| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 56990 | 2005-04-20 07:20:00 | IWantU.com | NZHawk (4093) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 347011 | 2005-04-20 07:20:00 | each time I go on the Internet with this computer I will browse using Internet Explorer and another Internet Explorer browser page will open to IWantU.com stating that your search was successful here are your results. I have run spyware programs, have a firewall & Norton Anti-Virus 2002. Windows XP Home. I searched the registy for iwantu came up with nothing. Suggestions on how to remove this or why it shows up? |
NZHawk (4093) | ||
| 347012 | 2005-04-20 07:26:00 | Download and install HijackThis from here: www.download.com Copy and paste the log that it generates back here, and it will allow us to look at the problem. |
godfather (25) | ||
| 347013 | 2005-04-20 07:35:00 | Thank you. Here is the report from HiJackThis: Logfile of HijackThis v1.99.1 Scan saved at 6:28:25 p.m., on 20/04/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Microsoft Works\WksSb.exe C:\Program Files\Microsoft Works\WkDetect.exe C:\WINDOWS\Mixer.exe C:\Program Files\Ahead\InCD\InCD.exe C:\PROGRA~1\NORTON~1\navapw32.exe C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\FinePixViewer\QuickDCF.exe C:\Documents and Settings\Des Gyde\Desktop\Hijack This\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = targetclicks.net R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.xtra.co.nz R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.xtra.co.nz/home R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.xtra.co.nz R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.xtra.co.nz R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.xtra.co.nz R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.co.nz R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.co.nz R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.co.nz R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = www.google.co.nz R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://google.co.nz R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R3 - URLSearchHook: (no name) - {E46253DE-5912-4F36-BB30-861A1C47F66F} - (no file) O2 - BHO: (no name) - {8BF5DA64-8EE8-4F7A-9A80-F84F45910533} - (no file) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [cmon14] slamm.exe O4 - HKCU\..\Run: [bhoserv] systemdll.exe O4 - HKCU\..\Run: [qwe] media64.exe O4 - Global Startup: Exif Launcher.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O15 - Trusted Zone: http://*.63.219.181.7 O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe |
NZHawk (4093) | ||
| 347014 | 2005-04-20 07:53:00 | Remove these for a start . R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = . net/srch . php?qq=%s" target="_blank">targetclicks . net R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R3 - URLSearchHook: (no name) - {E46253DE-5912-4F36-BB30-861A1C47F66F} - (no file) O2 - BHO: (no name) - {8BF5DA64-8EE8-4F7A-9A80-F84F45910533} - (no file) O4 - HKCU\ . . \Run: [cmon14] slamm . exe O4 - Global Startup: Exif Launcher . lnk = ? O15 - Trusted Zone: http://* . 63 . 219 . 181 . 7 |
pctek (84) | ||
| 347015 | 2005-04-20 07:57:00 | Bunch of nasty stuff there, including trojans and keyloggers. Have HJT fix these. R3 - URLSearchHook: (no name) - {E46253DE-5912-4F36-BB30-861A1C47F66F} - (no file) O2 - BHO: (no name) - {8BF5DA64-8EE8-4F7A-9A80-F84F45910533} - (no file) O4 - HKCU\..\Run: [cmon14] slamm.exe O4 - HKCU\..\Run: [bhoserv] systemdll.exe O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll Also unless you recognise where this has come from, deal to it as well: O4 - HKCU\..\Run: [qwe] media64.exe Boot in safe mode and delete the file C:\WINDOWS\System32\vbsys2.dll Then reboot and post a new log. |
godfather (25) | ||
| 347016 | 2005-04-20 08:10:00 | Done, although O15 - Trusted Zone: http://*.63.219.181.7 would not be removed. |
NZHawk (4093) | ||
| 347017 | 2005-04-20 08:40:00 | Thank you, again. Before I continue with the log, when I went to Start, Search, For Files or Folders the search windows was incomplete, no heading, the panels were there but no writing or menu's. I am inclined that I should reformat. Opinion please. Here is the HJT log requested: Logfile of HijackThis v1.99.1 Scan saved at 7:30:26 p.m., on 20/04/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Microsoft Works\WksSb.exe C:\Program Files\Microsoft Works\WkDetect.exe C:\WINDOWS\Mixer.exe C:\Program Files\Ahead\InCD\InCD.exe C:\PROGRA~1\NORTON~1\navapw32.exe C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Des Gyde\Desktop\Hijack This\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.xtra.co.nz R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.xtra.co.nz/home R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.xtra.co.nz R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.xtra.co.nz R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.xtra.co.nz R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.co.nz R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.co.nz R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.co.nz R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = www.google.co.nz R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://google.co.nz O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O15 - Trusted Zone: http://*.63.219.181.7 O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe I sincerely appreciate your help, but I need to call it a night. My children await. Please post your reply and I will get to it tomorrow or Friday New Zealand time. Cheers. |
NZHawk (4093) | ||
| 347018 | 2005-04-20 09:29:00 | Well I quite like reformats - clears all the accumulated clutter out as well. | pctek (84) | ||
| 347019 | 2005-04-22 02:07:00 | I have decided to repair windows 1st then if needed reform. Thank you to everyone for their assistance. |
NZHawk (4093) | ||
| 347020 | 2005-04-22 07:30:00 | install SP2 while your at it | Prescott (11) | ||
| 1 | |||||