Dark Knight Posted November 16, 2003 Report Share Posted November 16, 2003 i got your message and i dl'ed spybot blaster it helped out alot unfortunately it did not fix my idgsearch homepage problem they are still robbing my homepage at the whim of whatever command they have slid into my pc!If someone could tell me how the idea of posting my findings from the program("hijack this") will help... Quote Link to comment Share on other sites More sharing options...
Boris Posted November 16, 2003 Report Share Posted November 16, 2003 Have a look here about Hijack This :-http://mjc1.com/mirror/hjt/It tells you how to run it and then copy/paste your findings into a post here so we can help. Quote Link to comment Share on other sites More sharing options...
Dark Knight Posted November 16, 2003 Author Report Share Posted November 16, 2003 Logfile of HijackThis v1.97.6Scan saved at 4:42:17 PM, on 11/16/2003Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\DRIVERS\CDANTSRV.EXEC:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exeC:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\hkcmd.exeC:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exeC:\Program Files\BroadJump\Client Foundation\CFD.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Documents and Settings\rperkins.HENRYCO\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iecR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iecR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.htmlR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: Microsoft SearchWord - {79369D5C-2903-4b7a-ADE2-D5E0DEE14D24} - C:\Documents and Settings\rperkins.HENRYCO\Application Data\SearchWord.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exeO4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exeO4 - HKLM\..\Run: [bJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exeO8 - Extra context menu item: Stop popups from this web page - C:\Program Files\GIANT Company Software inc\PopUp Inspector\denysite.htmO12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dllO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO14 - IERESET.INF: START_PAGE_URL=http://www.rr.comO15 - Trusted Zone: *.xxxtoolbar.comO16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.uniden.com/CFIDE/classes/CFJava.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cabO16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://66.48.68.135/save/makeover.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/288bea81350e259e4c05/...ip/RdxIE601.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7880.7214351852O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_In...ller/dwnldr.cabO16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.dotphoto.com/XUpload.ocxO16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/crack.CABO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = henryco.wanO17 - HKLM\Software\..\Telephony: DomainName = henryco.wanO17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = henryco.wanO17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = henryco.wan Quote Link to comment Share on other sites More sharing options...
Guest ellas Posted November 16, 2003 Report Share Posted November 16, 2003 have you had kazaa on if so hijacker is the registry kazaagold + kazaalite, delete them then problem solved Quote Link to comment Share on other sites More sharing options...
Dark Knight Posted November 16, 2003 Author Report Share Posted November 16, 2003 I saw several entries from idgsearchi was tempted to just remove them myself but i was concerned that i screw something up and also i saw another entry there that said xxx toolbar now granted i am a man who has been known to visit Dirty sites i do not ever ever ever install anything on my pc from them so i am 100% sure that this is not supposed to be in there also... :lol: Quote Link to comment Share on other sites More sharing options...
Dark Knight Posted November 16, 2003 Author Report Share Posted November 16, 2003 and yes i have i have had Kazaa which i removed but i never had the problem of my hompage being robbed i only uninstalled because i removed some adware and it stopped working so i dl'ed the newer version knowing that since one of the first versions that i had installed on my pc. i was sure the had improved their spyware cuz the old stuff i was able to turn off and the program worked fine but when i got ad aware i removed the wrong spyware and kazaa stopped working and then i had to dl the new version and bam *hijack* i have since removed the program as far as i know and i use kazalite k ++ but the problem persists.. i will try what you were just mentioning... Quote Link to comment Share on other sites More sharing options...
Boris Posted November 16, 2003 Report Share Posted November 16, 2003 Try this ?Run Hijack This again.Tick the boxes next to all these, then close all browser and explorer windows, and tell HijackThis to "Fix checked". R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iecR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iecR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/Reboot your computer after this Quote Link to comment Share on other sites More sharing options...
Boris Posted November 16, 2003 Report Share Posted November 16, 2003 You may have to zap this one as well ?O2 - BHO: Microsoft SearchWord - {79369D5C-2903-4b7a-ADE2-D5E0DEE14D24} - C:\Documents and Settings\rperkins.HENRYCO\Application Data\SearchWord.dll Quote Link to comment Share on other sites More sharing options...
Boris Posted November 16, 2003 Report Share Posted November 16, 2003 In the same vein - if you ever get CoolWebSearch hijacking you - use this :- http://www.spychecker.com/program/cwshredder.htmlCoolWebShredder will find and destroy all traces of CoolWebSearch on your system. This includes redirections or hijacking to www.coolwwwsearch.com and coolwebsearch.com, youfindall.net and white-pages.ws. If you find that your browser is sending you to these sites all of a sudden, this little program will take care of it Quote Link to comment Share on other sites More sharing options...
Dark Knight Posted November 16, 2003 Author Report Share Posted November 16, 2003 Thank you Boris i am trying these methods as you are reading probably..I will only know when and if my page is hijacked as i said in my very first post here is was not an all the time thing just kinda random like which made it that much more annoying.. Quote Link to comment Share on other sites More sharing options...
mark2 Posted November 17, 2003 Report Share Posted November 17, 2003 Also put a check mark next to these, close all browser windows and get HT to fix themO4 - HKLM\..\Run: [bJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exeO16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/crack.CABO16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://66.48.68.135/save/makeover.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/288bea81350e259e4c05/...ip/RdxIE601.cabNot sure why this is in the trusted zoneO15 - Trusted Zone: *.xxxtoolbar.com if you don't know either get HT to fix it too.once all done post another log so we can check it over once moreAlso get spywareblaster from http://www.javacoolsoftware.com/spywareblaster.html and install it, update regularly and it will prevent a lot of these nasties.BTW I don't see any firewall running ? Quote Link to comment Share on other sites More sharing options...
-pops- Posted November 17, 2003 Report Share Posted November 17, 2003 Don't know if this is relevant but I protect my homepage using Startpage Guard http://www.webattack.com/get/startpageguard.shtmlI also use Spybot S&D, Ad-aware, Spywareblaster, Spywareguard and Agnitum firewall.They're all free!!!!!! :rolleyes: Quote Link to comment Share on other sites More sharing options...
Guest Grim Reaper Posted November 17, 2003 Report Share Posted November 17, 2003 Don't know if this is relevant but I protect my homepage using Startpage Guard http://www.webattack.com/get/startpageguard.shtmlI also use Spybot S&D, Ad-aware, Spywareblaster, Spywareguard and Agnitum firewall.They're all free!!!!!! :rolleyes:pops, perhaps we could find you another spyware program to use, you look like you are running a little short of them!! :D Quote Link to comment Share on other sites More sharing options...
Boris Posted November 17, 2003 Report Share Posted November 17, 2003 Glad the expert helped out mark2 - I thought that O4 - HKLM\..\Run: [bJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exeO16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/crack.CABO16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://66.48.68.135/save/makeover.cabshould probably all go as well - but wasn't confident enough :unsure: to give a definite answer ! Quote Link to comment Share on other sites More sharing options...
mark2 Posted November 17, 2003 Report Share Posted November 17, 2003 Boris, no expert here, but I do recall seeing them before elsewhere and recommendation was KILL 'EM.Been googling and this O15 - Trusted Zone: *.xxxtoolbar.com if you don't know either get HT to fix it too. should go. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.