1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Cannot solve this homepage hijack-Help

Discussion in 'Virus & Other Malware Removal' started by DanNCG, Sep 21, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. DanNCG

    DanNCG Thread Starter

    Joined:
    Sep 21, 2004
    Messages:
    5
    Hoping anyone can help me. I have tried everything. Spybot does not pick this up, AdAware does but of course it comes back on start up. Xoftspy was also helpful at picking this up. I had McAfee and Norton antivirus on free trail, I have uninstalled both and now running Symantec antivirus 8.0 with a firewall. Symantec has picked up that javapk32.exe is an issue. (?)

    I know some of this is bad and I have had hijack fix portions, but I am missing something because it all comes back on start up. Looking for any input, trying to fix this for months! Let me know if a new logfile is needed

    Here is my log from hijack this:

    Logfile of HijackThis v1.98.1
    Scan saved at 11:22:46 PM, on 8/2/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
    C:\WINDOWS\ntny32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~2\IAMAPP.EXE
    C:\WINDOWS\system32\javapk32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\NetZero\exec.exe
    C:\Program Files\NZSearch\hcm.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\ATRACK.EXE
    C:\Program Files\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\kcflw.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://kcflw.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://kcflw.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\kcflw.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\kcflw.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://kcflw.dll/index.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {24A9B7CC-0A40-BEE6-67C3-A5771F0A62F7} - C:\WINDOWS\system32\atlay32.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [iamapp] C:\PROGRA~1\SYMANT~1\SYMANT~2\IAMAPP.EXE
    O4 - HKLM\..\Run: [javapk32.exe] C:\WINDOWS\system32\javapk32.exe
    O4 - HKLM\..\RunOnce: [syskf32.exe] C:\WINDOWS\syskf32.exe
    O4 - HKLM\..\RunOnce: [d3vz32.exe] C:\WINDOWS\d3vz32.exe
    O4 - HKLM\..\RunOnce: [sdkko32.exe] C:\WINDOWS\sdkko32.exe
    O4 - HKLM\..\RunOnce: [addej.exe] C:\WINDOWS\addej.exe
    O4 - HKLM\..\RunOnce: [mfcow.exe] C:\WINDOWS\mfcow.exe
    O4 - HKLM\..\RunOnce: [atlkp32.exe] C:\WINDOWS\system32\atlkp32.exe
    O4 - HKLM\..\RunOnce: [netsi.exe] C:\WINDOWS\netsi.exe
    O4 - HKLM\..\RunOnce: [sdkim32.exe] C:\WINDOWS\system32\sdkim32.exe
    O4 - HKLM\..\RunOnce: [atlog.exe] C:\WINDOWS\system32\atlog.exe
    O4 - HKLM\..\RunOnce: [winiv.exe] C:\WINDOWS\system32\winiv.exe
    O4 - HKLM\..\RunOnce: [ipyl32.exe] C:\WINDOWS\ipyl32.exe
    O4 - HKLM\..\RunOnce: [iete.exe] C:\WINDOWS\iete.exe
    O4 - HKLM\..\RunOnce: [addmu.exe] C:\WINDOWS\system32\addmu.exe
    O4 - HKLM\..\RunOnce: [ietw.exe] C:\WINDOWS\system32\ietw.exe
    O4 - HKLM\..\RunOnce: [sysur32.exe] C:\WINDOWS\system32\sysur32.exe
    O4 - HKLM\..\RunOnce: [d3fv32.exe] C:\WINDOWS\system32\d3fv32.exe
    O4 - HKLM\..\RunOnce: [netye.exe] C:\WINDOWS\netye.exe
    O4 - HKLM\..\RunOnce: [d3qt32.exe] C:\WINDOWS\d3qt32.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [uoltray] C:\Program Files\NetZero\exec.exe regrun
    O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\hcm.exe" -w
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/share...insctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/share...cgdmgr.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup...mAData.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup...veData.cab
     
  2. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    Welcome to TSG

    Please download About:Buster http://downloads.subratam.org/AboutBuster.zip Created by RubberDucky...and unzip it to your desktop. Start it....1st hit the "Update" button to make sure you have the very latest definition files. hit Ok, Start, And Ok again to start the scan....dont worry if your startpage changes to www.google.com,its neccessary for the program to do this. When finished,it will generate a log.....Post that log along with a new Hijack this log here.

