Forum Home
Press F1
 
Thread ID: 56990 2005-04-20 07:20:00 IWantU.com NZHawk (4093) Press F1
Post ID Timestamp Content User
347011 2005-04-20 07:20:00 each time I go on the Internet with this computer
I will browse using Internet Explorer and another Internet Explorer browser page will open to IWantU.com stating that your search was successful here are your results.
I have run spyware programs, have a firewall & Norton Anti-Virus 2002.
Windows XP Home.
I searched the registy for iwantu came up with nothing.

Suggestions on how to remove this or why it shows up?
NZHawk (4093)
347012 2005-04-20 07:26:00 Download and install HijackThis from here:
www.download.com

Copy and paste the log that it generates back here, and it will allow us to look at the problem.
godfather (25)
347013 2005-04-20 07:35:00 Thank you.
Here is the report from HiJackThis:
Logfile of HijackThis v1.99.1
Scan saved at 6:28:25 p.m., on 20/04/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\Microsoft Works\WkDetect.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Documents and Settings\Des Gyde\Desktop\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = targetclicks.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.xtra.co.nz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.xtra.co.nz/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.xtra.co.nz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.xtra.co.nz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.xtra.co.nz
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.co.nz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.co.nz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.co.nz
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = www.google.co.nz
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://google.co.nz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: (no name) - {E46253DE-5912-4F36-BB30-861A1C47F66F} - (no file)
O2 - BHO: (no name) - {8BF5DA64-8EE8-4F7A-9A80-F84F45910533} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [cmon14] slamm.exe
O4 - HKCU\..\Run: [bhoserv] systemdll.exe
O4 - HKCU\..\Run: [qwe] media64.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://*.63.219.181.7
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
NZHawk (4093)
347014 2005-04-20 07:53:00 Remove these for a start .



R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) =

. net/srch . php?qq=%s" target="_blank">targetclicks . net

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: (no name) - {E46253DE-5912-4F36-BB30-861A1C47F66F} - (no file)
O2 - BHO: (no name) - {8BF5DA64-8EE8-4F7A-9A80-F84F45910533} - (no file)



O4 - HKCU\ . . \Run: [cmon14] slamm . exe

O4 - Global Startup: Exif Launcher . lnk = ?

O15 - Trusted Zone: http://* . 63 . 219 . 181 . 7
pctek (84)
347015 2005-04-20 07:57:00 Bunch of nasty stuff there, including trojans and keyloggers.

Have HJT fix these.
R3 - URLSearchHook: (no name) - {E46253DE-5912-4F36-BB30-861A1C47F66F} - (no file)
O2 - BHO: (no name) - {8BF5DA64-8EE8-4F7A-9A80-F84F45910533} - (no file)

O4 - HKCU\..\Run: [cmon14] slamm.exe
O4 - HKCU\..\Run: [bhoserv] systemdll.exe

O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll

Also unless you recognise where this has come from, deal to it as well:

O4 - HKCU\..\Run: [qwe] media64.exe

Boot in safe mode and delete the file C:\WINDOWS\System32\vbsys2.dll

Then reboot and post a new log.
godfather (25)
347016 2005-04-20 08:10:00 Done,
although
O15 - Trusted Zone: http://*.63.219.181.7
would not be removed.
NZHawk (4093)
347017 2005-04-20 08:40:00 Thank you, again.
Before I continue with the log,
when I went to Start, Search, For Files or Folders
the search windows was incomplete, no heading, the panels were there but no writing or menu's.
I am inclined that I should reformat.
Opinion please.

Here is the HJT log requested:
Logfile of HijackThis v1.99.1
Scan saved at 7:30:26 p.m., on 20/04/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\Microsoft Works\WkDetect.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Des Gyde\Desktop\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.xtra.co.nz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.xtra.co.nz/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.xtra.co.nz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.xtra.co.nz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.xtra.co.nz
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.co.nz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.co.nz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.co.nz
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = www.google.co.nz
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://google.co.nz
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://*.63.219.181.7
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


I sincerely appreciate your help, but I need to call it a night.
My children await. Please post your reply and I will get to it tomorrow or Friday New Zealand time.

Cheers.
NZHawk (4093)
347018 2005-04-20 09:29:00 Well I quite like reformats - clears all the accumulated clutter out as well. pctek (84)
347019 2005-04-22 02:07:00 I have decided to repair windows 1st then if needed reform.

Thank you to everyone for their assistance.
NZHawk (4093)
347020 2005-04-22 07:30:00 install SP2 while your at it Prescott (11)
1