Advertisement

04.02.2004 at 05:06PM PST, ID: 20942106
[x]
Attachment Details

browser hijack/possible worm?

Asked by synjlet in Miscellaneous

Tags: hijack

i have run ad aware,  goodbye spy,  spybot S&D,  and hijack this.  they all destroyed a good number of things, but i continually get that damn default-homepage-network thing.  it seems to be on a timer, as it replaces my homepage every 5 minutes or so which makes browsing downright annoying.  it happens each time i re-open IE after 5 minutes of not using it.

i saw a previous person's post about this, and following the instruction did not seem to help me.

here is my hijack this log:



Logfile of HijackThis v1.97.6
Scan saved at 8:07:45 PM, on 4/2/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\System32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\DRIVERS\CDANTSRV.EXE
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Supero Doctor II\NTService.exe
C:\WINNT\System32\Tablet.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINNT\Explorer.EXE
C:\Program Files\AIM95\aim.exe
C:\WINNT\System32\wuauclt.exe
C:\WINNT\System32\mshta.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\mshta.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\SYSTEM32\CS4P028.EXE
C:\WINNT\SYSTEM32\CS4P028.EXE
C:\WINNT\System32\mshta.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\mshta.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\SYSTEM32\CS4P028.EXE
C:\WINNT\SYSTEM32\CS4P028.EXE
C:\WINNT\System32\mshta.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\SYSTEM32\CS4P028.EXE
C:\WINNT\System32\mshta.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\SYSTEM32\CS4P028.EXE
C:\WINNT\System32\mshta.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\mshta.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\SYSTEM32\CS4P028.EXE
C:\WINNT\SYSTEM32\CS4P028.EXE
C:\Program Files\mIRC\mirc.exe
C:\WINNT\System32\mshta.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\SYSTEM32\CS4P028.EXE
C:\Program Files\Macromedia\Flash MX\Flash.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Kazaa Lite\kazaalite.kpp
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijackthis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?hkcu
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.synj.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?hklm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?hklm
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKLM\..\RunOnce: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" "+b1"
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Allow Site's Pop-&ups - file://C:\Program Files\PopNot\trustsite.script
O8 - Extra context menu item: Always &Kill this Pop-up - file://C:\Program Files\PopNot\blocksite.script
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

please help!  it has been annoying me for over a week.  it's the only spyware i've ever had a serious problem with.
Start Free Trial
[+][-]04.02.2004 at 05:06PM PST, ID: 10745706

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.02.2004 at 05:06PM PST, ID: 10745707

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.02.2004 at 05:07PM PST, ID: 10745711

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.02.2004 at 05:09PM PST, ID: 10745721

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.02.2004 at 05:10PM PST, ID: 10745730

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.02.2004 at 05:12PM PST, ID: 10745741

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zone: Miscellaneous
Tags: hijack
Sign Up Now!
Solution Provided By: CrazyOne
Participating Experts: 5
Solution Grade: A
 
 
[+][-]04.02.2004 at 05:32PM PST, ID: 10745821

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.27.2004 at 12:54PM PDT, ID: 10932529

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.30.2004 at 07:42PM PDT, ID: 10965483

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.01.2004 at 08:26AM PDT, ID: 11447676

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32