    ;)
     
  3. DanNCG

    DanNCG Thread Starter

    Joined:
    Sep 21, 2004
    Messages:
    5
    Thanks Steve! Here is my log from Buster, followed by my hijack this log:

    canned at: 9:48:46 PM on: 9/21/2004


    -- Scan 1 ---------------------------
    About:Buster Version 3.0
    Reference List : 15


    ADS not scanned System(FAT)
    Removed 5 Random Key Entries
    Deleted 1 Service Keys Successfully!
    Removed! : C:\WINDOWS\houso.dat
    Removed! : C:\WINDOWS\hxyqk.dat
    Removed! : C:\WINDOWS\hxyqkq.dat
    Removed! : C:\WINDOWS\sdkko32.exe
    Removed! : C:\WINDOWS\mseg32.exe
    Removed! : C:\WINDOWS\mfcow.exe
    Removed! : C:\WINDOWS\yepxov.dat
    Removed! : C:\WINDOWS\ntro.exe
    Removed! : C:\WINDOWS\sysxd32.exe
    Removed! : C:\WINDOWS\ieth.exe
    Removed! : C:\WINDOWS\atlkv.exe
    Removed! : C:\WINDOWS\jamwmp.dat
    Removed! : C:\WINDOWS\ipyl32.exe
    Removed! : C:\WINDOWS\iete.exe
    Removed! : C:\WINDOWS\cjtka.dat
    Removed! : C:\WINDOWS\netye.exe
    Removed! : C:\WINDOWS\iejj.exe
    Removed! : C:\WINDOWS\utoqo.dat
    Removed! : C:\WINDOWS\utoqo.dll
    Removed! : C:\WINDOWS\knvfr.dat
    Removed! : C:\WINDOWS\rvljb.dat
    Removed! : C:\WINDOWS\pyauq.dat
    Removed! : C:\WINDOWS\jzuhe.dat
    Removed! : C:\WINDOWS\jxzii.dat
    Removed! : C:\WINDOWS\cftml.dat
    Removed! : C:\WINDOWS\asfsc.dat
    Removed! : C:\WINDOWS\adzvp.dat
    Removed! : C:\WINDOWS\mscq.exe
    Removed! : C:\WINDOWS\mmczd.dat
    Removed! : C:\WINDOWS\addyo32.exe
    Removed! : C:\WINDOWS\winjc32.exe
    Removed! : C:\WINDOWS\kkooh.dat
    Removed! : C:\WINDOWS\bmkou.dat
    Removed! : C:\WINDOWS\yefvo.dat
    Removed! : C:\WINDOWS\fjxaz.dat
    Removed! : C:\WINDOWS\mfcfm32.exe
    Removed! : C:\WINDOWS\anraf.dat
    Removed! : C:\WINDOWS\rpjew.dat
    Removed! : C:\WINDOWS\eusdl.dat
    Removed! : C:\WINDOWS\netcm32.exe
    Removed! : C:\WINDOWS\ntpy32.exe.bak
    Removed! : C:\WINDOWS\kqzcxf.dat
    Removed! : C:\WINDOWS\mpvsys.exe
    Removed! : C:\WINDOWS\mstr.exe
    Removed! : C:\WINDOWS\xsslu.dat
    Removed! : C:\WINDOWS\titsa.dat
    Removed! : C:\WINDOWS\lgyue.dat
    Removed! : C:\WINDOWS\advck.dat
    Removed! : C:\WINDOWS\sgfxf.dat
    Removed! : C:\WINDOWS\swkzj.dat
    Removed! : C:\WINDOWS\iqzcz.dat
    Removed! : C:\WINDOWS\iqzcz.dll
    Removed! : C:\WINDOWS\kdavm.dat
    Removed! : C:\WINDOWS\yrrmn.dat
    Removed! : C:\WINDOWS\ynaqe.dat
    Removed! : C:\WINDOWS\wgldx.dll
    Removed! : C:\WINDOWS\bmwec.dll
    Removed! : C:\WINDOWS\atlnm32.exe
    Removed! : C:\WINDOWS\fgqme.dat
    Removed! : C:\WINDOWS\jngyo.dat
    Removed! : C:\WINDOWS\oukhs.dat
    Removed! : C:\WINDOWS\uvtww.dat
    Removed! : C:\WINDOWS\sqzhl.dat
    Removed! : C:\WINDOWS\dewbi.dat
    Removed! : C:\WINDOWS\eqwftj.dat
    Removed! : C:\WINDOWS\wqolnt.dat
    Removed! : C:\WINDOWS\addox32.exe
    Removed! : C:\WINDOWS\ebqib.dat
    Removed! : C:\WINDOWS\xkamy.dll
    Removed! : C:\WINDOWS\mfctr.exe
    Removed! : C:\WINDOWS\bfwto.dll
    Removed! : C:\WINDOWS\zsygm.dat
    Removed! : C:\WINDOWS\lnpxo.dat
    Removed! : C:\WINDOWS\ooguc.dat
    Removed! : C:\WINDOWS\ceutt.dat
    Removed! : C:\WINDOWS\fddgd.dat
    Removed! : C:\WINDOWS\wqplv.dat
    Removed! : C:\WINDOWS\xkfff.dll
    Removed! : C:\WINDOWS\xtfzq.dat
    Removed! : C:\WINDOWS\ejmng.dll
    Removed! : C:\WINDOWS\zowwm.dat
    Removed! : C:\WINDOWS\nwwml.dat
    Removed! : C:\WINDOWS\ncvmn.dat
    Removed! : C:\WINDOWS\rtjbi.dll
    Removed! : C:\WINDOWS\cxpkk.dat
    Removed! : C:\WINDOWS\godzf.dat
    Removed! : C:\WINDOWS\zrwwa.dll
    Removed! : C:\WINDOWS\qyhgw.dat
    Removed! : C:\WINDOWS\oanrd.dat
    Removed! : C:\WINDOWS\lfcbw.dat
    Removed! : C:\WINDOWS\qqyol.dat
    Removed! : C:\WINDOWS\olrud.dat
    Removed! : C:\WINDOWS\sysis.exe
    Removed! : C:\WINDOWS\jxxub.dat
    Removed! : C:\WINDOWS\notbw.dat
    Removed! : C:\WINDOWS\appiq32.exe
    Removed! : C:\WINDOWS\cjbef.dll
    Removed! : C:\WINDOWS\bltok.dll
    Removed! : C:\WINDOWS\aperp.dat
    Removed! : C:\WINDOWS\aperp.dll
    Removed! : C:\WINDOWS\tqnbt.dat
    Removed! : C:\WINDOWS\pnaqp.dll
    Removed! : C:\WINDOWS\sysid.exe
    Removed! : C:\WINDOWS\adzzc.dat
    Removed! : C:\WINDOWS\rjyhe.dat
    Removed! : C:\WINDOWS\tfwxb.dll
    Removed! : C:\WINDOWS\outby.dat
    Removed! : C:\WINDOWS\ujhbl.dat
    Removed! : C:\WINDOWS\vkezl.dat
    Removed! : C:\WINDOWS\lgqmg.dat
    Removed! : C:\WINDOWS\lgqmg.dll
    Removed! : C:\WINDOWS\zdjgt.dat
    Removed! : C:\WINDOWS\lxkce.dat
    Removed! : C:\WINDOWS\uxlhv.dat
    Removed! : C:\WINDOWS\lxkce.dll
    Removed! : C:\WINDOWS\javaqp.exe
    Removed! : C:\WINDOWS\kanin.dat
    Removed! : C:\WINDOWS\apivl.exe
    Removed! : C:\WINDOWS\kdjcj.dat
    Removed! : C:\WINDOWS\gawqf.dll
    Removed! : C:\WINDOWS\lokpl.dat
    Removed! : C:\WINDOWS\lnorp.dat
    Removed! : C:\WINDOWS\gmxez.dll
    Removed! : C:\WINDOWS\yvwwx.dat
    Removed! : C:\WINDOWS\tzkzl.dat
    Removed! : C:\WINDOWS\addph32.exe
    Removed! : C:\WINDOWS\agklh.dat
    Removed! : C:\WINDOWS\ytery.dat
    Removed! : C:\WINDOWS\wmpes.dll
    Removed! : C:\WINDOWS\plslo.dat
    Removed! : C:\WINDOWS\hpnnv.dat
    Removed! : C:\WINDOWS\dxoeu.dat
    Removed! : C:\WINDOWS\eallc.dat
    Removed! : C:\WINDOWS\eqpmp.dll
    Removed! : C:\WINDOWS\shjlu.dat
    Removed! : C:\WINDOWS\hcmqs.dat
    Removed! : C:\WINDOWS\ypddn.dat
    Removed! : C:\WINDOWS\wrkgd.dat
    Removed! : C:\WINDOWS\fknni.dat
    Removed! : C:\WINDOWS\uyalo.dat
    Removed! : C:\WINDOWS\d3fo.exe
    Removed! : C:\WINDOWS\srsye.dat
    Removed! : C:\WINDOWS\rnnik.dat
    Removed! : C:\WINDOWS\dwyed.dat
    Removed! : C:\WINDOWS\umvtu.dat
    Removed! : C:\WINDOWS\awhpk.dat
