Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

hotoffers.com turns into zadolbali.com


  • Please log in to reply

#1
warmoth1

warmoth1

    New Member

  • Member
  • Pip
  • 1 posts
Wondering if you can help me with a small problem. I have scanned my computer with many different spyware detectors etc... and none have found this hotoffers.com crud. When I open my IE, if I don't hit X for stop immediately, it will load hotoffers.com, but then change to http://www.zadolbali.....online casino (or some variations) and closes my explorer. Most of the time I have to reboot my computer. I have a program called SpyWare Killer Plus 5 in 1 and have added both of these websites to my blacklist, but they still pop up. Also, I can change my home page to a different web address, click apply, then close the window. When I go back into tools then internet options guess what is still showing as my home page..... You guessed it... Hotoffers.com. Is there any help for this? Here is my most current log of HJT:

Logfile of HijackThis v1.99.1
Scan saved at 12:28:17 PM, on 12/28/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Cosmi\SpyWare Killer 5 in 1\wc\wcservice.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Media Gateway\MediaGateway.exe
C:\PROGRA~1\STOMPS~1\SPYWAR~1\PPControl.exe
C:\PROGRA~1\STOMPS~1\SPYWAR~1\CookiePatrol.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Marty Pelto\Local Settings\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {60D3AAEB-AA39-4AE0-B2F9-E4AF0613A2A3} - C:\PROGRA~1\Cosmi\SPYWAR~1\pop\ABG_PL~1.DLL
O2 - BHO: (no name) - {D1AE4E62-8C27-4C41-9122-9685A0AA4883} - C:\WINDOWS\System32\hbbg.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [FHAPage] C:\WINDOWS\system32\shdocha.exe
O4 - HKLM\..\Run: [Spyware X-terminator Control Center] C:\PROGRA~1\STOMPS~1\SPYWAR~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\STOMPS~1\SPYWAR~1\CookiePatrol.exe
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [scanSYS] Preliminary.exe
O4 - HKLM\..\Run: [vxdman] lpt.exe
O4 - HKLM\..\Run: [dmidv.exe] C:\WINDOWS\System32\dmidv.exe
O4 - HKLM\..\Run: [rscn] C:\WINDOWS\System32\bum448.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\MARTYP~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Microsoft AntiSpyware helper - {26A34F03-8CAA-49B4-8881-F9A0F337EC87} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {26A34F03-8CAA-49B4-8881-F9A0F337EC87} - (no file) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com/start.html
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll
O23 - Service: CXPT_Service - Cyberspace Headquarters, LLC - C:\Program Files\Cosmi\SpyWare Killer 5 in 1\wc\wcservice.exe
O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

Edited by warmoth1, 28 December 2005 - 04:45 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP