Schadenfroh....
I'm copying my post from the other thread, just to save some time, and then I will cut-n-past the HijackThis log here as wel.....per your request. I hope you can find something. I've been loking thru the log, but can't really tell what might be safe to delete and what not to. Oh well....here goes and thanks again!!
------------------------------------------------------------------------------------------------------------------------Original Post From Other Thread:
Hi all....
Somehow I managed to get some kind of scumware loaded onto my system.
I have a fairly clean, XP Home box with IE 6.0, with Spybot, Ad-Aware, and ZoneAlarm loaded on it. I also am using the Grisoft AVG Antivirus software. I update each of these about once per 2 week intervals. I have run them all, at least twice......
......but.....
.....somehow my home page is being redirected to here: http://a-search.biz/?wmid=1010
Be careful with that....I don't know how poisonous it is!
Anyway....I have checked my home page in tools/options/advanced it is as I have set it....my home page. What hapens is, when I launch a new page from say, the start menu the page opens and quickly gives an "Action Canceled" notice, and then launches to the link I gave above. The it displays a dialog about my 'current settings prohibit ActiveX from running'.
I am unable to re-install the Google toolbar. I ahve tried to re-install it 2-3 times now and it will not take. The folder for it is still alive, but something is catching it and preventing it from being active.
I've looked thru the Registry & the Windows folder.......couldn't find anything obvious....looked thru the Programs folder.....there is a mysterious file called "pl.exe" that I have not seen before. I have deleted it 2-3 times, but it keeps coming back. So that is a clue. Ad-Aware found, and removed a registry entry. I thought that would do it, but apparently it has not.
On the Taskbar is an entry, like what a minimized program would look like when it's sitting there, but it will not open or maximize. Its title is just "about:blank Trusted Start Page".
I have looked in "msconfig" for entries listed there, but there is nothing. This is a tuffie! I can't figure this one out, and I do not (apparently) have te tools to tackle this one!
I have also tried a couple online scanners...with ZA turned off.....and nothing.
Anyone know how I can get rid of this demon from hell!?
Thanks
-------------------------------------------------------------------------------------------------------------------------
LOG File From HijackThis
Logfile of HijackThis v1.98.2
Scan saved at 11:25:27 PM, on 9/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\Iconoid\iconoid.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Misc\Applications\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.answerway.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.icon.rite2u.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.icon.rite2u.com
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yi...t/applet/c381/chat.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yi...applet/v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840.../housecall/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/downloa...uite/yautocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1739A3F2-60BE-4B16-AD0A-91D176FC4C0D}: NameServer = 207.69.188.187 207.69.188.186
--------------------------------------------------------------------------------------------------------------------------
<end>
Thanks again......!!!!
bluto
I'm copying my post from the other thread, just to save some time, and then I will cut-n-past the HijackThis log here as wel.....per your request. I hope you can find something. I've been loking thru the log, but can't really tell what might be safe to delete and what not to. Oh well....here goes and thanks again!!
------------------------------------------------------------------------------------------------------------------------Original Post From Other Thread:
Hi all....
Somehow I managed to get some kind of scumware loaded onto my system.
I have a fairly clean, XP Home box with IE 6.0, with Spybot, Ad-Aware, and ZoneAlarm loaded on it. I also am using the Grisoft AVG Antivirus software. I update each of these about once per 2 week intervals. I have run them all, at least twice......
......but.....
.....somehow my home page is being redirected to here: http://a-search.biz/?wmid=1010
Be careful with that....I don't know how poisonous it is!
Anyway....I have checked my home page in tools/options/advanced it is as I have set it....my home page. What hapens is, when I launch a new page from say, the start menu the page opens and quickly gives an "Action Canceled" notice, and then launches to the link I gave above. The it displays a dialog about my 'current settings prohibit ActiveX from running'.
I am unable to re-install the Google toolbar. I ahve tried to re-install it 2-3 times now and it will not take. The folder for it is still alive, but something is catching it and preventing it from being active.
I've looked thru the Registry & the Windows folder.......couldn't find anything obvious....looked thru the Programs folder.....there is a mysterious file called "pl.exe" that I have not seen before. I have deleted it 2-3 times, but it keeps coming back. So that is a clue. Ad-Aware found, and removed a registry entry. I thought that would do it, but apparently it has not.
On the Taskbar is an entry, like what a minimized program would look like when it's sitting there, but it will not open or maximize. Its title is just "about:blank Trusted Start Page".
I have looked in "msconfig" for entries listed there, but there is nothing. This is a tuffie! I can't figure this one out, and I do not (apparently) have te tools to tackle this one!
I have also tried a couple online scanners...with ZA turned off.....and nothing.
Anyone know how I can get rid of this demon from hell!?
Thanks
-------------------------------------------------------------------------------------------------------------------------
LOG File From HijackThis
Logfile of HijackThis v1.98.2
Scan saved at 11:25:27 PM, on 9/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\Iconoid\iconoid.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Misc\Applications\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.answerway.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.icon.rite2u.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.icon.rite2u.com
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yi...t/applet/c381/chat.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yi...applet/v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840.../housecall/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/downloa...uite/yautocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1739A3F2-60BE-4B16-AD0A-91D176FC4C0D}: NameServer = 207.69.188.187 207.69.188.186
--------------------------------------------------------------------------------------------------------------------------
<end>
Thanks again......!!!!
bluto