    Removed! : C:\WINDOWS\sqihu.dat
    Removed! : C:\WINDOWS\lomzt.dat
    Removed! : C:\WINDOWS\hfagn.dat
    Removed! : C:\WINDOWS\bbyek.dat
    Removed! : C:\WINDOWS\imtqa.dat
    Removed! : C:\WINDOWS\rwowt.dat
    Removed! : C:\WINDOWS\vcqqh.dat
    Removed! : C:\WINDOWS\System32\apizj.exe
    Removed! : C:\WINDOWS\System32\atlkp32.exe
    Removed! : C:\WINDOWS\System32\appmy32.exe
    Removed! : C:\WINDOWS\System32\crxg.exe
    Removed! : C:\WINDOWS\System32\sysby.exe
    Removed! : C:\WINDOWS\System32\sdkim32.exe
    Removed! : C:\WINDOWS\System32\addad.exe
    Removed! : C:\WINDOWS\System32\winlc.exe
    Removed! : C:\WINDOWS\System32\addmu.exe
    Removed! : C:\WINDOWS\System32\mitev.dat
    Removed! : C:\WINDOWS\System32\d3fv32.exe
    Removed! : C:\WINDOWS\System32\ipwx.exe
    Removed! : C:\WINDOWS\System32\atlpo32.exe
    Removed! : C:\WINDOWS\System32\ozlvb.dat
    Removed! : C:\WINDOWS\System32\fanek.dat
    Removed! : C:\WINDOWS\System32\lyrxs.dll
    Removed! : C:\WINDOWS\System32\bsjow.dat
    Removed! : C:\WINDOWS\System32\feczv.dat
    Removed! : C:\WINDOWS\System32\bdnql.dat
    Removed! : C:\WINDOWS\System32\hkztg.dat
    Removed! : C:\WINDOWS\System32\phknk.dat
    Removed! : C:\WINDOWS\System32\gjvyb.dat
    Removed! : C:\WINDOWS\System32\zjukm.dat
    Removed! : C:\WINDOWS\System32\dbjip.dat
    Removed! : C:\WINDOWS\System32\ghojq.dat
    Removed! : C:\WINDOWS\System32\muryi.dat
    Removed! : C:\WINDOWS\System32\fuapi.dat
    Removed! : C:\WINDOWS\System32\bovoh.dat
    Removed! : C:\WINDOWS\System32\atlga32.exe
    Removed! : C:\WINDOWS\System32\nzwwi.dat
    Removed! : C:\WINDOWS\System32\abjcs.dat
    Removed! : C:\WINDOWS\System32\tguvf.dat
    Removed! : C:\WINDOWS\System32\lyrxs.dat
    Removed! : C:\WINDOWS\System32\dsrkf.dat
    Removed! : C:\WINDOWS\System32\zzaxx.dll
    Removed! : C:\WINDOWS\System32\cwjcc.dat
    Removed! : C:\WINDOWS\System32\adzcy.dat
    Removed! : C:\WINDOWS\System32\steek.dat
    Removed! : C:\WINDOWS\System32\ssifp.dat
    Removed! : C:\WINDOWS\System32\qmpje.dll
    Removed! : C:\WINDOWS\System32\gxait.dat
    Removed! : C:\WINDOWS\System32\cpwxo.dll
    Removed! : C:\WINDOWS\System32\rkryw.dat
    Removed! : C:\WINDOWS\System32\twlqx.dat
    Removed! : C:\WINDOWS\System32\pohfs.dll
    Removed! : C:\WINDOWS\System32\cfzpm.dat
    Removed! : C:\WINDOWS\System32\uamqe.dat
    Removed! : C:\WINDOWS\System32\mbfon.dat
    Removed! : C:\WINDOWS\System32\aagdt.dat
    Removed! : C:\WINDOWS\System32\ehpqd.dat
    Removed! : C:\WINDOWS\System32\tzjda.dat
    Removed! : C:\WINDOWS\System32\pqfsv.dll
    Removed! : C:\WINDOWS\System32\wixoj.dll
    Removed! : C:\WINDOWS\System32\geggd.dat
    Removed! : C:\WINDOWS\System32\zesed.dll
    Removed! : C:\WINDOWS\System32\yrtbh.dat
    Removed! : C:\WINDOWS\System32\hggwf.dat
