Computing.Net > Forums > Windows 2000 > hijacked browser

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

hijacked browser

Reply to Message Icon

Name: Bryan
Date: September 5, 2003 at 14:32:16 Pacific
OS: Windows 2000 Professional
CPU/Ram: 130mb
Comment:

My browser keeps getting hijacked to offensive URLs. I have run Spybot S&D and Ad-Aware, and also run Hijackthis and removed the potential problems I noticed. But, it keeps happening. Pleeeze help! Thanks

Here is the latest logfile (after removal of known problems):

Logfile of HijackThis v1.96.4
Scan saved at 5:06:51 PM, on 9/5/2003
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\PROGRA~1\CISCOS~1\VPNCLI~1\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\ati2plab.exe
C:\WINNT\CPQDIAG\CPQDFWAG.exe
C:\Program Files\NavNT\defwatch.exe
C:\PROGRA~1\Compaq\COMPAQ~3\hibserv.exe
c:\winnt\k9nt.exe
C:\WINNT\LogWatNT.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\Promon.exe
C:\WINNT\System32\ltmsg.exe
C:\WINNT\System32\Atiptaxx.exe
C:\Program Files\Compaq\HotKey Software\hkss.exe
C:\Program Files\Compaq\EasyAccessButtons\cpqek.exe
C:\PROGRA~1\Compaq\Security\Secure32.exe
C:\Program Files\Compaq\PowerCon Enhancements\CPQAcDc.exe
C:\WINNT\System32\PRPCUI.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\winnt\winlogon.exe
C:\Program Files\Microsoft Office\Office\OSA.exe
C:\Program Files\Microsoft Office\Office\MSOFFICE.exe
C:\Program Files\Iomega\Tools\IMGICON.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\bmccann\LOCALS~1\Temp\HijackThis.exe

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [hkss] C:\Program Files\Compaq\HotKey Software\hkss.exe
O4 - HKLM\..\Run: [cpqek] C:\Program Files\Compaq\EasyAccessButtons\cpqek.exe
O4 - HKLM\..\Run: [Compaq Computer Security] C:\PROGRA~1\Compaq\Security\Secure32.exe
O4 - HKLM\..\Run: [CPQAcDc] C:\Program Files\Compaq\PowerCon Enhancements\CPQAcDc.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [winlogon] c:\winnt\winlogon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.exe
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.exe
O4 - Global Startup: Iomega Backup Scheduler.lnk = C:\Program Files\Iomega\Iomega Backup\dtiom98.exe
O4 - Global Startup: Iomega Icons.lnk = C:\Program Files\Iomega\Tools\IMGICON.exe
O4 - Global Startup: Iomega Startup Options.lnk = C:\Program Files\Iomega\Tools\IMGSTART.exe
O4 - Global Startup: QuikSync.lnk = C:\Program Files\Iomega\QuikSync\QUIKSYNC.exe
O4 - Global Startup: IomegaWare.lnk = C:\Program Files\Iomega\Iomegaware\COMMANDER.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A6D037B-8C31-4547-AC67-3FA901B30504}: NameServer = 167.206.112.99,167.206.7.4




Sponsored Link
Ads by Google

Response Number 1
Name: Spinal
Date: September 5, 2003 at 14:43:29 Pacific
Reply:

Try a good virus scan off the net. I recommend norton. The site is www.symantec.com they have a free virus scan online. Good luck spinal.


0

Response Number 2
Name: Bryan
Date: September 5, 2003 at 15:07:54 Pacific
Reply:

Thanks Spinal. I already have Norton running, and I just updated it again, this morning. No virus found. Funny, I was actually hoping to have a virus. It might have been easier to fix.


0

Response Number 3
Name: Spinal
Date: September 5, 2003 at 17:24:29 Pacific
Reply:

I had a similar prob about a year ago, but it was (fortunately???) a virus... i got it out without oo many problems with norton. I found that most virus hijackin triggers are in the search button on IE. All I can reccomend from reading ur post is to get a couple of more service packs (being VERY carefull of teh infinite reboot bug in service pack 4). Sory, maybe some1 else might be able to help,
Spinal


0

Response Number 4
Name: Analyst
Date: September 6, 2003 at 15:08:18 Pacific
Reply:

Manually delete all your Temporary Internet Files and Temp files. Script files hide here that are not always removed by disk cleanup.

C:\Documents And Setting\(profile_name)\Local Settings\Temporary Internet Files\

and

C:\Documents And Setting\\Local Settings\Temp\

and

C:\WINNT\TEMP\

Delete ALL files in these folder, then reboot and see what happens.


0

Response Number 5
Name: Methix
Date: September 25, 2003 at 14:55:15 Pacific
Reply:

I have seen this exact situation at a customer site. Generally it is not a virus, but a similar type of program called malware. The definition of a virus is a program that self-propagates. Malware can have similar behavior, but it instead spreads usually through cookies or programs that are inadvertantly downloaded to the machine. I would suggest going to www.lavasoftusa.com and download the free version of ad-aware 6.0 This is a tool that will scan your machine for malware and clean it.


0

Related Posts

See More



Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 2000 Forum Home


Sponsored links

Ads by Google


Results for: hijacked browser

Hijacked Browser www.computing.net/answers/windows-2000/hijacked-browser/58369.html

Browser Hijacked - Can't Remove www.computing.net/answers/windows-2000/browser-hijacked-cant-remove/58103.html

Vrape hijack browser www.computing.net/answers/windows-2000/vrape-hijack-browser/50375.html