Home   News  Product reviews  Website reviews  Forums   Competitions  Subscribe 

Software >> Web browser software

 |  Print Thread
woofit1
regular


Reg'd: Thu
Posts: 52
Loc: Blackpool UK
Intruding Web Page
      Fri Sep 19 2003 05:45 PM

A web page keeps popping up without me loading it. I wonder can anyone help. Having read other posts I've downloaded HijackThis and the log is as follows:

Logfile of HijackThis v1.97.2
Scan saved at 17:37:16, on 19/09/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\WINDOWS\System32\WVO_CTRL.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DelFin\PromulGate\PgMonitr.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
C:\Program Files\Microsoft Office\Office\Osa.exe
C:\Program Files\Outlook Express\msimn.exe
C:\unzipped\hijackthis[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.freeserve.com/iesearch/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.download.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.netscapeonline.co.uk/search/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by etelecom
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.uk.netscape.com/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - _{2C2C1BED-5B1C-4bf2-BC2A-86BF224B01AB} - (no file)
R3 - URLSearchHook: SrchHook Class - {2C2C1BED-5B1C-4bf2-BC2A-86BF224B01AB} - C:\WINDOWS\System32\SRHOOK.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Atomica BHO - {3392BD0A-A851-4AA4-86E0-4651006F9EA8} - C:\Program Files\Common Files\Atomica Shared\agtbho.dll
O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\Program Files\MediaLoads Enhanced\ME2.DLL
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem212.dll
O2 - BHO: Comodo TTB BHO - {D80E1356-AC78-4218-961C-A7689B4CB7FE} - C:\WINDOWS\System32\TTBBHO.DLL
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem214.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [Comodo_WebVisibleObject] C:\WINDOWS\System32\WVO_CTRL.EXE
O4 - HKLM\..\Run: [DAupdate] C:\Program Files\NavEnhance\DoubleAgent\DAupdate.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [UpdateMedia] C:\Program Files\MediaUpdate\UpdateMedia.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O8 - Extra context menu item: GuruNet... - file:C:\Program Files\GuruNet\Html\atiemenu.htm
O8 - Extra context menu item: Send Image to Photo Library - file://C:\Program Files\MGI\MGI PhotoSuite III\Temp\MGI00000.html
O9 - Extra button: TTB Pane (HKLM)
O9 - Extra button: FastNet99 (HKLM)
O9 - Extra 'Tools' menuitem: &FastNet99 (HKLM)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: Win32 Classes -
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.143/code/PWActiveXImgCtl.CAB
O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} - http://62.129.133.7/mt/dialers/nl/UK/exe/99935000.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37603.4019675926
O16 - DPF: {A0F0D762-D1DE-43AF-B70E-D87864743EB3} (NSLiteUpdateCtrl Class) - http://217.145.76.16/nslite/nslite.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1C95B2D3-06F2-4DFB-ACC2-408A6CCBAE78}: NameServer = 195.92.195.95 195.92.195.94

Is there anything there that shouldn't be there?
Thanks in advance.


Post Extras Print Post   Remind Me!     Notify Moderator
Rate this thread

Jump to


Entire topic
Subject Posted by Posted on
* Intruding Web Page woofit1 Fri Sep 19 2003 05:45 PM
. * * Re: Intruding Web Page putasolutionsModerator   Fri Sep 19 2003 06:08 PM
. * * Re: Intruding Web Page woofit1   Tue Sep 23 2003 12:45 PM
. * * Re: Intruding Web Page putasolutionsModerator   Tue Sep 23 2003 01:13 PM
. * * Re: Intruding Web Page woofit1   Tue Sep 23 2003 03:01 PM
. * * Re: Intruding Web Page putasolutionsModerator   Tue Sep 23 2003 03:23 PM
. * * Re: Intruding Web Page woofit1   Tue Sep 23 2003 04:34 PM
. * * Re: Intruding Web Page putasolutionsModerator   Tue Sep 23 2003 05:03 PM
. * * Re: Intruding Web Page greystsModerator   Tue Sep 23 2003 09:12 PM
. * * Re: Intruding Web Page arney   Tue Sep 23 2003 09:17 PM
. * * Re: Intruding Web Page greystsModerator   Wed Sep 24 2003 11:23 AM
. * * Re: Intruding Web Page putasolutionsModerator   Wed Sep 24 2003 11:46 AM
. * * Re: Intruding Web Page woofit1   Wed Sep 24 2003 12:53 PM
. * * Re: Intruding Web Page putasolutionsModerator   Wed Sep 24 2003 01:20 PM
. * * W32 Spybot Worm woofit1   Thu Sep 25 2003 06:31 PM
. * * Re: W32 Spybot Worm putasolutionsModerator   Thu Sep 25 2003 09:48 PM
. * * Re: W32 Spybot Worm woofit1   Fri Sep 26 2003 12:12 PM
. * * Re: W32 Spybot Worm putasolutionsModerator   Fri Sep 26 2003 12:39 PM
. * * Re: W32 Spybot Worm woofit1   Fri Sep 26 2003 01:00 PM
. * * Re: W32 Spybot Worm putasolutionsModerator   Fri Sep 26 2003 01:04 PM
. * * Re: W32 Spybot Worm woofit1   Fri Sep 26 2003 07:32 PM
. * * Re: W32 Spybot Worm Barney_Rubble   Fri Oct 03 2003 05:22 PM
. * * Re: W32 Spybot Worm Barney_Rubble   Fri Sep 26 2003 02:19 PM
. * * Re: W32 Spybot Worm bricatModerator   Fri Sep 26 2003 04:50 PM
. * * Re: Intruding Web Page Arandora   Tue Sep 23 2003 07:57 PM
. * * Re: Intruding Web Page woofit1   Tue Sep 23 2003 03:21 PM
. * * Re: Intruding Web Page bricatModerator   Tue Sep 23 2003 03:29 PM

Extra information
0 registered and 4 anonymous users are browsing this forum.

Moderator:  Mouse, Joe_London, greysts, John_McKenna, putasolutions, bricat, Hello_There, Nanook, TheFatControlleR 


Print Thread
Forum Permissions
      You cannot start new topics
      You cannot reply to topics
      HTML is disabled
      Mark-up is enabled

Rating:
Thread views: 11

Contact Us | Privacy statement Main website
Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy
© Copyright IPC Media Limited, All rights reserved