Notices
General NON-Automotive Conversation No Political, Sexual or Religious topics please.

hijack this screen

Thread Tools
 
Search this Thread
 
Old Jun 18, 2004 | 06:10 PM
  #1  
triplethreat's Avatar
triplethreat
Thread Starter
|
Senior User
Joined: Apr 2004
Posts: 164
Likes: 0
From: Hubert North Carolina
hijack this screen

Here is the requested screen can anybody give me a clue what i should delete. if you did not read my other post i have a hijack virus that is changing my homepage to homesearch. Thanks

Dan
Here is my hijack screen thanks for any help

Logfile of HijackThis v1.97.7
Scan saved at 12:14:39 PM, on 6/18/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss*****
C:\WINDOWS\system32\winlogon*****
C:\WINDOWS\system32\services*****
C:\WINDOWS\system32\lsass*****
C:\WINDOWS\system32\svchost*****
C:\WINDOWS\System32\svchost*****
C:\WINDOWS\Explorer*****
C:\WINDOWS\system32\LEXBCES*****
C:\WINDOWS\system32\LEXPPS*****
C:\WINDOWS\system32\spoolsv*****
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr*****
C:\WINDOWS\System32\cisvc*****
C:\Program Files\Norton AntiVirus\navapsvc*****
C:\WINDOWS\System32\nvsvc32*****
C:\WINDOWS\System32\svchost*****
C:\WINDOWS\system32\mshz32*****
C:\WINDOWS\system32\qttask*****
C:\program files\support.com\client\bin\tgcmd*****
C:\Program Files\Logitech\iTouch\iTouch*****
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd*****
C:\Program Files\BroadJump\Client Foundation\CFD*****
C:\Program Files\Common Files\Symantec Shared\ccApp*****
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd*****
C:\Program Files\HP\hpcoretech\hpcmpmgr*****
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC*****
C:\WINDOWS\System32\ndllzxy*****
C:\WINDOWS\system32\iels*****
C:\Program Files\Messenger\msmsgs*****
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf*****
C:\Program Files\Sony\VAIO Action Setup\VAServ*****
C:\Program Files\Sony Corporation\Image Transfer\SonyTray*****
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08*****
C:\Program Files\Road Runner\Medic\RRMedic*****
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD*****
C:\WINDOWS\System32\HPZipm12*****
C:\WINDOWS\System32\cidaemon*****
C:\WINDOWS\System32\WISPTIS*****
C:\Program Files\Internet Explorer\iexplore*****
C:\Documents and Settings\Tina\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis*****
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nsjjn.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://nsjjn.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://nsjjn.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nsjjn.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://nsjjn.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\nsjjn.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Roadrunner
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = ;127.0.0.1;localhost
O2 - BHO: (no name) - {34486039-E905-10CA-29CC-C115092F02E3} - C:\WINDOWS\system32\crrq.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32***** NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\system32\qttask*****
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\bin\tgcmd***** /server
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch*****
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd*****
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD*****
O4 - HKLM\..\Run: [tgcmd] "c:\program files\support.com\client\bin\tgcmd*****" /server /nosystray /deaf
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp*****"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy*****"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd*****"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr*****"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC*****
O4 - HKLM\..\Run: [stwitpwciru] C:\WINDOWS\System32\ndllzxy*****
O4 - HKLM\..\Run: [iels*****] C:\WINDOWS\system32\iels*****
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs*****" /background
O4 - HKCU\..\Run: [SureCleanProfessional] "C:\PROGRA~1\PANICW~1\SURECL~1\SRCLEAN*****"
O4 - HKLM\..\RunOnce: [ieee32*****] C:\WINDOWS\ieee32*****
O4 - HKLM\..\RunOnce: [d3ub*****] C:\WINDOWS\system32\d3ub*****
O4 - HKLM\..\RunOnce: [sysna32*****] C:\WINDOWS\system32\sysna32*****
O4 - HKLM\..\RunOnce: [winys32*****] C:\WINDOWS\system32\winys32*****
O4 - HKLM\..\RunOnce: [winbf*****] C:\WINDOWS\winbf*****
O4 - HKLM\..\RunOnce: [syspo32*****] C:\WINDOWS\system32\syspo32*****
O4 - Startup: Medic.lnk = C:\Program Files\Road Runner\Medic\RRMedic*****
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Adobe Gamma Loader*****.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader*****
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08*****
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf*****
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL*****/3000
O9 - Extra button: Research (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/gam...ts/y/grt5_x.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdc...ad/tgctlins.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/...director/sw.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeu...ontent/opuc.cab
O16 - DPF: {72944257-0AE0-44FD-8A51-AA21853092C8} (PhxStudent.OeSetup15) - https://mycampus.phoenix.edu/secure/PhxStudent15.CAB
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/...ash/swflash.cab
O16 - DPF: {FF054BED-D972-4215-897E-726C348DBB} (sonyctl.sonycm) - http://supportcentral4.sel.sony.com...oad/sonyctl.CAB
 
Reply
Old Jun 18, 2004 | 06:12 PM
  #2  
drewcoolness99's Avatar
drewcoolness99
Elder User
Joined: Jul 2003
Posts: 935
Likes: 0
From: TEXAS!!!!!!!!!!!!
C:\WINDOWS\System32\HPZipm12*****
C:\WINDOWS\System32\cidaemon*****
C:\WINDOWS\System32\WISPTIS*****


?
 
Reply
Old Jun 18, 2004 | 06:45 PM
  #3  
TrunkSlammer's Avatar
TrunkSlammer
Senior User
Joined: Jan 2003
Posts: 315
Likes: 0
Sorry took so long,

You have Searchpage.cc: searchpage.cc is a browser helper object changes your SearchURL, Search Bar, Search Page, Default Page URL, SearchAssistant and CustomizeSearch to nkvd.us or searchpage.cc.

Please notice that you must follow the instructions very carefully and delete everything that is mentioned. In most cases the removal will fail if one single item is not deleted. If searchpage.cc remains on your system after stepping through the removal instructions, please double-check by stepping through them again.

Click here for instructions: http://www.kephyr.com/spywarescanner...cc/index.phtml
 
Reply
Old Jun 18, 2004 | 07:10 PM
  #4  
MustangGT221's Avatar
MustangGT221
Post Fiend
Joined: Nov 2001
Posts: 14,947
Likes: 6
From: Topsfield, MA
Club FTE Gold Member
Sounds to me like spyware if you're having the homepage being changed. Download spybot search & destroy and adware 6.0 from download.com and run them, should fix the problem.
 
Reply
Old Jun 18, 2004 | 07:51 PM
  #5  
triplethreat's Avatar
triplethreat
Thread Starter
|
Senior User
Joined: Apr 2004
Posts: 164
Likes: 0
From: Hubert North Carolina
I've already tried spybot and so forth. what it is is a hijacking virus. i'm going to try and follow the manuel removal in the morning i'll let ya'll know how it turns out tommarow.

Dan
 
Reply
Old Jun 19, 2004 | 06:52 PM
  #6  
Reu's Avatar
Reu
New User
Joined: May 2004
Posts: 3
Likes: 0
Run - CWShredder - that program is just for removing browser hijacks.

Always run Adaware then Spybot then CWShredder.

Panda has a free online virus scan if you dont have Norton. Just search for Panda virus scan.
 
Reply
Old Jun 19, 2004 | 08:11 PM
  #7  
triplethreat's Avatar
triplethreat
Thread Starter
|
Senior User
Joined: Apr 2004
Posts: 164
Likes: 0
From: Hubert North Carolina
i have run all three of those and do have nortons however the hijack is still there from what i have found out it is a new virus. i have gotten directions on removal and have tried them but there are many variables as to locations changing and i do not have enough computer know-how to do it. they say a fix should be out by next week so i guess i'll just what a little to see if one comes out or take it to get fixed.

Dan
 
Reply
Old Jun 21, 2004 | 08:25 PM
  #8  
Jerry Gougeon's Avatar
Jerry Gougeon
Elder User
Joined: May 2004
Posts: 553
Likes: 0
From: Ont. Can.
Highjacked :

From the looks of your page nothing seems to be out of the ordinary . I would however pull up your tree and explore what the file C:\D&S\tina|localsettings\temp\temporydirectory4\e tc.etc.etc. and seewhat the properties of this are .

If this is not your culprit I would be leaning towards Mustangs opinion that your virus is a spyware cookie and not a virus at all as it does not seem to be eating up your files or OP system .

Will probably be attatched to a legitimate program so it remains undetected without a lot of effort .

If you have run all the spyware detection you have said without results you may be into searching manually through your files to find an attachment that is the hitchiker .

I attained some German **** site cookie like this one time before I was on a private server with full filter system that took me 3 days to find manually as nothing I ran would detect it .

Finally , a small square pink icon attatched to one of the thousands of DLL's
in my system . Recorded the DLL and deleted it and then reload the DLL was the only way I found to get rid of it .
 
Reply
FTE Stories

Ford Trucks for Ford Truck Enthusiasts

story-0

Top 10 Ford Truck Tragedies

 Joe Kucinski
story-1

AEV FXL Super Duty - the Super Duty Raptor Ford Doesn't Make

 Brett Foote
story-2

Lobo Vs Lobo: Proof the F-150 Lobo Should Be Even Lower!

 Michael S. Palmer
story-3

Ford's 2001 Explorer Sportsman Concept Looks For a New Home

 Verdad Gallardo
story-4

10 Best Ford Truck Engines We Miss the Most!

 Joe Kucinski
story-5

2026 Shelby F-150 Off-Road: Better Than a Raptor R?

 Brett Foote
story-6

2027 Super Duty Carhartt Package First Look: 12 Things You NEED to Know!

 Michael S. Palmer
story-7

10 Most Surprising 2026 Ford Truck Features!

 Joe Kucinski
story-8

Top 10 Ford Trucks Coming to Mecum Indy 2026

 Brett Foote
story-9

5 Best / 5 Worst Ford Truck Wheels of All Time

 Joe Kucinski
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
ford2go
General NON-Automotive Conversation
7
Apr 10, 2009 09:16 AM
cdrmotorsports
General NON-Automotive Conversation
21
Jan 24, 2007 07:44 PM
99PSDCREW
General NON-Automotive Conversation
18
Oct 24, 2004 12:17 PM
paul812
General NON-Automotive Conversation
16
Oct 10, 2004 03:46 PM
TrunkSlammer
General NON-Automotive Conversation
12
Jun 16, 2004 02:01 AM




All times are GMT -5. The time now is 04:06 AM.

story-0
Top 10 Ford Truck Tragedies

Slideshow: Top 10 Ford truck tragedies.

By Joe Kucinski | 2026-05-18 19:34:33


VIEW MORE
story-1
AEV FXL Super Duty - the Super Duty Raptor Ford Doesn't Make

And it might be even better than that.

By Brett Foote | 2026-05-18 19:26:42


VIEW MORE
story-2
Lobo Vs Lobo: Proof the F-150 Lobo Should Be Even Lower!

Slideshow: Does lowering an F-150 Lobo RUIN the ride quality?

By Michael S. Palmer | 2026-05-18 19:20:37


VIEW MORE
story-3
Ford's 2001 Explorer Sportsman Concept Looks For a New Home

Slideshow: Ford's bizarre fishing-themed Explorer concept has resurfaced after spending decades largely forgotten.

By Verdad Gallardo | 2026-05-12 18:07:46


VIEW MORE
story-4
10 Best Ford Truck Engines We Miss the Most!

Slideshow: The 10 best Ford truck engines we miss the most.

By Joe Kucinski | 2026-05-12 13:09:47


VIEW MORE
story-5
2026 Shelby F-150 Off-Road: Better Than a Raptor R?

Slideshow: first look at the 810 hp 2026 Shelby F-150 Off-Road!

By Brett Foote | 2026-05-12 12:50:07


VIEW MORE
story-6
2027 Super Duty Carhartt Package First Look: 12 Things You NEED to Know!

Slideshow: Everything You Need to Know about the 2027 Super Duty Carhartt Package!

By Michael S. Palmer | 2026-05-07 17:51:06


VIEW MORE
story-7
10 Most Surprising 2026 Ford Truck Features!

Slideshow: 10 most surprising Ford truck options/features in 2026.

By Joe Kucinski | 2026-05-05 11:17:22


VIEW MORE
story-8
Top 10 Ford Trucks Coming to Mecum Indy 2026

Slideshow: Here are the top 10 Fords coming to Mecum Indy 2026.

By Brett Foote | 2026-05-04 13:49:49


VIEW MORE
story-9
5 Best / 5 Worst Ford Truck Wheels of All Time

Slideshow: The 5 best and 5 worst Ford truck wheels of all time

By Joe Kucinski | 2026-04-29 16:49:01


VIEW MORE