Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
This is my logfile from hijackthis:
Logfile of HijackThis v1.97.7
Scan saved at 17:26:04, on 01.12.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\SOUNDMAN.exe
C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programfiler\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Programfiler\QuickTime\qttask.exe
C:\Programfiler\Java\j2re1.4.2_04\bin\jusched.exe
C:\Programfiler\D-Tools\daemon.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe
C:\Programfiler\Norton AntiVirus\navapsvc.exe
C:\Programfiler\Microsoft Office\Office\1044\msoffice.exe
C:\Programfiler\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Programfiler\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe
C:\Programfiler\Fellesfiler\Symantec Shared\Security Center\SymWSC.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.exe
C:\Programfiler\Internet Explorer\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
C:\Documents and Settings\Tor Johan Norheim\Diverse Installasjoner\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.sppgawdbzy.com/RibZayNj1TRv8KpGlnIY5nWWGV_j55iUk/LEcSKjvTxQv1wCAm09ggBjM0pbooDY.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wghrbgljgsdcdjijbxdnbzg.info/RibZayNj1TQmrgMrzm3HafqS/g1_Z8RItBqJ2iuPwVc.asp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.2.3:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {23413104-F3B5-5123-0478-62E1249A2E3B} - C:\DOCUME~1\TORJOH~1\PROGRA~1\JOYUP~1\Bin tray.exe
O2 - BHO: (no name) - {39B754F4-D021-6681-3DD3-B64D35245013} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programfiler\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programfiler\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programfiler\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programfiler\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programfiler\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [websx] C:\Programfiler\websx\int339890.exe -auto
O4 - HKLM\..\Run: [TkBellExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [defy ooze ford heart] C:\Documents and Settings\All Users\Programdata\trust bin defy ooze\01iso.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [FlawProgram] C:\DOCUME~1\TORJOH~1\PROGRA~1\ONCEAD~1\skip 1.exeO4 - Global Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/no/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37952.3034027778
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
My problem is an annoying toolbar at the bottom of the screen. It's called "Search Now!", and in properties, the url is called; http://searchweb2.com/passthrough/newpass2.htmlAnyone who can help me get rid of this thing? Please. I hate this thing.

hey man wazup..the problem u have now,,i used to have the same thing, the toolbar comes as soon as you open internet widnows right?..so what i did is i download trojan hunter 4 and MaCfee anitvirus v8, i scan my computer using both program,one of these program removed that toolbar.and i used to have norton too but it never detect that toolbar. so i think you should try MaCfee or trojan hunter. good luck man. hope it works for you
wazup

This from another forum:
The Searchweb2.com tool bar is an add on that comes with Yahoo Messanger Plus!. It is spyware added when you install messanger plus and have clicked to allow the other componets to install at the same time. To remove it just just do Add/Remove and remove messanger plus.
Give a man a fish and you feed him for a day;
Teach a man to fish and you feed him for a lifetime;
Then industry pollutes the water and kills all the fish.

Paste your HJT log here, you will learn how to fix things yourself. Doing this will improve your self esteem...
Ignis vulpes impero

I will now attempt to improve mine...
Here's the url.
http://hijackthis.de/index.php?langselect=english
Ignis vulpes impero

-It must be a variant, sometimes these come in different flavors
Give a man a fish and you feed him for a day;
Teach a man to fish and you feed him for a lifetime;
Then industry pollutes the water and kills all the fish.

Hey!
I too, have a problem with the toolbar! I went to the website and tried to download the unistaller, however, it says "the security settings wont allow this"...I really dont understand, as I lowered the security settings to try and fix this problem! HELP!
~Leigh

![]() |
Problem with Isass.exe
|
Matrox Monitor
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |