Hello All
My browser is hacked. when ever I open IE its connecting to some search Engine like
www.coolsearch.com etc etc....
And in Task Manager simultaneously various sites are getting opened and making system process very slow.
I run a anti virus software called HiJackeThis. It shows the following report at the end
Cud u pls tell me what are the files I have to delete i.e unimportant
**********************
Logfile of HijackThis v1.97.7
Scan saved at 1:43:57 AM, on 3/15/2001
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.ex
e
C:\WINNT\system32\winlogon
.exe
C:\WINNT\system32\services
.exe
C:\WINNT\system32\lsass.ex
e
C:\WINNT\system32\svchost.
exe
C:\WINNT\system32\spoolsv.
exe
C:\WINNT\System32\msdtc.ex
e
C:\WINNT\System32\svchost.
exe
C:\WINNT\System32\llssrv.e
xe
C:\WINNT\system32\regsvc.e
xe
C:\WINNT\system32\MSTask.e
xe
C:\WINNT\System32\inetsrv\
inetinfo.e
xe
C:\WINNT\system32\Dfssvc.e
xe
C:\WINNT\System32\taskmgr.
exe
C:\WINNT\Explorer.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\Trojan Remover\Trjscan.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\npbgbw.e
xe
C:\Program Files\WindUpdates\WinUpdt.
exe
C:\Program Files\a2\a2guard.exe
C:\WINNT\System32\services
\msxmidi.e
xe
C:\Documents and Settings\Administrator\App
lication Data\lrtd.exe
C:\Program Files\WindUpdates\WinKA.ex
e
C:\WINNT\System32\svchost.
exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.ex
e
C:\ToolsDownloads\HijackTh
is.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer,SearchURL =
http://mega.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://mega.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://mega.directwebsearch.net/search.phpR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://mega.directwebsearch.net/index.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = C:\WINNT\secure.html
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://mega.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://mega.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://mega.directwebsearch.net/search.phpR1 - HKLM\Software\Microsoft\In
ternet Explorer,SearchURL =
http://mega.directwebsearch.net/search.phpR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://mega.directwebsearch.net/index.phpR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://mega.directwebsearch.net/search.phpR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://mega.directwebsearch.net/search.phpR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = C:\WINNT\secure.html
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://mega.directwebsearch.net/search.phpR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://mega.directwebsearch.net/search.phpR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://mega.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) = about:blank
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\WINNT\secure.html
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\WINNT\secure.html
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Explorer,Search =
http://mega.directwebsearch.net/search.phpR1 - HKLM\Software\Microsoft\In
ternet Explorer,Search =
http://mega.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,SearchAssist
ant = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,SearchAssist
ant = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Search,(Default) = about:blank
F1 - win.ini: run=C:\WINNT\System32\serv
ices\msxmi
di.exe
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4
A4827C2E4C
8} - C:\WINNT\nem219.dll (file missing)
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-D
D56626C6C4
2} - C:\WINNT\twaintec.dll
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-0
3CA8155F0B
3} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-0
0E04C60FAF
2} - C:\WINNT\2_0_1browserhelpe
r2.dll
O2 - BHO: (no name) - {A3FDD654-A057-4971-9844-4
ED8E67DBBB
8} - C:\Program Files\SideFind\sfbho.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [winupd] C:\WINNT\System32\winupd.e
xe
O4 - HKLM\..\Run: [hgxwteamrmasq] C:\WINNT\System32\npbgbw.e
xe
O4 - HKLM\..\Run: [WindUpdates] C:\Program Files\WindUpdates\WinUpdt.
exe
O4 - HKLM\..\Run: [xpsystem] C:\WINNT\System32\services
\msxmidi.e
xe
O4 - HKCU\..\Run: [IridiumTimeWizard] C:\\iridium.exe
O4 - HKCU\..\Run: [a²] "C:\Program Files\a2\a2guard.exe"
O4 - HKCU\..\Run: [Rbrt] C:\Documents and Settings\Administrator\App
lication Data\lrtd.exe
O4 - HKCU\..\Run: [xpsystem] C:\WINNT\System32\services
\msxmidi.e
xe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: 24Online Client.lnk = C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.ex
e
O8 - Extra context menu item: Shorten URL -
http://www.cjb.net/menuext.htmlO9 - Extra button: SideFind (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O13 - DefaultPrefix:
O13 - WWW Prefix:
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D
3488ABDDC6
B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {11010101-1001-1111-1000-1
1011234567
8} - ms-its:mhtml:file://c:\nos
uch.mht!
http://69.50.173.252/bonus.chm::/winpromo.exeO16 - DPF: {11111111-1111-1111-1111-1
1111111115
7} - ms-its:mhtml:file://c:\nos
uch.mht!
http://super-gals.com/scj/rotation/templates/s/x.chm::/ad.exeO16 - DPF: {11111111-1111-1111-1111-1
1111111117
1} - ms-its:mhtml:file://c:\\no
such.mht!
http://line-plus.com/newhelp.chm::/newhelp.exeO16 - DPF: {11120607-1001-1111-1000-1
1019990112
3} - ms-its:mhtml:file://c:\nos
uch.mht!
http://www.2awm.com/file/colinwork.chm::/on-line.exeO16 - DPF: {15AD4789-CDB4-47E1-A9DA-9
92EE8E6BAD
6} -
http://public.windupdates.com/get_file.php?bt=ie&p=0c8af29cad1529a0c2f12262efe492244d317f6ab2c86bff7585b7e883263ddf35912dd813dee463c744961d2b31add589650eef4d876c0fc2a2f745d64562:c31e3730b38c174130e1e2729109a237O16 - DPF: {706F3805-27D7-478D-80E5-E
25D2BB030B
3} (VacPro.internazionale_ver
3) -
http://www.advnt01.com/dialer/internazionale_ver3.CABO16 - DPF: {9EB320CE-BE1D-4304-A081-4
B4665414BE
F} -
http://www.mt-download.com/MediaTicketsInstaller.cabO16 - DPF: {A17E30C4-A9BA-11D4-8673-6
0DB54C1000
0} (YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dllO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{B
D03053B-1C
A0-4B10-B5
F8-EF22998
23390}: NameServer = 172.20.0.1