Member Panel


Sponsors and Ads

Live Tag Cloud

[Fixed] Hijackthis! Logs - [FIXED] - New Log posted in the Security & Safety forums; Hi I have aquired a browser hijacker. It is named cool web search. I have been looking at this forum & have downloaded Hijackthis. This is what i have done ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 05-15-2005
Simon2711's Avatar
Bronze Member
 
Join Date: May 2005
Posts: 5
Simon2711 - See this Members User comments on their Profile page
Default [FIXED] - New Log

Hi

I have aquired a browser hijacker. It is named cool web search. I have been looking at this forum & have downloaded Hijackthis.

This is what i have done so far..

Run spybot adaware & spy subtract. all have recognised the spyware & have deleted it.

When i open IE again the spyware is re-instaled

I have tried CWS shredder which is part of spy subtract. It does not recognise it & say there is no CWS.

I have tried to change my homepage in internet options but it still goes back to 'about blank' which has all these crappy search options.

About blank was on the hijackthis log file. I deleted it tried to load IE again & it came back again.

I'm gussing i have to use regedit but have had no experience in this.

So here is the log file from hijack this. Any help would be very much apreciated.

Simon
Attached Files
File Type: txt Log-1.txt (10.1 KB, 1 views)


  #2  
Old 05-15-2005
Hengis's Avatar
PCHF Founder & Owner
My PC
 
Join Date: Jan 2004
Location: Berkshire, England
Posts: 10,856
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default Re: New Log

Hi Simon, welcome to PCHF

Make a system restore point - then put a tick next to the following log entries and select fix.

C:\WINDOWS\ntku32.exe
C:\WINDOWS\system32\sysia32.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\damci.dll/sp.html#44768
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\damci.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\damci.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\damci.dll/sp.html#44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\damci.dll/sp.html#44768
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\damci.dll/sp.html#44768
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\damci.dll/sp.html#44768
O2 - BHO: Class - {41F3D01F-6C89-A15F-70E9-32BE0CB61C71} - C:\WINDOWS\system32\ntyo32.dll
O4 - HKLM\..\Run: [ntku32.exe] C:\WINDOWS\ntku32.exe
O4 - HKLM\..\RunOnce: [ntmd32.exe] C:\WINDOWS\system32\ntmd32.exe
O4 - HKLM\..\RunOnce: [sysia32.exe] C:\WINDOWS\system32\sysia32.exe
O23 - Service: Network Security Service (NSS) ( 11F??#????`I) - Unknown owner - C:\WINDOWS\sdkmc32.exe

Before re-booting re-run: Ad-aware, Spybot and CWS.

Re-boot and let us know how you get on.


__________________
> Pre-Work > System File Checker
> Did we help you? If we did, please consider A Donation
  #3  
Old 05-15-2005
Simon2711's Avatar
Bronze Member
 
Join Date: May 2005
Posts: 5
Simon2711 - See this Members User comments on their Profile page
Default Re: New Log

Hi Hengis

Thank you for the swift reply.

i deleted the r1 etc, but i couldnt delete the C: extensions.

When i re-booted my spyware program stated that an attempt to change IE's hompage. This happened 9 time. This is a sticky fella aye. Got me pulling my hair out.

Do i have to explore the C: drive to delete the C: extensions?

Attached is the new log file.

Regards

Simon
Attached Files
File Type: txt Log-2.txt (9.2 KB, 3 views)


  #4  
Old 05-16-2005
Zimbo's Avatar
Friend of PCHF
 
Join Date: Sep 2004
Location: Right here !
Posts: 2,150
Zimbo - See this Members User comments on their Profile page
Default Re: New Log

Originally Posted by Simon2711
When i re-booted my spyware program stated that an attempt to change IE's hompage. This happened 9 time.
Could you install Microsoft Antispyware this should help to prevent anything trying to change the homepage.
Also run Stinger, this program should remove any trojans which are normally associated with these "Toolbars"

Next your log file, you can delete the following entries:

O4 - HKLM\..\RunOnce: [d3xs.exe] C:\WINDOWS\d3xs.exe
O4 - HKLM\..\RunOnce: [sdkmc32.exe] C:\WINDOWS\sdkmc32.exe
O4 - HKLM\..\Run: [ntku32.exe] C:\WINDOWS\ntku32.exe
O23 - Service: Network Security Service (NSS) ( 11F??#????`I) - Unknown owner - C:\WINDOWS\sdkmc32.exe

Once you have deleted those entries from HijackThis and installed both Stinger and Microsoft Antispyware, boot your machine into safe-mode and run spybot,stinger and ms antispy.

Let us know how you get on.

It would be a good idea to explore C and delete those files. (just use normal windows explorer)


  #5  
Old 05-17-2005
Simon2711's Avatar
Bronze Member
 
Join Date: May 2005
Posts: 5
Simon2711 - See this Members User comments on their Profile page
Default Re: New Log

Hi Zimbo.

Looks like it's pretty much sorted. Thank you to you & Hengis

I keep getting 7 spywares that Adaware finds. These are classed as low risk but this dosnt instil confidence.

Worth showing you guys another log?

Thanks for the help again.

Simon


  #6  
Old 05-17-2005
Hengis's Avatar
PCHF Founder & Owner
My PC
 
Join Date: Jan 2004
Location: Berkshire, England
Posts: 10,856
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default Re: New Log

Happy to help Simon

Post a new log if u like - sounds like we got it tho

Don't forget to Recommend a Friend


__________________
> Pre-Work > System File Checker
> Did we help you? If we did, please consider A Donation

Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 12:28 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top