1. This Board Rocks has been moved to a new domain: CarolinaPanthersForum.com

    All member accounts remain the same.

    Most of the content is here, as well. Except that the Preps Forum has been split off to its own board at: http://www.prepsforum.com

    Welcome to the new Carolina Panthers Forum!

    Dismiss Notice

Help Needed

Discussion in 'Technology Forum' started by Peteywheatstraw, Jun 10, 2004.

  1. Peteywheatstraw

    Peteywheatstraw Junior Member

    Posts:
    21
    Likes Received:
    0
    Joined:
    Jan 7, 2003
    My homepage has been hijacked. Everytime i restart my computer my homepage is different than what i set it to, and also there are about 10 or so things added to my favorites. I've installed Spysweeper and Spy Remover both, and they found a few things and removed them, but i still have the homepage changed and things in my favorites every time that i restart. I've also ran both Norton and Panda antivirus and they both say that i'm virus free. So what's the deal? oh, and of course i've deleted the things that were added to my favorites and they keep returning. I'm running Windows Xp Home if that makes a difference. Any help is very much appreciated. thanks
     
    Last edited: Jun 10, 2004
  2. two-six

    two-six yes, i carved this

    Age:
    49
    Posts:
    9,712
    Likes Received:
    0
    Joined:
    Apr 20, 2003
    Location:
    Concord, NC
    google search for cwshredder and install. run it and that should take care of your problems.....then, quit lookin at free porn :laugh1:
     
  3. Randomsoleil

    Randomsoleil Junior Member

    Age:
    45
    Posts:
    26
    Likes Received:
    0
    Joined:
    Jul 11, 2003
    yeah you have got one hell of a trojan..... I would try the above option if not...just switch browsers..i have noticed that IE is more suceptible (sp) to trojans than netscape
     
  4. LarryD

    LarryD autodidact polymath

    Posts:
    29,846
    Likes Received:
    0
    Joined:
    Feb 7, 2002
    Location:
    living the dream
    look for the thread where i helped out kakia here a few months back. search here for cwshredder
     
  5. dig-it

    dig-it Wait'n On That Post Rookie Deal

    Posts:
    20,349
    Likes Received:
    2,466
    Joined:
    Jan 7, 2003
    Location:
    Concord, NC
  6. Peteywheatstraw

    Peteywheatstraw Junior Member

    Posts:
    21
    Likes Received:
    0
    Joined:
    Jan 7, 2003
    i ran cwshredder and it removed a few things, but when i restart my homepage is still changed and the items are still in my favorites. each time i restart i run cwshredder again and it finds the same amount of items and removes them. and yes, i make sure all my windows are closed before i run it. so, nothing has changed, and i still have a hijacked homepage and items in my favorites. i also ran hack this but i have no clue what i should possibly try to fix with it. maybe someone could help me out if i post the log? thanks to everyone that tried to help me out, i appreciate it.

    Logfile of HijackThis v1.97.7
    Scan saved at 3:57:32 PM, on 6/10/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\PROGRA~1\NORTON~1\navapw32.exe
    C:\WINDOWS\System32\devldr32.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\PROGRA~1\Zone Labs\ZoneAlarm\zapro.exe
    C:\WINDOWS\ziphelp.exe
    C:\WINDOWS\System32\RUNDLL32.EXE
    C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
    C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
    C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\System32\wuauclt.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
    O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
    O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
    O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\Zone Labs\ZoneAlarm\zapro.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ziphelp] C:\WINDOWS\ziphelp.exe
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - Global Startup: America Online Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
    O4 - Global Startup: Camio Viewer.lnk = C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: MoneySide (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {17163BB4-107E-11D4-9B76-006097DF2317} (EABootStrap Class) - http://aol.ea.com/downloads/games/common/boot_strap/iegils.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
    O16 - DPF: {33288993-5664-11D4-8B5B-00D0B73B3518} (ell Class) - http://aol.ea.com/downloads/games/common/ieell.cab
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.142/code/PWActiveXImgCtl.CAB
    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
    O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3A8318E7-EF68-44BA-9A75-89272AE1FADC}: NameServer = 192.168.0.1 209.198.7.5
    O17 - HKLM\System\CS1\Services\Tcpip\..\{3A8318E7-EF68-44BA-9A75-89272AE1FADC}: NameServer = 192.168.0.1 209.198.7.5
     
  7. Patti

    Patti ~

    Posts:
    16,755
    Likes Received:
    2
    Joined:
    Jan 7, 2003
  8. two-six

    two-six yes, i carved this

    Age:
    49
    Posts:
    9,712
    Likes Received:
    0
    Joined:
    Apr 20, 2003
    Location:
    Concord, NC
    i had a pesky awhile back that did that. don't remember how i fixed it, but if i do, i'll let ya know.
     
  9. Peteywheatstraw

    Peteywheatstraw Junior Member

    Posts:
    21
    Likes Received:
    0
    Joined:
    Jan 7, 2003
    yeah, i searched and found that thread earlier. it's where i got the link to cwshredder and hijack this from. thanks for trying to help me out though, i appreciate the effort.
     
  10. Peteywheatstraw

    Peteywheatstraw Junior Member

    Posts:
    21
    Likes Received:
    0
    Joined:
    Jan 7, 2003

    damn, i hope u do cuz this is pretty fuckin annoying. free porn ain't really free i guess.
     

Share This Page