Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Security Center Hijack


  • Please log in to reply

#1
Kazukikazama

Kazukikazama

    New Member

  • Member
  • Pip
  • 5 posts
Hi, i've had this problem for quite a while now, its just been a major annoyance but ive lived on ^^

Whenever i open my IE my homepage is changed to http://updatescenter.com/ and it tells me to download PsGuard and SpyTrooper to get rid of the Spyware, but i know ofcourse that those two have spyware themselves...

Hope someone could help me with this

Logfile of HijackThis v1.99.1
Scan saved at 03:11:46, on 22/09/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Kazuki\Desktop\ddd\NAVSetup.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Kazuki\Desktop\ddd\Support\Prescan\Prescan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Kazuki\Desktop\HijackThis.exe

O2 - BHO: HomepageBHO - {893fad3a-931e-4e53-b515-b1426d63799b} - C:\WINDOWS\System32\hp857B.tmp
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\rwchu.dll (file missing)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [warez] "C:\Program Files\WarezP2P\warez.exe" -h
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1125510179842
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E1929CA-6DF8-4BFD-9F96-8F52A94E7A62}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A6DA1E1-6AEE-46C3-A623-394D1C390144}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{86881A6B-F1ED-471F-9131-FEDE12C32DCF}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E1929CA-6DF8-4BFD-9F96-8F52A94E7A62}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E1929CA-6DF8-4BFD-9F96-8F52A94E7A62}: NameServer = 85.255.113.140,85.255.112.26
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Edited by Kazukikazama, 21 September 2005 - 08:28 PM.

  • 0

Advertisements


#2
Kazukikazama

Kazukikazama

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Hi, i've had this problem for quite a while now, its just been a major annoyance but ive lived on ^^

Whenever i open my IE my homepage is changed to http://updatescenter.com/ and it tells me to download PCGuard and SpyTrooper to get rid of the Spyware, but i know ofcourse that those two have spyware themselves...

Hope someone could help me with this

ogfile of HijackThis v1.99.1
Scan saved at 03:11:46, on 22/09/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Kazuki\Desktop\ddd\NAVSetup.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Kazuki\Desktop\ddd\Support\Prescan\Prescan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Kazuki\Desktop\HijackThis.exe

O2 - BHO: HomepageBHO - {893fad3a-931e-4e53-b515-b1426d63799b} - C:\WINDOWS\System32\hp857B.tmp
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\rwchu.dll (file missing)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [warez] "C:\Program Files\WarezP2P\warez.exe" -h
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1125510179842
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E1929CA-6DF8-4BFD-9F96-8F52A94E7A62}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A6DA1E1-6AEE-46C3-A623-394D1C390144}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{86881A6B-F1ED-471F-9131-FEDE12C32DCF}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E1929CA-6DF8-4BFD-9F96-8F52A94E7A62}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E1929CA-6DF8-4BFD-9F96-8F52A94E7A62}: NameServer = 85.255.113.140,85.255.112.26
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
  • 0

#3
Kazukikazama

Kazukikazama

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Sorry for the Bump but this is now on page 5 could someone look into this please...thanks
  • 0

#4
Kazukikazama

Kazukikazama

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Another BUMP! PAGE 7 >.< Come on People!! Please!
  • 0

#5
Kazukikazama

Kazukikazama

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Hi, Whenever i go on IE i get alot of popups, not straight away, when ive been on for around 10mins...when i click a link it will direct me to somewhere totally irrelivant, I've used so many spyware/anti-virus software and nothing has worked..

Heres my log

Logfile of HijackThis v1.99.1
Scan saved at 01:54:25, on 23/09/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
F:\symsetup.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\MsiExec.exe
C:\Documents and Settings\Kazuki\Desktop\hijackthis\HijackThis.exe
C:\WINDOWS\Installer\MSI83.tmp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [warez] "C:\Program Files\WarezP2P\warez.exe" -h
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1125510179842
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E1929CA-6DF8-4BFD-9F96-8F52A94E7A62}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A6DA1E1-6AEE-46C3-A623-394D1C390144}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{86881A6B-F1ED-471F-9131-FEDE12C32DCF}: NameServer = 85.255.113.140,85.255.112.26
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E1929CA-6DF8-4BFD-9F96-8F52A94E7A62}: NameServer = 85.255.113.140,85.255.112.26
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP