jumbuck
Topic Starter
Browser Hijack Blaster keeps popping up every so often to tell my me my homepage has been changed and sometimes no matter how many times I click Yes to put it back to what it's supposed to be, it pops up again immediately saying it's been changed again. Sometimes this can go on forever until in the end I just close the box in disgust.
After this, when I check IE Properties it just has a blank box with some sort of little symbol at the beginning and even if I change it manually back to Google (which is my usual homepage) the next time I check it, it's gone back to the blank thing again.
I've run Adaware a lot of times lately and each time it's picked up a few nasties but nothing major. (Just after the trouble first started a couple of weeks ago it found both Wild Tangent and Alexa but said it had got rid of both). After I've run it and had it get rid of whatever it has found, the next time I boot up my homepage has been restored to Google and I become hopeful the problem has been fixed. Then after a few hours I get the warning again from Browser Hijack Blaster telling me it's been changed and the whole cycle begins again.
Here is my Hijack This log file. Could someone please have a look at it and tell me what I need to remove. I'd be very grateful.
Logfile of HijackThis v1.98.2
Scan saved at 9:22:09 PM, on 31/07/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Vet\VetTray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Vet\isafe.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Vet\VetMsg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Browser Hijack Blaster\bhblaster.exe
C:\PROGRA~1\PAINTS~1\Psp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Maxis\The Sims\SimCategorizer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\old d drive\DOWNLOADS\HIJACK THIS\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
After this, when I check IE Properties it just has a blank box with some sort of little symbol at the beginning and even if I change it manually back to Google (which is my usual homepage) the next time I check it, it's gone back to the blank thing again.
I've run Adaware a lot of times lately and each time it's picked up a few nasties but nothing major. (Just after the trouble first started a couple of weeks ago it found both Wild Tangent and Alexa but said it had got rid of both). After I've run it and had it get rid of whatever it has found, the next time I boot up my homepage has been restored to Google and I become hopeful the problem has been fixed. Then after a few hours I get the warning again from Browser Hijack Blaster telling me it's been changed and the whole cycle begins again.
Here is my Hijack This log file. Could someone please have a look at it and tell me what I need to remove. I'd be very grateful.
Logfile of HijackThis v1.98.2
Scan saved at 9:22:09 PM, on 31/07/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Vet\VetTray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Vet\isafe.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Vet\VetMsg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Browser Hijack Blaster\bhblaster.exe
C:\PROGRA~1\PAINTS~1\Psp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Maxis\The Sims\SimCategorizer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\old d drive\DOWNLOADS\HIJACK THIS\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =