-
Grand Future Air Dried Fresh Beef Dog Food
Air Dried Dog Food | Fresh Beef

Carnivore Diet for Dogs

Go Back   Automotive Forums Car Chat > Coffee Break (Off-Topic) > COMPLETELY off-topic
Register FAQ Community
COMPLETELY off-topic Talk about anything other than cars. But you can't be mad and angry in this forum!
Reply Show Printable Version Show Printable Version | Subscription Subscribe to this Thread
 
Thread Tools
  #1  
Old 08-26-2004, 07:25 PM
Killa_DSM's Avatar
Killa_DSM Killa_DSM is offline
AF Enthusiast
 
Join Date: Jan 2004
Posts: 726
Thanks: 0
Thanked 0 Times in 0 Posts
Unhappy Anyone good with comps in here, who can help me?

Help me!!!!! I think i have a Trojan in my comp. It changes my home page to http://www.windowws.cc/hp.htm?id=9 and i dont know how to get it out. Well here is my Hijack this log.
Hope someone can help.

Logfile of HijackThis v1.98.2
Scan saved at 3:02:48 PM, on 8/25/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\lexbces.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Windows\Compaq\Ereg\Remind32.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\--------\Desktop\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\jax3onl28lxtmv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [My Search Bar Eq] "C:\Program Files\MySearch\bar\s4bareq.exe" /r
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [searchassistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [romahere] C:\WINDOWS\System32\matrixhere.exe
O4 - HKLM\..\Run: [pnpsvc_lock] C:\WINDOWS\System32\933372.exe
O4 - HKCU\..\Run: [FileFreedom_Plugin] C:\Program Files\FileFreedom\wtm.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [romahere] C:\WINDOWS\System32\matrixhere.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Reminder-cpq40601.lnk = C:\WINDOWS\Compaq\Ereg\Remind32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.greg-search.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AAE311E-88F5-4840-8A9C-B22AD86FB55A}: NameServer = 63.93.96.20 63.93.96.21
__________________
"Life begins at 20psi"

97 Eclipse GST-X 5spd
PTE 5031e/pte 880cc/vr4 fuel pump/Devils Own Water injection 12gph nozzle/pre turbo meth injection/fmic 28x10.5x3.5/greddy type-s bov/12" K&N/FP intake/dsmlink/gm 3.3 bar/maft/blitz ebc/act 2600/act 6 puck/SS Clutch line/3" turboback.

Last edited by Killa_DSM; 12-09-2009 at 04:38 AM.
Reply With Quote
  #2  
Old 08-26-2004, 09:26 PM
vladlos's Avatar
vladlos vladlos is offline
AF Enthusiast
 
Join Date: Jul 2004
Posts: 580
Thanks: 0
Thanked 0 Times in 0 Posts
Send a message via AIM to vladlos
Re: Anyone good with comps in here, who can help me?

first of all, download something like "Spybot - Search and Destroy" to get rid of any spyware on your computer. Go to www.euyulio.org and download a good trojan horse remover. I'm kind of thinking its more of spyware/adware problem you've got there and not a trojan/hacker problem.
__________________
Reply With Quote
  #3  
Old 08-27-2004, 03:28 AM
-Jayson-'s Avatar
-Jayson- -Jayson- is offline
AF Enthusiast
 
Join Date: Apr 2004
Posts: 3,634
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Anyone good with comps in here, who can help me?

no you want adware, thats the best in my opinion.

www.lavasoft.com and download adware 6.0 its free and works wonders.
__________________
2009 Ninja 650 R
stock for now...

SouthEast Ecotec Enthusiast
Reply With Quote
  #4  
Old 08-27-2004, 12:33 PM
Shortbus Shortbus is offline
Blah blah blah
 
Join Date: Aug 2002
Posts: 15,483
Thanks: 3
Thanked 3 Times in 3 Posts
Send a message via AIM to Shortbus
Re: Anyone good with comps in here, who can help me?

Looks like you have a variation of cool web search running in your registry. Get CWS shredder and run that, also boot up in safe mode and run Ad-aware it is by far the best removal tool spyware. You may also be able to remove "mysearchbar" fromthe add remove programs in the CP.
Reply With Quote
  #5  
Old 08-27-2004, 01:16 PM
Spyke^ Spyke^ is offline
AF Regular
 
Join Date: Feb 2004
Posts: 124
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Anyone good with comps in here, who can help me?

If you want to post your Hijack This log, you really should go to http://www.security-forums.com/forum/index.php

You might have to register to get to their Hijack This section, I can't remember, I'm a member so it will load for me..
Anyway, for any sort of computer problem they are the ones to get ahold of.
Excellent bunch of guys/gals.
Very impressive knowledge base.
Anything from Trojans, Firewalls, data encryption etc..
One thing though, they would be considered White Hats so don't even bother asking for advice on how to "Hack" or anything along that line.

Hope this helps..
Reply With Quote
  #6  
Old 08-27-2004, 01:35 PM
Killa_DSM's Avatar
Killa_DSM Killa_DSM is offline
AF Enthusiast
Thread starter
 
Join Date: Jan 2004
Posts: 726
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Anyone good with comps in here, who can help me?

Ok thats everyone for your help. I got winpatrol and i think i got it out.
__________________
"Life begins at 20psi"

97 Eclipse GST-X 5spd
PTE 5031e/pte 880cc/vr4 fuel pump/Devils Own Water injection 12gph nozzle/pre turbo meth injection/fmic 28x10.5x3.5/greddy type-s bov/12" K&N/FP intake/dsmlink/gm 3.3 bar/maft/blitz ebc/act 2600/act 6 puck/SS Clutch line/3" turboback.
Reply With Quote
  #7  
Old 08-30-2004, 01:10 AM
SSBigBlock's Avatar
SSBigBlock SSBigBlock is offline
AF Enthusiast
 
Join Date: Aug 2004
Posts: 229
Thanks: 0
Thanked 0 Times in 0 Posts
Send a message via AIM to SSBigBlock Send a message via MSN to SSBigBlock Send a message via Yahoo to SSBigBlock
Re: Anyone good with comps in here, who can help me?

If all else fails but your fails you don't want to lose in a back up file, make sure they arn't currupt. Then reformat your pc.
__________________
Runs with the Hatchet.


This is the year were hope fails you
Reply With Quote
 
Reply

POST REPLY TO THIS THREAD

Go Back   Automotive Forums Car Chat > Coffee Break (Off-Topic) > COMPLETELY off-topic


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -5. The time now is 08:28 PM.

Community Participation Guidelines | How to use your User Control Panel

Powered by: vBulletin | Copyright Jelsoft Enterprises Ltd.
 
 
no new posts