In trouble again...
I open internet explorer - and the default page it keeps opening on is::
http://win-eto.com/hp.htm?id=31403I have tried all the usual spyware - and remove some bugs but none fix this. - I have pasted in the hijackthis log below
It does report the following in the hijack log
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://win-eto.com/hp.htm?id=31403But I cannot find this in the registry and when I use hijack to fix, it never seems to do it...
Logfile of HijackThis v1.98.2
Scan saved at 11:01:25, on 09/12/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
.exe
C:\WINNT\system32\services
.exe
C:\WINNT\system32\lsass.ex
e
C:\WINNT\system32\svchost.
exe
C:\WINNT\System32\svchost.
exe
C:\WINNT\system32\spoolsv.
exe
d:\Program Files\Nokia\Nokia D211\D211CTL.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\system32\Hummbird
\inetd32.e
xe
C:\WINNT\system32\inetsrv\
inetinfo.e
xe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\nvsvc32.
exe
c:\oracle\bin\agntsrvc.exe
C:\WINNT\system32\cmd.exe
C:\Program Files\Novadigm\radexecd.ex
e
c:\oracle\bin\dbsnmp.exe
C:\Program Files\Novadigm\radsched.ex
e
C:\Program Files\Novadigm\Radstgms.ex
e
C:\TNGRCO\RCManClient.exe
C:\WINNT\system32\rcmdsvc.
exe
C:\TNGRCO\RCOService.exe
C:\WINNT\system32\regsvc.e
xe
C:\WINNT\system32\MSTask.e
xe
C:\TNGRCO\rp32u.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\SUSS.EXE
c:\oracle\Apache\jdk\bin\j
ava.exe
C:\Program Files\Common Files\PFShared\UmxCfg.exe
C:\WINNT\System32\WBEM\Win
Mgmt.exe
C:\WINNT\System32\wltrysvc
.exe
C:\WINNT\system32\svchost.
exe
C:\Program Files\Common Files\PFShared\UmxPol.exe
C:\WINNT\System32\bcmwltry
.exe
C:\Program Files\Tiny Personal Firewall\UmxAgent.exe
C:\Program Files\Tiny Personal Firewall\UmxTray.exe
C:\Program Files\Tiny Personal Firewall\DseCC.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\NavNT\vptray.exe
C:\WINNT\system32\NWTRAY.E
XE
C:\Program Files\QuickTime\qttask.exe
D:\Program Files\Nokia\Nokia D211\D211STRT.EXE
C:\Program Files\Java\j2re1.4.2_06\bi
n\jusched.
exe
C:\WINNT\system32\dk0puxk8
srthd.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\SPYWAR~1\PRJSP
Y~1.EXE
c:\program files\reflection\r2win.exe
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE
c:\program files\reflection\r2win.exe
c:\program files\reflection\r2win.exe
C:\Lotus\Notes\NLNOTES.EXE
C:\Lotus\Notes\nhldaemn.EX
E
C:\WINNT\regedit.exe
C:\Documents and Settings\mf_locadm\Desktop
\HijackThi
s.exe
C:\Program Files\JavaSoft\JRE\1.3.1_1
3\bin\java
w.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://win-eto.com/hp.htm?id=31403R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2
A4752CA7F4
E} - C:\WINNT\system32\V36O5H~1
.DLL
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dl
l,NvStartu
p
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroChec
k.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [D211STRT.EXE] "d:\Program Files\Nokia\Nokia D211\D211STRT.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bi
n\jusched.
exe
O4 - HKLM\..\Run: [Control handler] C:\WINNT\system32\dk0puxk8
srthd.exe
O4 - HKCU\..\Run: [Spyware Vanisher] c:\spywarevanisher-free\Fr
eeScanner.
exe -FastScan
O4 - Global Startup: Anti-Virus&Spyware.lnk = C:\Program Files\Anti-Virus&Spyware\A
nti-Virus&
Spyware.ex
e
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RealDownload.lnk.disabled
O4 - Global Startup: winlogin.exe
O4 - Global Startup: WinZip Quick Pick.lnk.disabled
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINNT\system32\msjava.d
ll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINNT\system32\msjava.d
ll
O17 - HKLM\System\CCS\Services\T
cpip\..\{6
22DD145-74
23-4F50-94
8F-0CFADA9
DD9B3}: NameServer = 10.162.21.10,10.162.21.11
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: SearchList =
O17 - HKLM\System\CS1\Services\T
cpip\..\{6
22DD145-74
23-4F50-94
8F-0CFADA9
DD9B3}: NameServer = 10.162.21.10,10.162.21.11
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: SearchList =
O17 - HKLM\System\CS2\Services\T
cpip\..\{6
22DD145-74
23-4F50-94
8F-0CFADA9
DD9B3}: NameServer = 10.162.21.10,10.162.21.11
O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: SearchList =
O18 - Protocol: AxrObjrefStream - {78E7CF7E-D9E0-4122-86E9-E
D40A7C9E4C
8} - C:\Program Files\Actix\Analyzer\Bin\A
xrAccessor
.dll
O20 - AppInit_DLLs: x6cyyzvifbzsi7dll.dll.dll.
dll.dll.dl
l.dll.dll.
dll.dll.dl
l.dll.dll.
dll