I have XP Home Edition.
When I type incorrect web address in my IE,receive message that this site not exist&IE open new
page startnow.com.After that my CPU USE 100% capacity because svchost.exe use 100%.The only way to reduce this capacity is to restart PC.I think that I must do something with IE PROPERTIES but what????
THANKS
Logfile of HijackThis v1.97.7
Scan saved at 8:46:20 PM, on 10/4/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Ati2ev
xx.exe
C:\WINDOWS\system32\crypse
rv.exe
C:\PROGRA~1\MICROS~4\MSSQL
$~1\binn\s
qlservr.ex
e
C:\Program Files\QKeys\QKeys.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\WINDOWS\System32\ehjzbh
.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Siemens ISDN Utilities\calltray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
ngr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\slserv
.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\slrundll.exe
C:\WINDOWS\System32\taskmg
r.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\user\Desktop\Hija
ckThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://minisearch.startnow.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://minisearch.startnow.com/R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://minisearch.startnow.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://minisearch.startnow.com/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.startnow.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://minisearch.startnow.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://minisearch.startnow.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://minisearch.startnow.com/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://minisearch.startnow.com/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://minisearch.startnow.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page_bak =
http://www.yahoo.com/R3 - URLSearchHook: HyperSearchHook - {0E59CAB7-6610-45FE-9634-4
E5510EC6B7
3} - C:\Program Files\Common Files\Hyperbar\HyperbarSS3
.dll
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F
1C52D674FA
D} - (no file)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-1
4154ECE70A
C} - C:\Program Files\MyWay\myBar\1.bin\MY
BAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: HyperBHO - {4B2F5308-2CB0-40E2-8030-5
9936ED5D22
C} - C:\Program Files\Common Files\Hyperbar\Hyperbar.dl
l
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-1
4154ECE70A
C} - C:\Program Files\MyWay\myBar\1.bin\MY
BAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [QKeys] C:\Program Files\QKeys\QKeys.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [smbfadidrhnlk] C:\WINDOWS\System32\ehjzbh
.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - Global Startup: CAPI Monitor.lnk = C:\Program Files\Siemens ISDN Utilities\calltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
ngr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
2.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
2.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
2.dll/cmca
che.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
2.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
2.dll/cmtr
ans.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2
407B42F57C
9} (MSSecurityAdvisor Class) -
http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1093242894266O16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38139.0261458333O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{0
50A5FFF-4B
32-4309-94
F1-C48EF83
71597}: NameServer = 10.2.8.10,10.3.8.10
O17 - HKLM\System\CCS\Services\T
cpip\..\{0
E9267EE-D4
10-42BA-B6
1C-341D49C
77BCE}: NameServer = 10.2.8.10