    Removed! : C:\WINDOWS\System32\rlvae.dat
    Removed! : C:\WINDOWS\System32\odonr.dat
    Removed! : C:\WINDOWS\System32\iprot.dat
    Removed! : C:\WINDOWS\System32\ktoeq.dll
    Removed! : C:\WINDOWS\System32\jgzyi.dat
    Removed! : C:\WINDOWS\System32\jzeev.dll
    Removed! : C:\WINDOWS\System32\bfeau.dat
    Removed! : C:\WINDOWS\System32\enobo.dat
    Removed! : C:\WINDOWS\System32\mfcwe32.exe
    Removed! : C:\WINDOWS\System32\cdosn.dat
    Removed! : C:\WINDOWS\System32\lcfjx.dat
    Removed! : C:\WINDOWS\System32\pubyr.dll
    Removed! : C:\WINDOWS\System32\pxpqz.dat
    Removed! : C:\WINDOWS\System32\lwlft.dll
    Removed! : C:\WINDOWS\System32\hxxov.dat
    Removed! : C:\WINDOWS\System32\zeywf.dat
    Removed! : C:\WINDOWS\System32\fnxdi.dll
    Removed! : C:\WINDOWS\System32\knxvz.dat
    Removed! : C:\WINDOWS\System32\iiego.dat
    Removed! : C:\WINDOWS\System32\hdxlg.dat
    Removed! : C:\WINDOWS\System32\azumv.dll
    Removed! : C:\WINDOWS\System32\xtcqo.dat
    Removed! : C:\WINDOWS\System32\xtcqo.dll
    Removed! : C:\WINDOWS\System32\wgmso.dat
    Removed! : C:\WINDOWS\System32\sdhhk.dat
    Removed! : C:\WINDOWS\System32\nbzxk.dat
    Removed! : C:\WINDOWS\System32\zupdn.dat
    Removed! : C:\WINDOWS\System32\mgyxe.dat
    Removed! : C:\WINDOWS\System32\bmeqj.dat
    Removed! : C:\WINDOWS\System32\yglty.dat
    Removed! : C:\WINDOWS\System32\dzspb.dat
    Removed! : C:\WINDOWS\System32\vmfvx.dat
    Removed! : C:\WINDOWS\System32\nxriu.dll
    Removed! : C:\WINDOWS\System32\ztikq.dat
    Removed! : C:\WINDOWS\System32\rjmmv.dll
    Removed! : C:\WINDOWS\System32\knksv.dat
    Removed! : C:\WINDOWS\System32\npibt.dll
    Removed! : C:\WINDOWS\System32\kefzb.dat
    Removed! : C:\WINDOWS\System32\pbend.dat
    Removed! : C:\WINDOWS\System32\noqbv.dat
    Removed! : C:\WINDOWS\System32\iqvha.dat
    Removed! : C:\WINDOWS\System32\exduk.dat
    Removed! : C:\WINDOWS\System32\zwcto.dll
    Removed! : C:\WINDOWS\System32\qffoi.dat
    Removed! : C:\WINDOWS\System32\wnkxq.dat
    Removed! : C:\WINDOWS\System32\jxzom.dat
    Removed! : C:\WINDOWS\System32\jzikj.dat
    Removed! : C:\WINDOWS\System32\fwvzx.dat
    Removed! : C:\WINDOWS\System32\gwste.dat
    Removed! : C:\WINDOWS\System32\lnniz.dat
    Removed! : C:\WINDOWS\System32\vvmdc.dat
    Removed! : C:\WINDOWS\System32\rudqm.dat
    Removed! : C:\WINDOWS\System32\auxrg.dat
    Removed! : C:\WINDOWS\System32\edycc.dat
    Removed! : C:\WINDOWS\System32\rwwcr.dat
    Removed! : C:\WINDOWS\System32\pydng.dat
    Removed! : C:\WINDOWS\System32\zcgpm.dat
    Removed! : C:\WINDOWS\System32\udobd.dat
    Removed! : C:\WINDOWS\System32\xkfon.dat
    Removed! : C:\WINDOWS\System32\mfcdg.exe
    Attempted Clean Of Temp folder.
    Removed Uninstall Key (HSA)
    Removed Uninstall Key (SE)
    Removed Uninstall Key (SW)
    Pages Reset... Done!

