Start a Conversation

Unsolved

This post is more than 5 years old

764

September 14th, 2004 16:00

help me .....hijaackthis log...about:blank

​unning processes:​
​C:\WINDOWS\System32\smss.exe​
​C:\WINDOWS\system32\winlogon.exe​
​C:\WINDOWS\system32\services.exe​
​C:\WINDOWS\system32\lsass.exe​
​C:\WINDOWS\system32\svchost.exe​
​C:\WINDOWS\System32\svchost.exe​
​C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe​
​C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe​
​C:\WINDOWS\system32\spoolsv.exe​
​C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe​
​C:\Program Files\Norton AntiVirus\navapsvc.exe​
​C:\WINDOWS\System32\nvsvc32.exe​
​C:\WINDOWS\System32\svchost.exe​
​C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe​
​C:\Program Files\Norton AntiVirus\SAVScan.exe​
​C:\WINDOWS\Explorer.EXE​
​C:\WINDOWS\System32\RUNDLL32.EXE​
​C:\Program Files\Apoint\Apoint.exe​
​C:\Program Files\Dell\AccessDirect\dadapp.exe​
​C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe​
​C:\Program Files\Dell\Support\Alert\bin\DAMon.exe​
​C:\Program Files\QuickTime\qttask.exe​
​C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe​
​C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe​
​C:\Program Files\Dell\AccessDirect\DadTray.exe​
​C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe​
​C:\Program Files\Common Files\Symantec Shared\ccApp.exe​
​C:\Program Files\Common Files\Real\Update_OB\realsched.exe​
​C:\Program Files\Messenger\msmsgs.exe​
​C:\Program Files\WinZip\WZQKPICK.EXE​
​C:\Program Files\Apoint\Apntex.exe​
​C:\WINDOWS\System32\wuauclt.exe​
​C:\WINDOWS\wmsetup.log:pofwv​
​C:\WINDOWS\nttz.exe​
​C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe​
​C:\unzipped\hijackthis\HijackThis.exe​

​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R3 - Default URLSearchHook is missing​
​O2 - BHO: (no name) - {064B07E4-3062-F9A9-AD59-69604F8C8F77} - C:\WINDOWS\system32\msst32.dll​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx​
​O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll​
​O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx​
​O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll​
​O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll​
​O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize​
​O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe​
​O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe​
​O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"​
​O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime​
​O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe​
​O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe​
​O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe​
​O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"​
​O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot​
​O4 - HKLM\..\Run: [nttz.exe] C:\WINDOWS\nttz.exe​
​O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background​
​O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE​
​O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE​
​O8 - Extra context menu item: &Yahoo! Search - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycsrch.htm​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000​
​O8 - Extra context menu item: Yahoo! &Dictionary - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycdict.htm​
​O8 - Extra context menu item: Yahoo! &Maps - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycdict.htm​
​O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll​
​O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll​
​O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE​
​O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - ​​http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll​
​O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - ​​http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab​
​O17 - HKLM\System\CCS\Services\Tcpip\..\{D4A36E32-2805-4D23-A512-3D415ACF3DCC}: NameServer = 199.45.32.43,199.45.32.38
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\iupjf.dll/sp.html#29126​
​R3 - Default URLSearchHook is missing​
​O2 - BHO: (no name) - {064B07E4-3062-F9A9-AD59-69604F8C8F77} - C:\WINDOWS\system32\msst32.dll​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx​
​O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll​
​O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx​
​O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll​
​O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll​
​O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize​
​O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe​
​O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe​
​O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"​
​O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime​
​O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe​
​O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe​
​O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe​
​O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"​
​O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot​
​O4 - HKLM\..\Run: [nttz.exe] C:\WINDOWS\nttz.exe​
​O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background​
​O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE​
​O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE​
​O8 - Extra context menu item: &Yahoo! Search - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycsrch.htm​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000​
​O8 - Extra context menu item: Yahoo! &Dictionary - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycdict.htm​
​O8 - Extra context menu item: Yahoo! &Maps - ​​file:///C:\Program​​ Files\Yahoo!\Common/ycdict.htm​
​O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll​
​O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll​
​O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE​
​O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - ​​http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll​
​O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - ​​http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab​
​O17 - HKLM\System\CCS\Services\Tcpip\..\{D4A36E32-2805-4D23-A512-3D415ACF3DCC}: NameServer = 199.45.32.43,199.45.32.38

​ ​

860 Posts

September 14th, 2004 20:00

Scan your computer on http://security.symantec.com
scan your computer for spyware here http://www.pestscan.com/
Run http://www.safer-networking.org/en/mirrors/index.html spybot

Run http://www.majorgeeks.com/download4289.html about:buster
Run Cwshredder http://www.majorgeeks.com/download4086.html


run a browser which spyware cannot hijack that easily http://www.mozilla.org/products/firefox/

http://www.fixyourwindows.com/windowsxpsolutions.htm


If the above fixes fail you would need to run hijackthis

All hijackthis posts need to be posted on the sites listed below not here

http://www.a-sap.org/

http://amazingtechs.com/index.php?act=idx
Forum Led by: discogail, bistro, njustice

http://www.bleepingcomputer.com/forums/
Forum Led by: Moderators, Global Moderator, groovicus,Grinler,harrywaldron,Papakid,

http://forums.net-integration.net/
Forum Led by: Global Moderator, Administrators, Technical Experts, Technical Assistant, Team

Spybot S&D, Technical Guide
TonyKlein,Eagle1,Galadriel,tashi,Archon_Wing,

http://forums.subratam.org/
Forum Led by: Forum Moderators,subratam,baskar1234,efwis,Metallica,psyne, SpyDie, normmork, Admin

http://www.zerosrealm.com/forums/
Zero,Lopus,


http://forum.gladiator-antivirus.com/
Forum Led by: CalamityJane, LoPhatPhuud, FatsGordon,Hunter,TheSentinel,


http://forums.techguy.org/
$teve ,flrman1,Rollin' Rog ,whz ,Davey7549

http://forums.thatcomputerguy.us/
Forum Led by: Searcher, Matrix420, Forum Moderator

No Events found!

Top