| | |
| Thread Tools |
|
05-Aug-2004, 05:40 AM
#1 |
| 'Browser Hijack Attempt' item ( netsearchsoft popup toolbar) Was wondering if anyone would be able to help me get rid of this appalling netsearchsoft popup toolbar.many thanks enclosed is my Logfile of HijackThis v1.98.0 Scan saved at 06:25:31, on 05/08/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Iomega\System32\AppServices.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Iomega\AutoDisk\ADService.exe C:\WINDOWS\system32\fxssvc.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\PROGRA~1\Road Tons Download\kind blah.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\WINDOWS\system32\ps2.exe C:\WINDOWS\System32\pctspk.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe C:\Program Files\Kazaa\kazaa.exe C:\Program Files\Iomega\DriveIcons\ImgIcon.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\CMEII\CMESys.exe C:\program files\altnet\points manager\points manager.exe C:\Program Files\Iomega\AutoDisk\ADUserMon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\GMT\GMT.exe C:\Program Files\hp center\137903\Program\BackWeb-137903.exe C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe C:\Program Files\BTopenworld NetHelp\bin\mpbtn.exe C:\Program Files\PrecisionTime\PrecisionTime.exe C:\Program Files\Psion\PsiWin\Psconsv.exe C:\WINDOWS\System32\P2P Networking\P2P Networking.exe C:\PROGRA~1\Sony Ericsson\Mobile\Connectivity Pack\CONNMN~1.EXE c:\progra~1\mcafee.com\vso\mcvsftsn.exe c:\PROGRA~1\Intuwave Ltd\Shared\mRouterRunTime\mRouterRuntime.exe C:\PROGRA~1\Sony Ericsson\Mobile\Connectivity Pack\CapMan.exe C:\PROGRA~1\Sony Ericsson\Mobile\Connectivity Pack\ElogErr.exe C:\PROGRA~1\Sony Ericsson\Mobile\Connectivity Pack\BROADC~1.EXE C:\PROGRA~1\Sony Ericsson\Mobile\Connectivity Pack\SCRFS.exe C:\PROGRA~1\Sony Ericsson\Mobile\Mobile Phone Monitor\epmworker.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://netsearchsoft.com/searchbar.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://netsearchsoft.com/passthrough...w.hotmail.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://netsearchsoft.com/searchbar.html R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://netsearchsoft.com/searchbar.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: WebHlprObj Class - {1BDD55B8-3985-4E59-B906-5E0AD56D6710} - C:\Documents and Settings\Owner\My Documents\WH5_1843047.dll (file missing) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [MultiFirst] C:\PROGRA~1\Road Tons Download\kind blah.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int339890.exe -auto O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe" O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe O4 - Global Startup: BTopenworld NetHelp for Broadband.lnk = C:\Program Files\BTopenworld NetHelp\bin\matcli.exe O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Phone Connection Monitor.lnk = C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe O4 - Global Startup: PsiWin 2.3 Connection Server.lnk = C:\Program Files\Psion\PsiWin\Psconsv.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: Erotic - {2648BB17-1868-48d3-9A85-7C77F13A2288} - http://www.erotic.co.uk?ref=9999 (file missing) O9 - Extra 'Tools' menuitem: Erotic... - {2648BB17-1868-48d3-9A85-7C77F13A2288} - http://www.erotic.co.uk?ref=9999 (file missing) O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: IQ Test - {D9FA68E1-AEE2-48d8-B03D-C37DC602554E} - http://www.personaltest.co.uk (file missing) O9 - Extra 'Tools' menuitem: IQ Test... - {D9FA68E1-AEE2-48d8-B03D-C37DC602554E} - http://www.personaltest.co.uk (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra button: Homepage - {46D5159D-1057-44B7-8385-50CCE9D11C2C} - http://www.btopenworld.com/default (file missing) (HKCU) O9 - Extra button: Help - {9EF5A8B7-4D40-4AC2-851E-48CB7C37C8D4} - http://www.btopenworld.com/helpbb (file missing) (HKCU) O9 - Extra button: BT - {AC49F9BE-ECFC-4197-93CD-C6F175B0C99D} - http://www.bt.com (file missing) (HKCU) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: Ulster Bank AnyTime - https://anytime2.ulsterbank.com/asp/AnyTime.cab O16 - DPF: {034CC2DC-3245-4B26-B5C7-7B8777739CB7} - http://www.budsinc.com/gamesplaygrou.../fullgames.exe O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) - O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} - http://66.230.146.2/uk/gvx143uts6m_wall.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{D26968E5-DCFF-485C-AE2C-6975950112A5}: NameServer = 194.72.9.39 194.74.65.68 |
05-Aug-2004, 11:59 AM
#2 | ||||||
| I've split your post off from the other thread. We always want individual topics here, rather than "piggybacks". Please follow these instructions and post a new HijackThis Scanlog when done: Download and unzip to a convenient location the CoolWebShredder, CWShredder.exe available here: http://www.computercops.biz/downloads-cat-14.html Then: 1 >> Restart in Safe Mode: http://service1.symantec.com/SUPPORT...01052409420406 2 >> In Safe Mode run the CoolWebShredder and have it "fix" detected problems. Then run HijackThis and check and "fix" the following entries: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://netsearchsoft.com/searchbar.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://netsearchsoft.com/passthroug...ww.hotmail.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://netsearchsoft.com/searchbar.html R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://netsearchsoft.com/searchbar.html O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int339890.exe -auto O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY ^^^ yes Kazaa is a source of these issues and should be fully removed using Kazaabegone; I will give you a like at the bottom. O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe" O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe O9 - Extra button: Erotic - {2648BB17-1868-48d3-9A85-7C77F13A2288} - http://www.erotic.co.uk?ref=9999 (file missing) O9 - Extra 'Tools' menuitem: Erotic... - {2648BB17-1868-48d3-9A85-7C77F13A2288} - http://www.erotic.co.uk?ref=9999 (file missing) 3 >> Delete the following files or folders: C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL >> MYWay Folder C:\Program Files\websx\int339890.exe >> websx Folder C:\Program Files\Common Files\CMEII\CMESys.exe >> CMEII Folder c:\program files\altnet\points manager\points manager.exe >> Altnet Folder C:\Program Files\Common Files\GMT\GMT.exe >> GMT folder Additional cleanup instructions: Go to the Control Panel > Internet Options applet. Clear the Temporary Internet Cache, History and Offline Content. Go to the Programs tab and select "reset web settings", including your home page if it has been altered. You can reset that later to what you desire. 4 >> on rebooting you will need to install, UPDATE, and run a full Ad-aware scan following directions here: Ad-Aware Home Page and Ad-Aware 6: Reference Guide by Winchester73 How Did I Get Infected? {Basic Ad-Aware instructions: 1. Check for Updates. 2. Start > Activate in depth scan. 3. (note: green checks = enabled, it is best to leave defaults unless problems are encountered). 4. Use custom scanning options > Customize > Drives and Folders = Scan within Archives > Memory and Registry = check all. 5. Tweak > Scanning Engine = Unload recognized processes during scanning > Cleaning Engine = let windows remove files in use at next reboot > Proceed > Next. Upon completion > Select All. 6. Reboot} >> Kazaabegone link: http://computercops.biz/downloads-file-331.html >>> Post a new HijackThis scanlog when ready. |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 08:09 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

