This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Amazing! Reformat didn't work!

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Latest Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:40:11 AM, on 6/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\Temporary Directory 6 for hijackthis.zip\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1150224122765
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1150224110421
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
One more thing which adds to the mystery (for me anyhow) - the redirects to seeq.com aren't happening everytime I log on or go to Yahoo - sometimes I get to all the links in Yahoo without incident and at other times I am redirected to seeq.com For example - last night I was seeq'd. This morning I have not been (yet)
Please look at this thread.

I think a similar situation is happening to you.

Although, you have no "O17" line in your log that is "hijacked". I believe that sometimes you are getting routed through the SEEQ server, thus it can "hijack" your search results. I don't think there is any malware present on your machine locally.

I'm going to attempt to find primary, and secondary, DNS servers for you. That's why I wanted the geographical region of the country you live in, so I could find a DNS server "local" to you.

I'll post again with instructions when I find DNS servers close to you.

M68 :)
Change your "Preferred" and "Alternate" DNS servers to:

Preferred: 4.2.2.1

Alternate: 4.2.2.6

See if that keeps SEEQ off your back.

:)
Michah, Yes - I am still with you, sorry about the delay. I changed the DNS as you suggested and so far so good. Should I do the same change on my latop (I have my desktop and laptop on a home wireless network)? I really appreciate your help - because this stuff makes me crazy. Here's the latest: The desktop hasn't been seeq'd since before the change. The laptop is occasionally and unpredictably seeq'd. For example, this morning I clicked on Yahoo in my drop down of recently visited URLs and got seeq'd. I then did a web search (using the MSN home page) for Yahoo sports and clicked on the results link and was successful. Also, do you think changing internet service provider would help? Would that potentially eliminate the seeq? The ISP I use now - their tech help seems clueless - and insistent that something is on my machine. regards, cj
Making the same change on your laptop would be OK. I don't know about changing ISP's? Their tech support just probably hasn't ran into this before. Frankly, if I hadn't ran into a similar problem, I'd probably be clueless as well… Besides, we're not 100 per cent sure this is a "fix" at this point anyway. Give it a few days, and then post back and let me know. Post back sooner if you get "SEEQ'ed" again. :) :thumbup:
I will keep an eye on it and report back if it shows up. If it doesn't show up I'll report back in 72 hours. As always, thanks.
Micah, Haven't had a problem with seeq since the latest change - I think it may be gone. Thanks so much for the help. regards,' cj
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI