Computing.Net > Forums > Security and Virus > Browser hpage favorits highjacked

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Browser hpage favorits highjacked

Reply to Message Icon

Name: cahuet
Date: February 20, 2004 at 11:01:10 Pacific
OS: Win2000
CPU/Ram: PII
Comment:

Hi

I still have Hijackthis reporting R0 and R1 registry values set to www.2020search.com
as well as

015 trusted zone lines set to:
*.i-lookup.com
*.teensguru.com
*.offshoreclicks.com
*.xxxtoolbar.com

I ran spywareblastersetup, Cwschredder, ad-awar6, Spybots, xtracer, and finally highjackthis with the lastest updates (with reboot between different executions and at computer startup and offline) but I still have My IExplorer home page highjack and VIPru.com favorite added illegaly as well as shortcuts (loans sex etc) on my desktops.

I have done a lot of researches on the net to find a solution without any sucess. Any idea??

Thank you for your help
Talk to you soon




Sponsored Link
Ads by Google

Response Number 1
Name: blender
Date: February 20, 2004 at 14:44:59 Pacific
Reply:

cahuet

Can you post your hijack log here please?

Thanks!
_________________________

I never give up!


0

Response Number 2
Name: MrChalee
Date: February 21, 2004 at 05:41:52 Pacific
Reply:

There's an uninstaller on their web site.
Uninstall 2020search
So far as the 015's, have HJT fix them.


0

Response Number 3
Name: cahuet
Date: February 21, 2004 at 12:23:12 Pacific
Reply:

Hi Blender,

Here it is:

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\Pavsrv50.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\WebProxy.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\AVENGINE.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WebSiteViewer\122691.dlr
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Downloads\VirusDefense\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - C:\WINNT\winres.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.exe" /s
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m
O4 - HKCU\..\Run: [sp] C:\WINNT\sp.exe
O4 - Global Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
O4 - Global Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O15 - Trusted Zone: *.i-lookup.com
O15 - Trusted Zone: *.offshoreclicks.com
O15 - Trusted Zone: *.teensguru.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by8fd.bay8.hotmail.msn.com/activex/HMAtchmt.ocx


Thanks for your help


0

Response Number 4
Name: blender
Date: February 22, 2004 at 08:45:31 Pacific
Reply:

cahuet

While offline check the following in hijack:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - C:\WINNT\winres.dll

O4 - HKCU\..\Run: [sp] C:\WINNT\sp.exe

O15 - Trusted Zone: *.i-lookup.com
O15 - Trusted Zone: *.offshoreclicks.com
O15 - Trusted Zone: *.teensguru.com
O15 - Trusted Zone: *.xxxtoolbar.com

Close any open windows and click "fix checked"

Reboot to safe mode, offline and delete the following if still present:

c:\winnt\winres.dll <-file
c:\winnt\sp.exe <-file

Rerun your ad-aware and spybot (while in safe mode to remove what they find)

Reboot to normal windows and go here for virus scan:

http://housecall.trendmicro.com/housecall/start_corp.asp

You will need to disable your own av to prevent conflicts.


Post new log when done.
______________________________


I never give up!


0

Response Number 5
Name: blender
Date: February 22, 2004 at 08:52:47 Pacific
Reply:

cahuet

Before removing the 04 for:

O4 - HKCU\..\Run: [sp] C:\WINNT\sp.exe

Or deleting the file sp.exe....can you check its properties please?
I am not sure on that one....more research shows it may be valid...
Let me know what it is....thanks...sorry for confusion.
__________________________

I never give up!


0

Related Posts

See More



Response Number 6
Name: Sucumba
Date: February 24, 2004 at 19:00:57 Pacific
Reply:

I have the same problem with this HJ, i want to know if doing that things you could solve the problem, so as to follow the same steps...
ty
jp


0

Response Number 7
Name: Cassandra
Date: February 25, 2004 at 21:32:01 Pacific
Reply:

I can't get rid of this Golden Palace Casino that keeps downloading or the XXX toolbar....I ran hijack this, but I don't know what to delete...can somebody help me?


