WaqasTariq
Full Member
Posts: 356 Reputation: 3
42 / /
Joined: Jan 2003
|
O.P. RE: RE: IE hijacked... Help !
quote: Originally posted by Markus
quote: Originally posted by Markus
please do a scan with HijackThis and attach the log file here. I'll tell you which entries to select and remove/reset
Hi,
Here is the log file...
Logfile of HijackThis v1.99.1
Scan saved at 10:40:11 PM, on 5/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\prime Computer\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\PRIMEC~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\PRIMEC~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {977E10FC-95FE-4399-A349-C505A1DC502B} - C:\WINDOWS\system32\bogj.dll
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\PRIMEC~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DC5AE20-371B-4701-AEF4-F5B218B30D38}: NameServer = 202.163.96.3 202.163.96.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{1DC5AE20-371B-4701-AEF4-F5B218B30D38}: NameServer = 202.163.96.3 202.163.96.4
O18 - Filter: text/html - {7D305B7D-30C4-4C85-9BC0-1F29990A9E6F} - C:\WINDOWS\system32\bogj.dll
O18 - Filter: text/plain - {7D305B7D-30C4-4C85-9BC0-1F29990A9E6F} - C:\WINDOWS\system32\bogj.dll
|
|