    HIJACK THIS:[/B]

    Logfile of HijackThis v1.98.2
    Scan saved at 9:50:25 PM, on 9/21/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINDOWS\apisi32.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~2\IAMAPP.EXE
    C:\WINDOWS\system32\syskk32.exe
    C:\Program Files\NetZero\exec.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\ATRACK.EXE
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\boogy.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\boogy.dll/sp.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\boogy.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\boogy.dll/sp.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {88C5C2FB-75B8-C8BB-D572-EE7460D7AA2D} - C:\WINDOWS\netpf.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [iamapp] C:\PROGRA~1\SYMANT~1\SYMANT~2\IAMAPP.EXE
    O4 - HKLM\..\Run: [javapk32.exe] C:\WINDOWS\system32\javapk32.exe
    O4 - HKLM\..\Run: [syskk32.exe] C:\WINDOWS\system32\syskk32.exe
    O4 - HKLM\..\Run: [nthw32.exe] C:\WINDOWS\system32\nthw32.exe
    O4 - HKLM\..\Run: [sdkwv.exe] C:\WINDOWS\system32\sdkwv.exe
    O4 - HKLM\..\Run: [msna32.exe] C:\WINDOWS\system32\msna32.exe
    O4 - HKLM\..\Run: [sysde32.exe] C:\WINDOWS\system32\sysde32.exe
    O4 - HKLM\..\Run: [ipjj.exe] C:\WINDOWS\system32\ipjj.exe
    O4 - HKLM\..\Run: [crnr32.exe] C:\WINDOWS\system32\crnr32.exe
    O4 - HKLM\..\Run: [sysbh.exe] C:\WINDOWS\system32\sysbh.exe
    O4 - HKLM\..\Run: [sysek.exe] C:\WINDOWS\system32\sysek.exe
    O4 - HKLM\..\RunOnce: [syskf32.exe] C:\WINDOWS\syskf32.exe
    O4 - HKLM\..\RunOnce: [d3qt32.exe] C:\WINDOWS\d3qt32.exe
    O4 - HKLM\..\RunOnce: [winiv.exe] C:\WINDOWS\system32\winiv.exe
    O4 - HKLM\..\RunOnce: [ietw.exe] C:\WINDOWS\system32\ietw.exe
    O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\hcm.exe" -w
    O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
     
