Options

xhalo79 HomeSearchAssistant - she turned me into a newt!

Hi SVT team,
I too was a victim of HSA as well as Search Extender. I would really appreciate you guys taking a look at the HJT log below. Thanks in advance!

Logfile of HijackThis v1.98.2
Scan saved at 7:59:59 PM, on 12/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\RioMSC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ahead\InCD\InCD.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\uneng.exe:cxzbx
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\addca32.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\tibs3.exe
C:\Documents and Settings\Mike\My Documents\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ytwiz.dll/sp.html#52080
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ytwiz.dll/sp.html#52080
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ytwiz.dll/sp.html#52080
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ytwiz.dll/sp.html#52080
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ytwiz.dll/sp.html#52080
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ytwiz.dll/sp.html#52080
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ytwiz.dll/sp.html#52080
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {764C03C7-6D1B-884E-0CD9-42B7B8389B58} - C:\WINDOWS\msgh32.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [addca32.exe] C:\WINDOWS\system32\addca32.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O4 - HKLM\..\RunOnce: [cxzbx] C:\WINDOWS\uneng.exe:cxzbx
O4 - HKLM\..\RunOnce: [dehrj] C:\WINDOWS\spupdsvc.log:dehrj
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O15 - Trusted Zone: *.frame.crazywinnings.com

Comments

Sign In or Register to comment.