Jump to content

Build Theme!
  • Infected?


Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 91677 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!

Internet Explorer

  • Please log in to reply
4 replies to this topic

#1 Guest_jason eggleston_*

Guest_jason eggleston_*
  • Guests

Posted 05 January 2004 - 12:42 PM

I've given up on trying to get these dayam spyware infections out of my internet explorer because I've used spybot, ad-aware, browser hijack blaster to try to get my homepage back to normal but it will never be fixed. My homepage is yahoo.com and in the address bar it says yahoo.com, but on the page it is some search site that doesnt give real search results, it's some spyware that took over my homepage, and when I go to google.com it does the same thing. So what I want to know is if there is some way I can delete my internet explorer, and reinstall it, and if that would take care of the problem


Register to Remove

#2 Guest_jason eggleston`_*

Guest_jason eggleston`_*
  • Guests

Posted 05 January 2004 - 12:44 PM

if you can help please email me at jebaye@aol.com. thank you

#3 dave38


    Authentic Member

  • Authentic Member
  • PipPip
  • 82 posts

Posted 05 January 2004 - 01:37 PM

Please download Hijack this
Unzip it into its own folder, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, do Ctrl-A to Select All, and copy its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet.

And, unless you really, REALLY, like spam, it is not a good idea to post your email address.
I didn't believe in reincarnation last time either!

#4 Guest_jason eggleston_*

Guest_jason eggleston_*
  • Guests

Posted 05 January 2004 - 03:04 PM

it wont let me open that page. says it is unavalible..the url bar read "http:///" i noticed the same problem with some other dowloadas that i have tried in the past couple of days.

#5 Guest_jason eggleston_*

Guest_jason eggleston_*
  • Guests

Posted 05 January 2004 - 03:13 PM

ok...i got a copy of it from winmx.....here is the log....
Logfile of HijackThis v1.97.7
Scan saved at 4:12:03 PM, on 1/5/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://in.webcounter.cc/--/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://in.webcounter.cc/---/?ydtfs (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.locators.com/homepage/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://in.webcounter.cc/-/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://in.webcounter.cc/--/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://in.webcounter.cc/---/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://in.webcounter.cc/--/?ydtfs (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://in.webcounter.cc/-/?ydtfs about:blank (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.sma...t/7search/?hklm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.white-pages.ws/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.white-pages.ws/
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/--/?ydtfs (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/--/?ydtfs (obfuscated)
O1 - Hosts: gator.com #cooklop
O1 - Hosts: tripod.com #cooklop
O1 - Hosts: www.tripod.com #cooklop
O1 - Hosts: geocities.com #cooklop
O1 - Hosts: www.geocities.com #cooklop
O1 - Hosts: adultfriendfinder.com #cooklop
O1 - Hosts: www.adultfriendfinder.com #cooklop
O1 - Hosts: cj.com #cooklop
O1 - Hosts: www.cj.com #cooklop
O1 - Hosts: paypopup.com #cooklop
O1 - Hosts: www.paypopup.com #cooklop
O1 - Hosts: thehun.net #cooklop
O1 - Hosts: www.thehun.net #cooklop
O1 - Hosts: worldsex.com #cooklop
O1 - Hosts: www.worldsex.com #cooklop
O1 - Hosts: free6.com #cooklop
O1 - Hosts: www.free6.com #cooklop
O1 - Hosts: trafficmp.com #cooklop
O1 - Hosts: www.trafficmp.com #cooklop
O1 - Hosts: 1089288654 auto.search.msn.com
O1 - Hosts: sitefinder.verisign.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Locators.com Search Bar - {E720B458-B65A-438C-9FF3-B1DF65D7DB3E} - C:\PROGRA~1\LOCATO~1\LocatorS.dll
O3 - Toolbar: Locators.com Links Bar - {E720B458-B65A-438C-9FF3-B1DF65D7DB3F} - shdocvw.dll (file missing)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
O4 - Startup: PowerReg Scheduler V3.exe
O9 - Extra button: ATI TV (HKLM)
O9 - Extra button: Locators.com Search Bar (HKLM)
O9 - Extra 'Tools' menuitem: Locators.com Search Bar (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Pool 2 - http://download.game...ts/y/potc_x.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macr...director/sw.cab
O16 - DPF: {1FDEC088-A699-46FE-BF76-D5FD6DAE6150} (UCSearch.ucUCSearch) - http://www.armbender.com/UCSearch.CAB
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg...ntrol_v1-32.cab
O19 - User stylesheet: C:\WINDOWS\Web\tips.ini
O19 - User stylesheet: C:\WINDOWS\hh.htt (HKLM)

Related Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users