Hi I have been hijacked and can't seem to get it fixed.
When I open up IE 6 I get a page that says about:blank in the address bar.
When I change my home page back to google and close my browser, when I open it back up it resets to that page which has a search bar and what seems to be advertisements ( yea Im gonna buy from them). I also have a play strip poker advertisement pop up every so often.
I ran Spybot and got rid af all it found then I ran hijack this and put it in the web site to check it out. I re=moved all it sayed to and when I opened my browser back up it was the same so I ran Hijack this again and all of the R-1 HKCU files that I deleted are back. Her is a posting of my log. Can you help me get rid of this?
Logfile of HijackThis v1.99.0
Scan saved at 12:36:18 PM, on 1/18/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32
.DLL
C:\WINDOWS\SYSTEM\MSGSRV32
.EXE
C:\WINDOWS\SYSTEM\MPREXE.E
XE
C:\PROGRAM FILES\EASY INTERNET\ENCMONTR.EXE
C:\WINDOWS\SYSTEM\MSTASK.E
XE
C:\WINDOWS\SYSTEM\MSGLOOP.
EXE
C:\WINDOWS\SYSTEM\MSG32.EX
E
C:\WINDOWS\SYSTEM\mmtask.t
sk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.
EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV
.EXE
C:\WINDOWS\SYSTEM\USBMMKBD
.EXE
C:\WINDOWS\TPPALDR.EXE
C:\WINDOWS\SYSTEM\STIMON.E
XE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\WINDOWS\SYSTEM\USBMONIT
.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\WMIEXE.E
XE
C:\WINDOWS\SYSTEM\USRSHUTD
.EXE
C:\WINDOWS\SYSTEM\VWIPXSPN
T.EXE
C:\WINDOWS\SYSTEM\TLNTADMN
X.EXE
C:\WINDOWS\SYSTEM\PSTORES.
EXE
C:\WINDOWS\SYSTEM\DDHELP.E
XE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DESKTOP\HIJACKT
HIS.EXE
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\MC
ICDB.DLL/s
p.html (obfuscated)
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\MC
ICDB.DLL/s
p.html (obfuscated)
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\MC
ICDB.DLL/s
p.html (obfuscated)
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\MC
ICDB.DLL/s
p.html (obfuscated)
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINDOWS\SYSTEM\MC
ICDB.DLL/s
p.html (obfuscated)
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINDOWS\SYSTEM\MC
ICDB.DLL/s
p.html (obfuscated)
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: sPeerObj Class - {00000026-8735-428D-B81F-D
D098223B25
F} - C:\WINDOWS\SPEER.DLL
O2 - BHO: (no name) - {8420BB60-686A-11D9-9F02-0
00C41EA898
0} - C:\WINDOWS\SYSTEM\MSEAN.DL
L
O2 - BHO: (no name) - {916B7121-686A-11D9-9F02-0
00C3F5B0F2
0} - C:\WINDOWS\SYSTEM\MCICDB.D
LL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\SYSTEM\MSDXM.OC
X
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPw
rScheme
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFi
x.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv
.exe
O4 - HKLM\..\Run: [USBMMKBD] usbmmkbd.exe
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\stimon.e
xe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE
~1\AVGCC.E
XE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE
~1\AVGEMC.
EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE
~1\AVGAMSV
R.EXE
O4 - HKLM\..\Run: [Gene USB Monitor] c:\windows\SYSTEM\USBMonit
.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPw
rScheme
O4 - HKLM\..\RunServices: [Encompass_ENCMONTR] C:\Program Files\Easy Internet\ENCMONTR.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUND
LLENTRY
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR
1.DLL/cmse
arch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR
1.DLL/cmca
che.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR
1.DLL/cmsi
milar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR
1.DLL/cmba
cklinks.ht
ml
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR
1.DLL/cmtr
ans.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\SYSTEM\Shdocvw.
dll
O12 - Plugin for .mpeg: C:\PROGRA~1\INTERN~1\PLUGI
NS\npqtplu
gin3.dll
O15 - Trusted Zone:
http://*.63.219.181.7O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-0
4F4EACC2F3
B} (InstallShield Setup Player 2K2) -
http://www.jetsetpoker.com/setup.exeO16 - DPF: {11212111-2121-1311-1141-1
1561111122
2} - ms-its:mhtml:file://d: oo.mht!
http://69.50.166.212/counter/new/x.chm::/update.exeO17 - HKLM\System\CCS\Services\V
xD\MSTCP: NameServer = 69.50.188.180,195.225.176.
31
O18 - Filter: text/html - {916B7120-686A-11D9-9F02-0
00C5017AAB
B} - C:\WINDOWS\SYSTEM\MCICDB.D
LL
O18 - Filter: text/plain - {916B7120-686A-11D9-9F02-0
00C5017AAB
B} - C:\WINDOWS\SYSTEM\MCICDB.D
LL
I am starting the points low as I don't know how difficult this will be but if it gets drawn out I will award more.
Thanks sfogle