HickJack This log for super Hero Spyware people

I recently had Home search spyware and cleaned it all up, all seemed to be working until i tried to log onto my hotmail account - it logs me on then stays as a blank page with the security saying done.

I figure somewhere im restricted to viewing this from the home search.

I have used cw shredder, cleaned out all my old temp internet files and cookies using EClean_2. Have done a hot shut down of pc (pull the plug) - ran everything i can find. adware and spybot (all lastest definations -

so am left with this log - does anybody have any suggestions?

Many thanks in advance

HairySlug

Logfile of HijackThis v1.98.2
Scan saved at 23:14:42, on 08/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\AOL 8.0\aoltray.exe
C:\Program Files\Mustek 1200 UB Plus\Driver\WATCH.exe
C:\WINDOWS\System32\LVComS.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\AOL 8.0\waol.exe
C:\Program Files\AOL 8.0\shellmon.exe
C:\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.packardbell.co.uk/center
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Watch.lnk = C:\Program Files\Mustek 1200 UB Plus\Driver\WATCH.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.co.uk/center
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1098224379646
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

Comments

  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited December 2004
    There's nothing bad in your log. Try this.

    Download Hoster.

    http://members.aol.com/toadbee/hoster.zip

    This will restore your original Host files.
    Run the program and press Restore Original Hosts and press OK.
  • edited December 2004
    I have tried this and no results...

    still just get a blank page when opening hotmail.

    Any other suggestions are more than welcome

    Or any other places where i can log a question?

    Thanks in Advance Hairy
  • edited December 2004
    Just had a browse around the site for further info found these links

    http://www.short-media.com/forum/showthread.php?t=19305&highlight=open+hotmail

    http://www.short-media.com/forum/showthread.php?t=21290&highlight=open+hotmail

    http://www.short-media.com/forum/showthread.php?t=20466&highlight=open+hotmail

    the conlcusion seems to be to use another browser or do reinstall of ie6 or download sp2 for windows.

    I think i will go for the last option. Does anybody know where i can download a copy of sp2 and then bring it home to install via flash memory stick, as i am on a dial up connection and 60mb is a bit to optomisitic for a traditional modem..... :)

    Thanks again for all you help. Also going to install firefox browser.....time to distance myself from good old bill gates.......:)

    HairySlug
  • SpywareShooterSpywareShooter 127.0.0.1
    edited December 2004
    I wouldn't reccomend getting SP2. Microsoft uses it to spy on people's Internet activites. You can also fix it by enabling Meta Refresh in Internet Explorer (if you really want to use IE). This works in most cases.

    Open IE and go to Tools»Internet Options»Internet»Custom Level and make sure Meta Refresh is enabled.
  • edited December 2004
    I wouldn't reccomend getting SP2. Microsoft uses it to spy on people's Internet activites. You can also fix it by enabling Meta Refresh in Internet Explorer (if you really want to use IE). This works in most cases.

    Open IE and go to Tools»Internet Options»Internet»Custom Level and make sure Meta Refresh is enabled.


    meta refresh is enables then guess that means that its a reinstall of ie / change of web browser or install sp2.

    Thanks for all you help.

    Hairy
  • SpywareShooterSpywareShooter 127.0.0.1
    edited December 2004
    Try this:

    Tools»Internet Options»Programs»Reset Web Settings
  • edited December 2004
    no success there will use firefox instead seems like a nice program

    Thanks for everyones help
This discussion has been closed.