0

Response Number 8
Name: blender
Date: February 26, 2004 at 09:53:46 Pacific
Reply:

Cassandra

I had golden palace and xxxtoolbar on my 98 machine...I removed most of it by going to add/remove programs and removing:

CasProg
xxxtoolbar
CSync...comes with the toolbar and is spyware
n-case
ncase ads delivery...comes with xxx crap and is adware...you will be taken to a website to download the uninstaller.
IST
ISTsvc...part of the xxxtoolbar
Internet optimiser...comes with that toolbar
Active alert..comes with the toolbar

***note***
All those programs I listed may not be there but do remove any of the ones that are in my list above.

After you removed what you can with add/rem...reboot when it tells you, and you need to be online for most because the site that installed it will uninstall it.
Download these 3 programs for both protection and removal of what is left.

Ad-aware

Spybot

Spywareblaster

Once installed update all 3 programs.
Spywareblaster...once updated click the select all button, click the "protect from checked items button.

Spybot...after updating run its scan (turn off your antivirus to prevent conflicts) remove all in red.
Ad-aware...after updating, close it and restart the program, set up the following:

Click the gear icon on top of window
click scanning button on left...check everything you can there...green=on
Click tweak on left...
click the+ beside scanning engine, make sure this is green:
unload recognized processes during scanning
Click the+ beside cleaning engine
Make sure this is green:
Let windows remove files in use at next reboot
Click proceed at botom of window
click start
check use custom scanning options
Make sure Activate in depth scan is green
Click next
Let it remove all found.

Make sure you have all your windows updates, there has been many security related issues fixed that will help prevent re-infection.

And if you havn't already...wouldnt hurt to do a full system scan with antivirus.

Here is an online scanner if you need it:

Housecall

If ou use the online scanner...turn off your antivirus to prevent conflicts.

Once you have done all that...start your own new thread if you want to post hijack log...but do say you used spybot, ad-aware to clean up first. (there will still be a few things to remove (fix))

All the above programs are free.

Jp

Follow same advise as I gave Cassandra
_________________________________


I never give up!


0

Response Number 9
Name: mmmiha
Date: February 27, 2004 at 07:00:43 Pacific
Reply:

Hi,

I think I have the similar problem: about:blank page was highjacked with some internet search. The only thing I could do was to remove links to a file "winres.dll" from the registry. It helped but I wonder if is it an original Windows file or some trojan created it. One more thing: is it possible that trojan is still there?


Lamers everywhere!


0

Response Number 10
Name: Cassandra
Date: February 27, 2004 at 13:37:08 Pacific
Reply:

Hey Jp, I did everything you said, and Golden Palace Casino is still downloading. Here is my hijackthis log...thanks so much!!! ~Cassandra

Logfile of HijackThis v1.97.7
Scan saved at 4:24:37 PM, on 2/27/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\WINDOWS\System32\uvtqaxhq.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\iPod\bin\iPodManager.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Ares\ares.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\CASSANDRA\My Documents\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.globalcomputer.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://ucf.proxy.fcla.edu:8888
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C048B794-38AE-C293-FEFE-81DF7AD8FE08} - C:\WINDOWS\system32\vykulgti.dll
O2 - BHO: (no name) - {EFBDCDCC-BC0A-F92F-96CA-833D8BFD563C} - C:\WINDOWS\system32\poibtyab.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [onlhidhd] C:\WINDOWS\eydcnpsm.exe
O4 - HKLM\..\Run: [WinFavorites] C:\Program Files\WinFavorites\WinFavorites.exe1
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [xgnvkyza] C:\WINDOWS\System32\uvtqaxhq.exe
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\KaZaA Lite\Kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [] c:\WINDOWS\System32\
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [zzb] c:\WINDOWS\System32\zzb.exe
O4 - HKLM\..\Run: [nvid] C:\WINDOWS\System32\tpsaqfgv.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKCU\..\Run: [] c:\WINDOWS\System32\
O4 - HKCU\..\Run: [zzb] c:\WINDOWS\System32\zzb.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\ares.exe" -h
O4 - HKLM\..\RunOnce: [RealPlayer_update] C:\Program Files\America Online 9.0\Jiti\Real9_codec_upd.exe restart
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.globalcomputer.com
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab



0

Response Number 11
Name: blender
Date: February 27, 2004 at 14:01:34 Pacific
Reply:

mmmiha

That winres.dll is one of the cool web search trojan varients...

Link to CWShredder...removal tool. Second one in the list.
Run the tool while offline, with all windows closed except for cwshredder.

http://www.lurkhere.com/~nicefiles/

The tool will check for and remove any other varients and remains of the one you have (had).

To prevent it from happening again....Visit windows update, install all critical updates and service packs for both windows and for internet explorer.
_________________________________

I never give up!