  4. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    Cntrl-Alt-Delete and end process on:syskk32.exe
    Repeat above steps for: C:\WINDOWS\System32\apisi32.exe
    ================================================
    Run hijackthis again and put a checkmark against these entries....double check
    in case you miss anything....
    .....then,close all browser and outlook windows including this one and "fix checked"

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\boogy.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\boogy.dll/sp.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\boogy.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\boogy.dll/sp.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {88C5C2FB-75B8-C8BB-D572-EE7460D7AA2D} - C:\WINDOWS\netpf.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [iamapp] C:\PROGRA~1\SYMANT~1\SYMANT~2\IAMAPP.EXE
    O4 - HKLM\..\Run: [javapk32.exe] C:\WINDOWS\system32\javapk32.exe
    O4 - HKLM\..\Run: [syskk32.exe] C:\WINDOWS\system32\syskk32.exe
    O4 - HKLM\..\Run: [nthw32.exe] C:\WINDOWS\system32\nthw32.exe
    O4 - HKLM\..\Run: [sdkwv.exe] C:\WINDOWS\system32\sdkwv.exe
    O4 - HKLM\..\Run: [msna32.exe] C:\WINDOWS\system32\msna32.exe
    O4 - HKLM\..\Run: [sysde32.exe] C:\WINDOWS\system32\sysde32.exe
    O4 - HKLM\..\Run: [ipjj.exe] C:\WINDOWS\system32\ipjj.exe
    O4 - HKLM\..\Run: [crnr32.exe] C:\WINDOWS\system32\crnr32.exe
    O4 - HKLM\..\Run: [sysbh.exe] C:\WINDOWS\system32\sysbh.exe
    O4 - HKLM\..\Run: [sysek.exe] C:\WINDOWS\system32\sysek.exe
    O4 - HKLM\..\RunOnce: [syskf32.exe] C:\WINDOWS\syskf32.exe
    O4 - HKLM\..\RunOnce: [d3qt32.exe] C:\WINDOWS\d3qt32.exe
    O4 - HKLM\..\RunOnce: [winiv.exe] C:\WINDOWS\system32\winiv.exe
    O4 - HKLM\..\RunOnce: [ietw.exe] C:\WINDOWS\system32\ietw.exe


    Go to Start > run, enter cmd

    At the prompt copy/paste the Bolded text:

    del C:\WINDOWS\system32\syskk32.exe


    Press enter.
    [Note the space between del and C:]

    Repeat above steps for: C:\WINDOWS\System32\apisi32.exe
    You need to delete both files quickly...one after the other,thats why the copy/paste.
    ==============================
    Run About-Buster once more and see if it finds anything else.
    ==============================
    Empty the Recycle Bin.

    Open internet Explorer Click on "Tools">"Internet Options">And delete temp internet files.
    And clean out your %Userprofile%\Local Settings\Temp
    folder. [It's a good idea to do that regularly.]
    ==============================
    Go to Internet Options>Programs
    Click the "Reset Web Settings" Button to reset your prefered home and search pages.
    ==============================
    Turn off System Restore:

    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.
    Restart your computer and post a follow up HijackThis log.

    When you are sure you are clean turn it back on and create a restore point.

    ;)
     
  5. DanNCG

    DanNCG Thread Starter

    Joined:
    Sep 21, 2004
    Messages:
    5
    Steve, getting there, but I must be missing something. Still have the homepage hijack redirect when I open Microsoft Internet Explorer

    Here is my About-Buster that I ran as you stated in reply and what it found:

    Scanned at: 12:47:14 AM on: 9/23/2004


    -- Scan 1 ---------------------------
    About:Buster Version 3.0
    Reference List : 15


    ADS not scanned System(FAT)
    Removed 10 Random Key Entries
    Deleted 2 Service Keys Successfully!
    Removed! : C:\WINDOWS\cdpxr.dat
    Removed! : C:\WINDOWS\System32\jsmrm.dat
    Removed! : C:\WINDOWS\System32\ippu32.exe
    Removed! : C:\WINDOWS\System32\mnfnp.dat
    Removed! : C:\WINDOWS\System32\dtwvj.dat
    Removed! : C:\WINDOWS\System32\eqdsa.dat
    Removed! : C:\WINDOWS\System32\lkkrs.dat
    Removed! : C:\WINDOWS\System32\jnrcz.dat
    Removed! : C:\WINDOWS\System32\phxfo.dat
    Removed! : C:\WINDOWS\System32\mfctp32.exe
    Attempted Clean Of Temp folder.
    Removed Uninstall Key (HSA)
    Removed Uninstall Key (SE)
    Removed Uninstall Key (SW)
    Pages Reset... Done!

