Options

Please assist with Search hijack, hjt log included - allenn

Please help find the search hijack. I have reviewed my HijackThis log but cannot find the dll's that cause the search results to go to some inhoster search website. Yahoo, MSN, and Google will find what I search for, but when I click on the listed hyperlinks, it takes me to another Search Engine or unrelated web page. I had a 17 hjt entry, but deleted it. I installed a Linksys router and blocked all 85.225.116.98 - 85.255.112.197 entries. This has stopped the ip's from being added back. My current hjt log looks as follows:

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RunDll32.exe

C:\PROGRA~1\mcafee.com\agent\mcagent.exe

C:\Program Files\Microsoft AntiSpyware\gcasServ.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Google\Gmail Notifier\gnotify.exe

C:\Program Files\McAfee.com\VSO\mcvsshld.exe

C:\Program Files\McAfee.com\VSO\oasclnt.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

c:\progra~1\mcafee.com\vso\mcvsescn.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe

P:\DkService.exe

c:\program files\mcafee.com\agent\mcdetect.exe

c:\PROGRA~1\mcafee.com\vso\mcshield.exe

c:\PROGRA~1\mcafee.com\agent\mctskshd.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

P:\Program Files\Dantz\Retrospect 7.0\retrorun.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wdfmgr.exe

C:\Program Files\Executive Software\Undelete\UdServe.exe

C:\WINDOWS\System32\alg.exe

P:\Spyware\HijackThis.exe

C:\Documents and Settings\Edoardo\Desktop\Antivirus - Spyware\HijackThis.exe



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - P:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe

O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe

O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe

O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask

O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe

O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe

O4 - HKLM\..\Run: [DiskeeperSystray] "P:\DkIcon.exe"

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Lotus QuickStart.lnk = P:\lotus\wordpro\ltsstart.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128722647304

O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab

O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4664/mcfscan.cab

O23 - Service: Diskeeper - Diskeeper Corporation - P:\DkService.exe

O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe

O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe

O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Dantz - P:\Program Files\Dantz\Retrospect 7.0\retrorun.exe

O23 - Service: Executive Software Undelete (UndeleteService) - Executive Software International - C:\Program Files\Executive Software\Undelete\UdServe.exe

Thanks in advance for helping me with this search hijack!

Comments

  • skywalker45skywalker45 Bloomington, IN. USA
    edited February 2006
    There is nothing jumping out of your log that seems out of place. One question though. The 06 entry:

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    The only reasons I know for this to be present are listed below.
      1. You set the restrictions on purpose. 2. You used an anti-spyware program like Spybot S&D's Home Page and Option Lock down features in the Immunize section of Spybot. 3. Your workplace administrator or network administrator set the restrictions.

    Do any of these apply and also could you explain in further detail where your search is being redirected (do they seem to be a common spot, web page, etc.) as well as the contents of the 017 entry if you can remember.

    Also the top 2 lines of your Hijack This log are issing. Could you please post another log with the full header please. Thanks.
  • edited February 2006
    There is nothing jumping out of your log that seems out of place. One question though. The 06 entry:

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    The only reasons I know for this to be present are listed below.
      1. You set the restrictions on purpose. 2. You used an anti-spyware program like Spybot S&D's Home Page and Option Lock down features in the Immunize section of Spybot. 3. Your workplace administrator or network administrator set the restrictions.

    Do any of these apply and also could you explain in further detail where your search is being redirected (do they seem to be a common spot, web page, etc.) as well as the contents of the 017 entry if you can remember.

    Also the top 2 lines of your Hijack This log are issing. Could you please post another log with the full header please. Thanks.

    Thanks for the reply. Here's the hjt log prior to the 17 delete:
    Logfile of HijackThis v1.99.1

    Scan saved at 10:19:09 AM, on 2/9/2006

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\csrss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\RunDll32.exe

    C:\PROGRA~1\mcafee.com\agent\mcagent.exe

    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Google\Gmail Notifier\gnotify.exe

    C:\Program Files\McAfee.com\VSO\mcvsshld.exe

    C:\Program Files\McAfee.com\VSO\oasclnt.exe

    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    c:\progra~1\mcafee.com\vso\mcvsescn.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe

    P:\DkService.exe

    c:\program files\mcafee.com\agent\mcdetect.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

    P:\Program Files\Dantz\Retrospect 7.0\retrorun.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\wdfmgr.exe

    C:\Program Files\Executive Software\Undelete\UdServe.exe

    C:\WINDOWS\System32\alg.exe

    P:\Spyware\HijackThis.exe

    C:\Documents and Settings\Edoardo\Desktop\Antivirus - Spyware\HijackThis.exe



    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - P:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll

    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe

    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe

    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask

    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe

    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe

    O4 - HKLM\..\Run: [DiskeeperSystray] "P:\DkIcon.exe"

    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Lotus QuickStart.lnk = P:\lotus\wordpro\ltsstart.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128722647304

    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4664/mcfscan.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{DE508614-8368-4840-A2DF-B406CA22336B}: NameServer = 85.255.116.98 85.255.112.197

    O23 - Service: Diskeeper - Diskeeper Corporation - P:\DkService.exe

    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe

    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe

    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

    O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Dantz - P:\Program Files\Dantz\Retrospect 7.0\retrorun.exe

    O23 - Service: Executive Software Undelete (UndeleteService) - Executive Software International - C:\Program Files\Executive Software\Undelete\UdServe.exe

    ***End of hjt Log***

    I do not know why the 06 entry is present in the hjt log. I did run Spybot S&D, but I did not set anything for the Control Panel that I know of.
  • SpywareShooterSpywareShooter 127.0.0.1
    edited February 2006
    I don't see any malicious executables in your log, but your Internet is being redirected into Ukraine.