0

Response Number 12
Name: blender
Date: February 27, 2004 at 14:59:40 Pacific
Reply:

Cassandra

Just so I dont confuse you...I was giving Jp pretty much the same advise.

First place hijack in its own folder in your "my documents" folder...the program makes backups and will make a mess of your documents folder.

Start hijackthis and check all the following:

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {C048B794-38AE-C293-FEFE-81DF7AD8FE08} - C:\WINDOWS\system32\vykulgti.dll
O2 - BHO: (no name) - {EFBDCDCC-BC0A-F92F-96CA-833D8BFD563C} - C:\WINDOWS\system32\poibtyab.dll

O4 - HKLM\..\Run: [onlhidhd] C:\WINDOWS\eydcnpsm.exe
O4 - HKLM\..\Run: [WinFavorites] C:\Program Files\WinFavorites\WinFavorites.exe1

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [xgnvkyza] C:\WINDOWS\System32\uvtqaxhq.exe

O4 - HKLM\..\Run: [] c:\WINDOWS\System32\

O4 - HKLM\..\Run: [nvid] C:\WINDOWS\System32\tpsaqfgv.exe

O4 - HKCU\..\Run: [] c:\WINDOWS\System32\

O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

Close all windows except hijack and click "fix checked"

Reboot the computer to SAFE mode (tap f8 while booting)
Show hidden and system files:

Start> settings> control panel> folder options> View> Check "show hidden files and folders"> click apply> click ok.

Search for and delete the following files/folders:

C:\WINDOWS\eydcnpsm.exe <- file
C:\Program Files\WinFavorites <- folder
C:\WINDOWS\System32\P2P Networking <- folder
C:\WINDOWS\System32\uvtqaxhq.exe <-file
C:\WINDOWS\System32\tpsaqfgv.exe <-file
c:\program files\WebsavingsFromEbates <- folder

Reboot to normal windows, visit windows update, install all updates listed including sp1; there are many for both windows and internet explorer.

That should take care of most of the baddies but I do have a couple questions..


Is globalcomputer.com your homepage?

Can you go to c:\windows\system32\zzb.exe, right click the file> properties> and tell me whatever info you get from the properties box please?
Also for this one unless you can tell me...
c:\program files\ares\ares.exe <-this file

I am particularly interested in who made them and date created..(when installed on your computer)

Can you also post a fresh log too please?

Thanks!
_________________________________


I never give up!


0

Response Number 13
Name: Sucumba
Date: February 28, 2004 at 14:09:04 Pacific
Reply:

Hi,I think I solved the problem,it seems that my pc had a CWS.Googlemsn.
I used the Hijackthis, the Cwssrhedder and also i deleted the file winres.dll, which i think was the file that install the problem everytime the pc was reboot, then i had also a file call svshost similar to svchost , but the first is a kind of hj or similar,
well ty for the help and suggestions
bye

sorry for my poor english
jp..


0

Response Number 14
Name: blender
Date: February 29, 2004 at 18:23:32 Pacific
Reply:

JP

Hi..Glad you got it fixed up.
You are right the file winres.dll is one of the CWS varients.
The file svshost is a result of a virus. You may want to do an online scan or make sure your own antivirus is up to date and run a scan with it.
If you had the googlems cws hijack; you might want to check to see if your windows media player works ok. Sometimes the hijacker will replace the windows media player with its trojan.
If you find your windows media player does not work...you can re-instal it here:

For windows 95/me/nt4/2000/xp:

http://www.microsoft.com/windows/windowsmedia/9series/player.aspx

Make sure you check for updates when done installing it...there has been updates since media player 9 came out.

For windows 98 gold:

http://www.microsoft.com/windows/windowsmedia/software/playerV7.aspx

Online scans:

Housecall

Pandascan

Rav Antivirus

Turn off your own antivirus to run any of those scans.
If they report clean as well as your own...you are ok.

Good luck
_____________________________________

I never give up!

Windows Update


0

Sponsored Link
Ads by Google
Reply to Message Icon

bridge.dll/system 32 Trojan found



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Browser hpage favorits highjacked

Browser Hijacked Please HELP ! www.computing.net/answers/security/browser-hijacked-please-help-/23699.html

Google Redirect, I tried everything..Help! www.computing.net/answers/security/google-redirect-i-tried-everythinghelp/26684.html

Browser homepage highjacked www.computing.net/answers/security/browser-homepage-highjacked/9864.html