I have tried everything to get rid of the invasive browser hijaker including running all the utilities out there. i.e. Adaware, bugblaster,cwshredder etc...I have also deleted all temp files, cookies, reset home page, deleted registry keys, values..all to no avail
Can this be fixed...also going forward, what do I need to do to prevent this garbage installing on my PC....???
Here is the log file of hijack this..
Logfile of HijackThis v1.97.7
Scan saved at 9:44:20 AM, on 7/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\VPN\VPN Client\icsrv.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpm
gr.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpotdd01.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\BigFix\BigFix.exe
C:\WINDOWS\System32\rundll
32.exe
C:\WINDOWS\System32\MsgSys
.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\User\Desktop\Hija
ckThis.exe
C:\Documents and Settings\User\Desktop\Hija
ckThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LO
CALS~1\Tem
p\sp.html
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LO
CALS~1\Tem
p\sp.html
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = file://C:\DOCUME~1\User\LO
CALS~1\Tem
p\sp.html
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LO
CALS~1\Tem
p\sp.html
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LO
CALS~1\Tem
p\sp.html
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
www.google.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = file://C:\DOCUME~1\User\LO
CALS~1\Tem
p\sp.html
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Internet Explorer provided by Bell
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\WINNT\system32\blank.ht
m
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,Shellnext =
http://www.bellnexxia.com/O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIE
Helper.ocx
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O2 - BHO: (no name) - {CF4D4E99-F0EB-4D7C-9EA1-8
A29DE1DC20
F} - C:\WINDOWS\System32\mngcb.
dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
09B6AD74AC
C} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpm
gr.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4\PopupStopper.exe"
O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O14 - IERESET.INF: START_PAGE_URL=
http://www.emachines.comO16 - DPF: JavaConnect -
http://imessenger.tdbank.ca/sametime/javaconnect/JavaConnect.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {39B0684F-D7BF-4743-B050-F
DC3F48F7E3
B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cabO16 - DPF: {62475759-9E84-458E-A1AB-5
D2C442ADFD
E} -
http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exeO16 - DPF: {644E432F-49D3-41A1-8DD5-E
099162EEEC
5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {9F77A997-F0F3-11d1-9195-0
0C04FC990D
C} (JavaBeansBridge Object) -
http://papap31.ccf.ops.tdbank.ca:6010/OA_HTML/ji115211.exeO16 - DPF: {A25BE7A9-3102-46B4-BAAE-4
62471B60AC
B} (STConnectivityAgent Control) -
http://imessenger.tdbank.ca/sametime/javaconnect/InstallSTConnAgent.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{F
63E5081-9C
24-415E-9A
19-946ECDB
45D24}: NameServer = 206.47.244.101 206.47.244.61
Start Free Trial