Jump to content

Hijack this log


goehring
 Share

Recommended Posts

Hi guys!

I become crazy with this idgsearch! Please help me to remove this rubbish!

thx a lot

Logfile of HijackThis v1.97.7

Scan saved at 18:45:52, on 02.12.2003

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

D:\Program Files\Winamp3\winampa.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

D:\documents and settings\administrator\desktop\qttask.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\System32\RUNDLL32.EXE

C:\program files\GlobalDialer\wordi00055\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\rundll32.exe

D:\Program Files\WinZip\WZQKPICK.EXE

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe

C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe

C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe

C:\WINDOWS\System32\wuauclt.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

D:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe

D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

D:\PROGRA~1\WINZIP\winzip32.exe

C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ewebsearch.net/sp.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iec

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.idgsearch.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iec

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

O1 - Hosts: 69.56.223.196 t.rack.cc

O1 - Hosts: 69.56.223.196 www.alfa-search.com

O1 - Hosts: 69.56.223.196 webcoolsearch.com

O1 - Hosts: 69.56.223.196 in.webcounter.cc

O1 - Hosts: 69.56.223.196 i-lookup.com

O1 - Hosts: 69.56.223.196 www.hand-book.com

O1 - Hosts: 69.56.223.196 www.maxxxhosters.com

O1 - Hosts: 69.56.223.196 allneedsearch.com

O1 - Hosts: 69.56.223.196 nativehardcore.com

O1 - Hosts: 69.56.223.196 teen-biz.com

O1 - Hosts: 69.56.223.196 tits.hardcore4ever.net

O1 - Hosts: 69.56.223.196 best.royalsearch.net

O1 - Hosts: 69.56.223.196 default-homepage-network.com

O1 - Hosts: 69.56.223.196 xwebsearch.biz

O1 - Hosts: 69.56.223.196 www.rightfinder.net

O1 - Hosts: 69.56.223.196 www.search-1.net

O1 - Hosts: 69.56.223.196 www.searchv.com

O1 - Hosts: 69.56.223.196 www.websearch.com

O1 - Hosts: 69.56.223.196 mysearchnow.com

O1 - Hosts: 69.56.223.196 www.therealsearch.com

O1 - Hosts: 69.56.223.196 www.find-itnow.com

O1 - Hosts: 69.56.223.196 find.microgirls.com

O1 - Hosts: 69.56.223.196 super-spider.com

O1 - Hosts: 69.56.223.196 www.searching-the-net.com

O1 - Hosts: 69.56.223.196 www.firstbookmark.com

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: Microsoft Excel - {17DA0C9E-4A27-4ac5-BB75-5D24B8CDB972} - C:\DOCUME~1\ADMINI~1\APPLIC~1\MICROS~1\Office\Excel10.dll

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp3\winampa.exe"

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe

O4 - HKLM\..\Run: [QuickTime Task] "D:\documents and settings\administrator\desktop\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [Password Depot] D:\Program Files\AceBIT\Password Depot\PasswordDepot.exe

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook

O4 - HKCU\..\Run: [sws.exe] c:\program files\GlobalDialer\wordi00055\svchost.exe -remove

O4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O15 - Trusted Zone: *.teensguru.com

O15 - Trusted Zone: *.xxxtoolbar.com

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon...bin/AvSniff.cab

O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

Link to comment
Share on other sites

Hi goehring,

I've split this so you have your own thread.

1st of all unzip Hijack this to a folder on your drive, if we fix it whilst running from a temp folder you will have no back up if anything goes wrong :wacko:

then run Hijackthis and have it fix the following.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ewebsearch.net/sp.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iec

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.idgsearch.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iec

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/

O1 - Hosts: 69.56.223.196 t.rack.cc

O1 - Hosts: 69.56.223.196 www.alfa-search.com

O1 - Hosts: 69.56.223.196 webcoolsearch.com

O1 - Hosts: 69.56.223.196 in.webcounter.cc

O1 - Hosts: 69.56.223.196 i-lookup.com

O1 - Hosts: 69.56.223.196 www.hand-book.com

O1 - Hosts: 69.56.223.196 www.maxxxhosters.com

O1 - Hosts: 69.56.223.196 allneedsearch.com

O1 - Hosts: 69.56.223.196 nativehardcore.com

O1 - Hosts: 69.56.223.196 teen-biz.com

O1 - Hosts: 69.56.223.196 tits.hardcore4ever.net

O1 - Hosts: 69.56.223.196 best.royalsearch.net

O1 - Hosts: 69.56.223.196 default-homepage-network.com

O1 - Hosts: 69.56.223.196 xwebsearch.biz

O1 - Hosts: 69.56.223.196 www.rightfinder.net

O1 - Hosts: 69.56.223.196 www.search-1.net

O1 - Hosts: 69.56.223.196 www.searchv.com

O1 - Hosts: 69.56.223.196 www.websearch.com

O1 - Hosts: 69.56.223.196 mysearchnow.com

O1 - Hosts: 69.56.223.196 www.therealsearch.com

O1 - Hosts: 69.56.223.196 www.find-itnow.com

O1 - Hosts: 69.56.223.196 find.microgirls.com

O1 - Hosts: 69.56.223.196 super-spider.com

O1 - Hosts: 69.56.223.196 www.searching-the-net.com

O1 - Hosts: 69.56.223.196 www.firstbookmark.com

O15 - Trusted Zone: *.teensguru.com

O15 - Trusted Zone: *.xxxtoolbar.com

This is a dialer type virus

O4 - HKCU\..\Run: [sws.exe] c:\program files\GlobalDialer\wordi00055\svchost.exe -remove

sws.exe

Haldex type adult content dialler

removal instructions here

Make sure you have the right svchost.exe

C:\program files\GlobalDialer\wordi00055\svchost.exe

Close all browser windows before letting HJT fix the above.

Once done run HJT once more and post the updated log

Link to comment
Share on other sites

CoolWebShredder

A small utility for removing CoolWebSearch (aka CoolWwwSearch, YouFindAll, White-Pages.ws and a dozen other names). Spybot S&D tends to forget essential parts of the hijack, so until it is updated to reflect this, you can use CWS to completely remove the hijack. Its updated to remove the new variants once they come out.

http://www.spywareinfo.com/~merijn/

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy