![]() |
|
|||||||
| Spyware Cleaning Section Closed!! |
| Notice: The spyware cleaning (HijackThis) section is closed. Wilders Security no longer provides one on one spyware cleaning assistance. Please see this announcement for a list of websites that provide such services. |
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
I cannot get rid of this appearing
i have tried everything from deleting all registry entries to re naming the DLL file and deleting all of its contents but this res://ixiue.dll/index.html still keeps coming up here is my log from hijack this, i have tried deleting everything in here that contains part of it but it keeps coming back, any help would be highly appreciated, thanks Daniel Logfile of HijackThis v1.97.7 Scan saved at 12:31:47 PM, on 17/06/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Canon\VDC\AuVdc.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\SMART Board software\SMARTBoardService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\VetMsgNT.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\d3kl.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ipyl32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\regedit.exe \Server\Downloads\Programs\spybot\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ixiue.dll/sp.html#96676 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ixiue.dll/index.html#96676 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ixiue.dll/index.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ixiue.dll/sp.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ixiue.dll/index.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ixiue.dll/sp.html#96676 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.altavista.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://SERVER:8080 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.altavista.com/ O2 - BHO: (no name) - {51751739-CAF1-E684-719C-4B1197FD588C} - C:\WINDOWS\apieh32.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [ipyl32.exe] C:\WINDOWS\system32\ipyl32.exe O9 - Extra button: Research (HKLM) O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM) O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM) O16 - DPF: ServerPushBox - http://10.0.0.254/servp14.cab O16 - DPF: WebConnect Pro 5.1.7 - https://s1web4.cnh.com/WebConnectDU.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://digitalwebbooks.com/reader/dbplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeup...ntent/opuc.cab O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://10.0.0.188/activex/AxisCamControl.cab O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.comp...bio5_1_6_0.cab O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/crack.CAB O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.mcos.com.au.local O17 - HKLM\Software\..\Telephony: DomainName = corp.mcos.com.au.local O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.mcos.com.au.local O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = corp.mcos.com.au.local |
|
#2
|
||||
|
||||
|
Hi robbo5253,
Click Start > Run > Services.msc > OK In the services window find Network Security Service. Rightclick and stop it. Put the Startup type to disabled under Properties > General tab Then open TaskManager and stop these two processes: C:\WINDOWS\system32\d3kl.exe C:\WINDOWS\system32\ipyl32.exe Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ixiue.dll/sp.html#96676 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ixiue.dll/index.html#96676 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ixiue.dll/index.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ixiue.dll/sp.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ixiue.dll/index.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ixiue.dll/sp.html#96676 O2 - BHO: (no name) - {51751739-CAF1-E684-719C-4B1197FD588C} - C:\WINDOWS\apieh32.dll O4 - HKLM\..\Run: [ipyl32.exe] C:\WINDOWS\system32\ipyl32.exe O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/crack.CAB Then reboot into safe mode and delete: C:\WINDOWS\ixiue.dll C:\WINDOWS\apieh32.dat C:\WINDOWS\system32\ipyl32.exe C:\WINDOWS\system32\d3kl.exe Post a new log when you are done, so we can see if everything worked out as planned. Regards, Pieter
__________________
Regards, Pieter Itīs nice to be important, but itīs more important to be nice. It's human to make mistakes. It's even more so to blame the computer for it. |
|
#3
|
|||
|
|||
|
cheers for that, worked a treat!! all is well now, thanks for that
seams ad aware has a sort of fix for the same fault in it thanks for the help i will def be using this forum again |
|
#4
|
||||
|
||||
|
__________________
Regards, Pieter Itīs nice to be important, but itīs more important to be nice. It's human to make mistakes. It's even more so to blame the computer for it. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|