    O17 - HKLM\System\CCS\Services\Tcpip\..\{DE508614-8368-4840-A2DF-B406CA22336B}: NameServer = 85.255.116.98 85.255.112.197

    Fix that entry then reboot your computer and post a new log.
  • edited February 2006
    I don't see any malicious executables in your log, but your Internet is being redirected into Ukraine.

    O17 - HKLM\System\CCS\Services\Tcpip\..\{DE508614-8368-4840-A2DF-B406CA22336B}: NameServer = 85.255.116.98 85.255.112.197

    Fix that entry then reboot your computer and post a new log.


    Thanks again for the reply. Here's the latest hjt log minus the 17 entry.
    Logfile of HijackThis v1.99.1

    Scan saved at 11:06:22 PM, on 2/11/2006

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\csrss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\RunDll32.exe

    C:\PROGRA~1\mcafee.com\agent\mcagent.exe

    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Google\Gmail Notifier\gnotify.exe

    C:\Program Files\McAfee.com\VSO\mcvsshld.exe

    C:\Program Files\McAfee.com\VSO\oasclnt.exe

    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    c:\progra~1\mcafee.com\vso\mcvsescn.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe

    P:\DkService.exe

    c:\program files\mcafee.com\agent\mcdetect.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

    P:\Program Files\Dantz\Retrospect 7.0\retrorun.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\wdfmgr.exe

    C:\Program Files\Executive Software\Undelete\UdServe.exe

    C:\WINDOWS\System32\alg.exe

    C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE

    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE

    P:\HiJackThis\HijackThis.exe



    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - P:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll

    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe

    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe

    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask

    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe

    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe

    O4 - HKLM\..\Run: [DiskeeperSystray] "P:\DkIcon.exe"

    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Lotus QuickStart.lnk = P:\lotus\wordpro\ltsstart.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab

    O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,9/McUpdatePortal.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128722647304

    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4664/mcfscan.cab

    O23 - Service: Diskeeper - Diskeeper Corporation - P:\DkService.exe

    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe

    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe

    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

    O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Dantz - P:\Program Files\Dantz\Retrospect 7.0\retrorun.exe

    O23 - Service: Executive Software Undelete (UndeleteService) - Executive Software International - C:\Program Files\Executive Software\Undelete\UdServe.exe

    What is the 04 entry highlighted in red above? I removed this entry, but it returns.
  • skywalker45skywalker45 Bloomington, IN. USA
    edited February 2006
    ctfmon.exe is a legitimate MS file. It monitors text input and speech and handwriting recognition, blah, blah. You'll almost always find it in the running processes of any log but I admit it's a little strange to find it as an 04 entry. The reason you can't fix it is because it's a protected operating system file. I'll look over your log and do some more research. I see also that SpywareShooter is on the case here as well. That's a good thing. Are you still having the annoying redirects? Also let us know of any other symptoms you're having.
  • edited February 2006
    ctfmon.exe is a legitimate MS file. It monitors text input and speech and handwriting recognition, blah, blah. You'll almost always find it in the running processes of any log but I admit it's a little strange to find it as an 04 entry. The reason you can't fix it is because it's a protected operating system file. I'll look over your log and do some more research. I see also that SpywareShooter is on the case here as well. That's a good thing. Are you still having the annoying redirects? Also let us know of any other symptoms you're having.

    I appreciate yu'all looking into this problem.

    All searches are hijacked i.e. MSN, Yahoo, and Google; but not until you click on a link in the search engine list. Example: you do a Web search for "hijack searches". The search engine returns a list of links that matches the search criteria. When you click one of the links, you end up at another search website or some unrelated website.

    I installed a Linksys router and blocked the 85.255.... ip addresses, so the 17 entry has not re-appeared.

    Do you think a Win XP Pro repair install would fix the problem?
  • SpywareShooterSpywareShooter 127.0.0.1
    edited February 2006
    Please upload a .zip archive of your HOSTS file. Navigate to the folder C:\WINDOWS\system32\drivers\etc in your browser, right click, and go to New»WinRAR Zip Archive", or "New»Compressed Folder". Drag and drop the file HOSTS (the one with no file extension) into the folder and attach it to your post.
  • edited February 2006
    Here is the Hosts file:

    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host

    127.0.0.1 localhost

    ***** End Hosts File ******

    Also, unchecked "Enable LMHOSTS lookup" in Wins Network Configuration.

    I looked at my other PC's and none of them have an entry in the registry like this for CurrentUser O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe.
Sign In or Register to comment.