1/default.mspx

Service Pack 1 for Internet Explorer.
http://www.microsoft.com/windows/ie/downlo…p1/default.mspx


Also it appears you have No Antivirus Software on your system.
Please go here an do at least two on line scans:

http://housecall.trendmicro.com/housecall/start_corp.asp

http://www.pandasoftware.com/products/activescan/

http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

Next download Adaware
Download the latest version of Ad-Aware:
http://www.lavasoft.de/support/download/

After installing AAW, and before running the program.
Please be sure to update the reference file following the instructions here:
http://www.lavahelp.net/howto/updref/

Close all Windows Except Adaware

Reconfigure Ad-Aware for Full Scan:

Launch the program, and click on the Gear at the top of the start screen.

Click the "Scanning" button.
Under Drives, Folders and Files, select "Scan within Archives".
Click "Click here to select Drives + folders" and select your installed hard drives.

Under Memory & Registry, select all options.
Click the "Advanced" button.
Under "Log-file detail level", select all options.
Click the "Tweaks" button.

Under "Scanning Engine", select the following:
"Unload recognized processes during scanning."
Under "Cleaning Engine", select the following:
"Let Windows remove files in use after reboot."
Click on 'Proceed' to save these Preferences.

Run the Ad-Aware scan and allow it to remove everything it finds and then REBOOT to allow it to finish.

I see you have Spybot Search and destory
Open Spybot
In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.

Close ALL windows except Spybot S&D

Click the button to ‘Search for Updates’ and download and install the Updates.
Next click the button ‘Check for Problems’

When Spybot is complete, it will be showing RED entries BLACK entries and GREEN entries in the window

Make certain there is a check mark beside all of the RED entries ONLY.

Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.

REBOOT to complete the scan.

To remove the WARNING You're in Danger message showing up on your Desktop, Do This:
Go To Start - Control Panel - Display
Select Desktop
Then Select Customize Desktop
Select The Web Tab
Uncheck what is currently there and delete it.
Click OK
Then Apply, OK

You still have issues that need to be fixed. Post a new HJT log file into this thread.
Please make sure you run HJT while your computer is in regular mode, NOT in safe mode. Also make sure all windows and browsers Except HJT are closed.

Thanks,
Sky
Due to inactivity this topic will be closed.

To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?



If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI