1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Browser Hijack Problem - Log File attached

Discussion in 'Security and Privacy' started by mrp, 2004/07/12.

Thread Status:
Not open for further replies.
  1. 2004/07/12
    mrp

    mrp Inactive Thread Starter

    Joined:
    2004/07/12
    Messages:
    1
    Likes Received:
    0
    I have a hijacked IE interface
    I have run the Hijack software (see the log below)
    My problem is that after scanning and removal I tried a resacn as
    recommended but the problem persists
    It appear that there is someting runnning whenever I boot up that continually
    changes my home page, default page etc to the address in the logfile
    This causes my internet connection to drop out
    Any help would be appreciated I spent 4 hours last night getting nowhere
    Cheers
    Milos

    Logfile of HijackThis v1.97.7
    Scan saved at 12:20:07 AM, on 13/07/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\aa_mrp\hijack\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
     
    mrp,
    #1
  2. 2004/07/12
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    Welcome to the boards!
    Would you post the complete log, using the updated HJT 1.98?
    All I can say for now is that all the R0 and R1 entries needs to go, but would only be a bandaid, as there is more to see.
     

  3. to hide this advert.

Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.