hijack this log

Discussion in 'adware, spyware & hijack cleaning' started by Kristian Schling, Mar 25, 2004.

Thread Status:
Not open for further replies.
  1. Hello!

    My IE start page is being changed to about:blank all the time
    I´ve run ad aware spybot and spyware blaster and guard.
    The problem remains though spyware asks me if I want it to be changed all the time now.
    Here is the hijack this log

    Logfile of HijackThis v1.97.7
    Scan saved at 00:28:40, on 2004-03-26
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\System32\Ati2evxx.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\Program\Norton AntiVirus\navapsvc.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\WINDOWS\Explorer.EXE
    D:\WINDOWS\SOUNDMAN.EXE
    D:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
    D:\Program\Delade filer\InterVideo\SchSvr\SchSvr.exe
    D:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
    D:\Program\Delade filer\Real\Update_OB\realsched.exe
    D:\Program\QuickTime\qttask.exe
    D:\Program\NORTON~1\navapw32.exe
    D:\Program\Logitech\iTouch\iTouch.exe
    D:\Program\ICQLite\ICQLite.exe
    D:\Program\Messenger\msmsgs.exe
    D:\Program\SpywareGuard\sgmain.exe
    D:\Program\OpenOffice.org1.1.0\program\soffice.exe
    D:\Program\SpywareGuard\sgbhp.exe
    D:\Program\Windows Media Player\wmplayer.exe
    D:\Program\Internet Explorer\iexplore.exe
    D:\Documents and Settings\Kristian\Skrivbord\hijackthis1977\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
    O1 - Hosts: 213.159.117.235 auto.search.msn.com
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Program\SpywareGuard\dlprotect.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A
     
  2. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,144
    Location:
    North Carolina, USA
    Hi Kristian Schling,

    Welcome to Wilders!!!

    It looks like your log got cut off....
    Would you please repost your entire log?

    Regards,
    Kent
     
  3. I thought it was a bit short..
    Here it is:

    Logfile of HijackThis v1.97.7
    Scan saved at 00:45:47, on 2004-03-26
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\System32\Ati2evxx.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\WINDOWS\Explorer.EXE
    D:\WINDOWS\SOUNDMAN.EXE
    D:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
    D:\Program\Delade filer\InterVideo\SchSvr\SchSvr.exe
    D:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
    D:\Program\Delade filer\Real\Update_OB\realsched.exe
    D:\Program\QuickTime\qttask.exe
    D:\Program\NORTON~1\navapw32.exe
    D:\Program\Logitech\iTouch\iTouch.exe
    D:\Program\ICQLite\ICQLite.exe
    D:\Program\Messenger\msmsgs.exe
    D:\Program\Norton AntiVirus\navapsvc.exe
    D:\Program\OpenOffice.org1.1.0\program\soffice.exe
    D:\Program\SpywareGuard\sgmain.exe
    D:\WINDOWS\System32\svchost.exe
    D:\Program\SpywareGuard\sgbhp.exe
    D:\Program\Internet Explorer\iexplore.exe
    D:\Documents and Settings\Kristian\Skrivbord\hijackthis1977\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
    O1 - Hosts: 213.159.117.235 auto.search.msn.com
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Program\SpywareGuard\dlprotect.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [ATIPTA] D:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Home Theater SchSvr] "D:\Program\Delade filer\InterVideo\SchSvr\SchSvr.exe"
    O4 - HKLM\..\Run: [IHTWINCINEMAMGR] D:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - HKLM\..\Run: [TkBellExe] "D:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NAV Agent] D:\Program\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] D:\Program\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [ICQ Lite] D:\Program\ICQLite\ICQLite.exe -minimize
    O4 - HKCU\..\Run: [MSMSGS] "D:\Program\Messenger\msmsgs.exe" /background
    O4 - Startup: OpenOffice.org 1.1.0.lnk = D:\Program\OpenOffice.org1.1.0\program\quickstart.exe
    O4 - Startup: SpywareGuard.lnk = D:\Program\SpywareGuard\sgmain.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
    O9 - Extra button: ICQ Lite (HKLM)
    O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/21cabb0f17737246e606/netzip/RdxIE601.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38067.1923032407
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
     
  4. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,144
    Location:
    North Carolina, USA
    Hi Kristian Schling,

    Welcome to Wilders.

    Check the following items in HijackThis.
    Close all windows except HijackThis and click Fix checked:

    O1 - Hosts: 213.159.117.235 auto.search.msn.com

    16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/21cabb0f17737246e606/netzip/RdxIE601.cab

    Download CWShredder and run. Be sure ALL other windows are closed use the Fix button and follow the instructions you will receive.

    Reboot and then post a fresh HijackThis log.

    Regards,
    Kent
     
  5. That did the trick... Thanks a lot



    Logfile of HijackThis v1.97.7
    Scan saved at 01:18:50, on 2004-03-26
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\System32\Ati2evxx.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\WINDOWS\Explorer.EXE
    D:\WINDOWS\SOUNDMAN.EXE
    D:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
    D:\Program\Delade filer\InterVideo\SchSvr\SchSvr.exe
    D:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
    D:\Program\Delade filer\Real\Update_OB\realsched.exe
    D:\Program\QuickTime\qttask.exe
    D:\Program\NORTON~1\navapw32.exe
    D:\Program\Logitech\iTouch\iTouch.exe
    D:\Program\ICQLite\ICQLite.exe
    D:\Program\Messenger\msmsgs.exe
    D:\Program\OpenOffice.org1.1.0\program\soffice.exe
    D:\Program\SpywareGuard\sgmain.exe
    D:\Program\SpywareGuard\sgbhp.exe
    D:\Program\Norton AntiVirus\navapsvc.exe
    D:\WINDOWS\System32\svchost.exe
    D:\Documents and Settings\Kristian\Skrivbord\hijackthis1977\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Program\SpywareGuard\dlprotect.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [ATIPTA] D:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Home Theater SchSvr] "D:\Program\Delade filer\InterVideo\SchSvr\SchSvr.exe"
    O4 - HKLM\..\Run: [IHTWINCINEMAMGR] D:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - HKLM\..\Run: [TkBellExe] "D:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NAV Agent] D:\Program\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] D:\Program\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [ICQ Lite] D:\Program\ICQLite\ICQLite.exe -minimize
    O4 - HKCU\..\Run: [MSMSGS] "D:\Program\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\RunOnce: [ICQ Lite] D:\Program\ICQLite\ICQLite.exe -trayboot
    O4 - Startup: OpenOffice.org 1.1.0.lnk = D:\Program\OpenOffice.org1.1.0\program\quickstart.exe
    O4 - Startup: SpywareGuard.lnk = D:\Program\SpywareGuard\sgmain.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
    O9 - Extra button: ICQ Lite (HKLM)
    O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38067.1923032407
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
     
  6. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,144
    Location:
    North Carolina, USA
    Hi Kristian Schling,

    Good work, your log is clean now!!

    Regards,
    Kent
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.