    This is About-Buster after restart:

    Scanned at: 1:16:55 AM on: 9/23/2004


    -- Scan 1 ---------------------------
    About:Buster Version 3.0
    Reference List : 15


    ADS not scanned System(FAT)
    Removed 9 Random Key Entries
    Deleted 1 Service Keys Successfully!
    Attempted Clean Of Temp folder.
    Removed Uninstall Key (HSA)
    Removed Uninstall Key (SE)
    Removed Uninstall Key (SW)
    Pages Reset... Done!

    And here is Hijack This after reboot:

    Logfile of HijackThis v1.98.2
    Scan saved at 1:25:12 AM, on 9/23/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
    C:\WINDOWS\system32\javapk32.exe
    C:\Program Files\NZSearch\hcm.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\WINDOWS\d3qt32.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {B877A895-E66D-9B51-2A5E-B2821E0C16B0} - C:\WINDOWS\atlsl32.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
    O4 - HKLM\..\Run: [javapk32.exe] C:\WINDOWS\system32\javapk32.exe
    O4 - HKLM\..\RunOnce: [ccjgxy.dat] C:\WINDOWS\ccjgxy.dat
    O4 - HKLM\..\RunOnce: [d3qt32.exe] C:\WINDOWS\d3qt32.exe
    O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\hcm.exe" -w
    O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
     
  6. DanNCG

    DanNCG Thread Starter

    Joined:
    Sep 21, 2004
    Messages:
    5
    Steve - Here is what Hijack This picks up after I have gone on the internet:

    I was also unable to Cntrl-Alt-Delete as you stated:

    Cntrl-Alt-Delete and end process on:syskk32.exe
    Repeat above steps for: C:\WINDOWS\System32\apisi32.exe

    I did not have syskk32.exe as a running process, and could not see C:\WINDOWS\System32\apisi32.exe as a running process...is this a file that needs to be deleted from my C drive?


    Logfile of HijackThis v1.98.2
    Scan saved at 1:39:25 AM, on 9/23/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
    C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
    C:\WINDOWS\system32\javapk32.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\WINDOWS\d3qt32.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\NetZero\exec.exe
    C:\Program Files\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\hrovs.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://hrovs.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://hrovs.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\hrovs.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\hrovs.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://hrovs.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {B877A895-E66D-9B51-2A5E-B2821E0C16B0} - C:\WINDOWS\atlsl32.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
    O4 - HKLM\..\Run: [javapk32.exe] C:\WINDOWS\system32\javapk32.exe
    O4 - HKLM\..\RunOnce: [ccjgxy.dat] C:\WINDOWS\ccjgxy.dat
    O4 - HKLM\..\RunOnce: [d3qt32.exe] C:\WINDOWS\d3qt32.exe
    O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\hcm.exe" -w
    O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
     
  7. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    114,960
    Please do this. Click here http://forums.techguy.org/attachment.php?attachmentid=38105 to download getservice.zip and unzip it to your desktop. Open the Getservice folder and click on the getservice.bat file. A notepad will open up with a long list of services. Please save that notepad file and attach it to your next reply to this thread. It will be easier to attach it rather than copy and paste because it will be too long to paste in one post.

    After you post the next Hijack This log and the getservice list, it is very important that you do not restart your computer or attempt to do anything to remove this until I have posted the removal directions because the files and the entries in HJT will change and we will have to start all over again. It would be best that you do nothing at all with the computer until you get the directions.
     
  8. DanNCG

    DanNCG Thread Starter

    Joined:
    Sep 21, 2004
    Messages:
    5
    Cookie,

    Thanks for the response. I ended up working with a co-worker and we finally solved my homepage hijack. Dan
     
  9. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    114,960
    No problem. :)
     
  10. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/276430

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice