This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log - Homepage Kidnapped!

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, all the keys which i reset were all still set to about:blank, so I guess thats not the problem. The system is running fine and CWShredder hasnt picked anything up, nor has Hijack This! so perhaps its gone. Is there anyother sort of diagnostic test like those two which could check out my system and makesure its clean and that the item Adaware is picking up is nothing?
We got rid of the hidden hijacker so the problem will be fixed. AAW may be detecting a remnant, however, I'm not sure why it won't clean it.

Expert member freeatlast has a diagnostic tool for this one, we can check it if you wish but I'm not expecting anything to show up. Click here and download 'Find-All.zip'. Unzip and run the 'findall.bat' file inside. It'll run for a while and generate a file called output.txt - save it and paste the contents of 'output.txt' in your next reply.
Heres the info from the scan: –==***@@@ 'FIND-ALL' VERSION 7 -5/24 @@@***==– Sun May 23 22:16:26 2004 – Results: *System Info: Microsoft Windows XP [Version 5.1.2600] C: "" (FC03:0421) - FS:NTFS clusters:4k Total: 30 005 788 672 [28G] - Free: 19 584 983 040 [18G] *IE version and Service packs: 6.0.2800.1106 C:\Program Files\Internet Explorer\Iexplore.exe ! REG.EXE VERSION 2.0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings MinorVersion REG_SZ ;SP1;Q832894;Q831167; *Google Toolbar version and Attributes: Defaults: "A" ;"R" Path not found - C:\Program Files\google Path not found - C:\Program Files\google *UserAgent: REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] *Wmplayer version: 9.0.0.2980 C:\Program Files\Windows Media Player\wmplayer.exe 6.4.9.1125 C:\Program Files\Windows Media Player\mplayer2.exe *M$Java version: 5.0.3810.0 C:\WINDOWS\System32\msjava.dll *PC uptime: 10:16pm up 0 days, 10:59 *Locked or 'Suspect' file(s) found… *Tasks (services): 0 System Process 4 System 456 smss.exe 504 csrss.exe Title: 528 winlogon.exe Title: NetDDE Agent 572 services.exe Svcs: Eventlog,PlugPlay 584 lsass.exe Svcs: PolicyAgent,ProtectedStorage,SamSs 748 svchost.exe Svcs: RpcSs 800 svchost.exe Svcs: AudioSrv,Browser,CryptSvc,Dhcp,dmserver,ERSvc,EventSystem,FastUserSwitchingCompatibility,helpsvc,HidServ,lanmanserver,lanmanworkstation,Netman,Nla,RasMan,Schedule,seclogon,SENS,SharedAccess,ShellHWDetection,srservice,TapiSrv,TermService,Themes,TrkWks,uplo 880 svchost.exe Svcs: Dnscache 908 svchost.exe Svcs: LmHosts,RemoteRegistry,SSDPSRV,WebClient 1136 spoolsv.exe Svcs: Spooler 1356 explorer.exe Title: Program Manager 1600 CursorXP.exe Title: 1624 alg.exe Svcs: ALG 1648 acsd.exe Svcs: AOL ACS 1724 Navapsvc.exe Svcs: navapsvc 1788 NPROTECT.EXE Svcs: NProtectService 1824 nvsvc32.exe Svcs: NVSvc 1916 NOPDB.EXE Svcs: Speed Disk service 1976 svchost.exe Svcs: stisvc 2004 wanmpsvc.exe Svcs: WANMiniportService 3228 cmd.exe Title: C:\WINDOWS\System32\cmd.exe 3232 ntvdm.exe 2472 tlist.exe REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 "AppInit_DLLs"="" REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}] @="NAV Helper" REGEDIT4 [HKEY_CLASSES_ROOT\PROTOCOLS\Filter] [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\Class Install Handler] @="AP Class Install Handler filter" "CLSID"="{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}" [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\deflate] @="AP Deflate Encoding/Decoding Filter " "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}" [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\gzip] @="AP GZIP Encoding/Decoding Filter " "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}" [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\lzdhtml] @="AP lzdhtml encoding/decoding Filter" "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}" [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/webviewhtml] @="WebView MIME Filter" "CLSID"="{733AC4CB-F1A4-11d0-B951-00A0C90312E1}" *Security settings for 'Windows' key: ! REG.EXE VERSION 2.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows AppInit_Dlls REG_SZ RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (NI) ALLOW Read BUILTIN\Users (IO) ALLOW Read BUILTIN\Users (NI) ALLOW Read BUILTIN\Power Users (IO) ALLOW Read BUILTIN\Power Users (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Read BUILTIN\Power Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM *ACLs list: *Contents of file(s) in 'junk' folder: *Md5sums Sun May 23 22:16:32 2004 – *Find-All 'Windows'.hiv list: A C:\DOCUME~1\Hero\Desktop\Find-All\winBackup.hiv A C:\DOCUME~1\Hero\Desktop\Find-All\windows.txt A C:\FindallwinBackup.hiv  Thanks for all the help… :D
AWESOME! Thank you so much for all your help. I really appreciate you guys taking so much time out to read so many logs and diagnose our computer problems. Its really a great asset to everyone. Thanks again! :wavey:
You're welcome - glad to help :D

As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI