Hijacked Browser (Go Away, Google!)--Hijack This Log Included

  1. #1
    homeuzr is offline Newbie

    Unhappy Hijacked Browser (Go Away, Google!)--Hijack This Log Included

    Hi. I ran across your website last weekend while I was online searching for information about this relatively new browser hijacker that has invaded my Internet Explorer. I saw that you helped someone else with this problem and am hoping you might help me too (PLEASE!).

    I recently moved from dial-up service to high-speed internet and am confounded by the increase in potential threats! I've downloaded Spyware Search & Destroy, Ad-aware, and Hijack This...so far. I'm ready to load a firewall, but (for some reason) want to get this browswer thing fixed first?

    I'm pretty technically capable, but definitely not a techie--please be easy on me! I follow instructions reallly well, but work best with detail.

    Thanks in advance!!!!!

    Here's the log from my Hijack This scan tonight:

    Logfile of HijackThis v1.99.1
    Scan saved at 10:27:43 PM, on 3/21/2005
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\SSDPSRV.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
    C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
    C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\HPZTSB04.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\HPHMON03.EXE
    C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\PHOTOSMART\PHOTO IMAGING\HPI_MONITOR.EXE
    C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\PHOTOSMART\HP SHARE-TO-WEB\HPGS2WND.EXE
    C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
    C:\PROGRAM FILES\ISP50\BIN\BARTSHEL.EXE
    C:\WINDOWS\SYSTEM\SCRSVC.EXE
    C:\WINDOWS\SYSTEM\BOOTPD.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\PHOTOSMART\HP SHARE-TO-WEB\HPGS2WNF.EXE
    C:\WINDOWS\SYSTEM\BOOTPD.EXE
    C:\WINDOWS\RunDLL.exe
    C:\WINDOWS\RUNDLL32.EXE
    C:\HPDESK\HPPDDIR.EXE
    C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
    C:\WINDOWS\SYSTEM\HPHIPM09.EXE
    C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
    C:\PROGRAM FILES\ISP50\BIN\PPSHARED.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\PROGRAM FILES\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wowway.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msnmember.msn.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://my.lycos.com
    O1 - Hosts: 66.180.173.39 www.google.ae
    O1 - Hosts: 66.180.173.39 www.google.am
    O1 - Hosts: 66.180.173.39 www.google.as
    O1 - Hosts: 66.180.173.39 www.google.at
    O1 - Hosts: 66.180.173.39 www.google.az
    O1 - Hosts: 66.180.173.39 www.google.be
    O1 - Hosts: 66.180.173.39 www.google.bi
    O1 - Hosts: 66.180.173.39 www.google.ca
    O1 - Hosts: 66.180.173.39 www.google.cd
    O1 - Hosts: 66.180.173.39 www.google.cg
    O1 - Hosts: 66.180.173.39 www.google.ch
    O1 - Hosts: 66.180.173.39 www.google.ci
    O1 - Hosts: 66.180.173.39 www.google.cl
    O1 - Hosts: 66.180.173.39 www.google.co.cr
    O1 - Hosts: 66.180.173.39 www.google.co.hu
    O1 - Hosts: 66.180.173.39 www.google.co.il
    O1 - Hosts: 66.180.173.39 www.google.co.in
    O1 - Hosts: 66.180.173.39 www.google.co.je
    O1 - Hosts: 66.180.173.39 www.google.co.jp
    O1 - Hosts: 66.180.173.39 www.google.co.ke
    O1 - Hosts: 66.180.173.39 www.google.co.kr
    O1 - Hosts: 66.180.173.39 www.google.co.ls
    O1 - Hosts: 66.180.173.39 www.google.co.nz
    O1 - Hosts: 66.180.173.39 www.google.co.th
    O1 - Hosts: 66.180.173.39 www.google.co.ug
    O1 - Hosts: 66.180.173.39 www.google.co.uk
    O1 - Hosts: 66.180.173.39 www.google.co.ve
    O1 - Hosts: 66.180.173.39 www.google.com
    O1 - Hosts: 66.180.173.39 www.google.com.ag
    O1 - Hosts: 66.180.173.39 www.google.com.ar
    O1 - Hosts: 66.180.173.39 www.google.com.au
    O1 - Hosts: 66.180.173.39 www.google.com.br
    O1 - Hosts: 66.180.173.39 www.google.com.co
    O1 - Hosts: 66.180.173.39 www.google.com.cu
    O1 - Hosts: 66.180.173.39 www.google.com.do
    O1 - Hosts: 66.180.173.39 www.google.com.ec
    O1 - Hosts: 66.180.173.39 www.google.com.fj
    O1 - Hosts: 66.180.173.39 www.google.com.gi
    O1 - Hosts: 66.180.173.39 www.google.com.gr
    O1 - Hosts: 66.180.173.39 www.google.com.gt
    O1 - Hosts: 66.180.173.39 www.google.com.hk
    O1 - Hosts: 66.180.173.39 www.google.com.ly
    O1 - Hosts: 66.180.173.39 www.google.com.mt
    O1 - Hosts: 66.180.173.39 www.google.com.mx
    O1 - Hosts: 66.180.173.39 www.google.com.my
    O1 - Hosts: 66.180.173.39 www.google.com.na
    O1 - Hosts: 66.180.173.39 www.google.com.nf
    O1 - Hosts: 66.180.173.39 www.google.com.ni
    O1 - Hosts: 66.180.173.39 www.google.com.np
    O1 - Hosts: 66.180.173.39 www.google.com.pa
    O1 - Hosts: 66.180.173.39 www.google.com.pe
    O1 - Hosts: 66.180.173.39 www.google.com.ph
    O1 - Hosts: 66.180.173.39 www.google.com.pk
    O1 - Hosts: 66.180.173.39 www.google.com.pr
    O1 - Hosts: 66.180.173.39 www.google.com.py
    O1 - Hosts: 66.180.173.39 www.google.com.sa
    O1 - Hosts: 66.180.173.39 www.google.com.sg
    O1 - Hosts: 66.180.173.39 www.google.com.sv
    O1 - Hosts: 66.180.173.39 www.google.com.tr
    O1 - Hosts: 66.180.173.39 www.google.com.tw
    O1 - Hosts: 66.180.173.39 www.google.com.ua
    O1 - Hosts: 66.180.173.39 www.google.com.uy
    O1 - Hosts: 66.180.173.39 www.google.com.vc
    O1 - Hosts: 66.180.173.39 www.google.com.vn
    O1 - Hosts: 66.180.173.39 www.google.de
    O1 - Hosts: 66.180.173.39 www.google.dj
    O1 - Hosts: 66.180.173.39 www.google.dk
    O1 - Hosts: 66.180.173.39 www.google.es
    O1 - Hosts: 66.180.173.39 www.google.fi
    O1 - Hosts: 66.180.173.39 www.google.fm
    O1 - Hosts: 66.180.173.39 www.google.fr
    O1 - Hosts: 66.180.173.39 www.google.gg
    O1 - Hosts: 66.180.173.39 www.google.gl
    O1 - Hosts: 66.180.173.39 www.google.gm
    O1 - Hosts: 66.180.173.39 www.google.hn
    O1 - Hosts: 66.180.173.39 www.google.ie
    O1 - Hosts: 66.180.173.39 www.google.it
    O1 - Hosts: 66.180.173.39 www.google.kz
    O1 - Hosts: 66.180.173.39 www.google.li
    O1 - Hosts: 66.180.173.39 www.google.lt
    O1 - Hosts: 66.180.173.39 www.google.lu
    O1 - Hosts: 66.180.173.39 www.google.lv
    O1 - Hosts: 66.180.173.39 www.google.mn
    O1 - Hosts: 66.180.173.39 www.google.ms
    O1 - Hosts: 66.180.173.39 www.google.mu
    O1 - Hosts: 66.180.173.39 www.google.mw
    O1 - Hosts: 66.180.173.39 www.google.nl
    O1 - Hosts: 66.180.173.39 www.google.no
    O1 - Hosts: 66.180.173.39 www.google.off.ai
    O1 - Hosts: 66.180.173.39 www.google.pl
    O1 - Hosts: 66.180.173.39 www.google.pn
    O1 - Hosts: 66.180.173.39 www.google.pt
    O1 - Hosts: 66.180.173.39 www.google.ro
    O1 - Hosts: 66.180.173.39 www.google.ru
    O1 - Hosts: 66.180.173.39 www.google.rw
    O1 - Hosts: 66.180.173.39 www.google.se
    O1 - Hosts: 66.180.173.39 www.google.sh
    O1 - Hosts: 66.180.173.39 www.google.sk
    O1 - Hosts: 66.180.173.39 www.google.sm
    O1 - Hosts: 66.180.173.39 www.google.td
    O1 - Hosts: 66.180.173.39 www.google.tm
    O2 - BHO: PeoplePC FixedBandBHO - {3DE88907-3E38-11D4-BEB2-CBE76C0598DD} - C:\PROGRAM FILES\ISP50\BIN\BANDOBJECT.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {5483427F-93B8-1470-5A89-E6B56484CDB2} - C:\WINDOWS\TEMP\qlgcqjjkltg.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\PROGRA~1\Google\GoogleToolbar1.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\PROGRA~1\Google\GoogleToolbar1.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
    O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
    O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb04.exe
    O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\SYSTEM\HPHMON03.EXE
    O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
    O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
    O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP50\hta\station.sbrt
    O4 - HKLM\..\Run: [scrsvc] C:\WINDOWS\SYSTEM\SCRSVC.EXE
    O4 - HKLM\..\Run: [bootpd.exe] C:\WINDOWS\SYSTEM\BOOTPD.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
    O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
    O4 - HKLM\..\RunOnce: [AAW] "C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PERSONAL\AD-AWARE.EXE" "+b1"
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
    O4 - HKCU\..\Run: [OfotoNow USB Detection] C:\WINDOWS\RunDLL32.exe C:\PROGRA~1\OFOTO\OFOTONOW\OFUSBS.DLL,WatchForConn ection OfotoNow
    O4 - Startup: Document Assistant.lnk = C:\HPDESK\HPPDDIR.exe
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://msnmember.msn.com
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/...2/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/...16/mcgdmgr.cab[/SIZE]


  2. #2
    owen is offline D-A-L Team Member (UK)
    Close all browser windows, restart Hijack This and put a checkmark next to the following entries:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://my.lycos.com
    O1 - Hosts: 66.180.173.39 www.google.ae
    O1 - Hosts: 66.180.173.39 www.google.am
    O1 - Hosts: 66.180.173.39 www.google.as
    O1 - Hosts: 66.180.173.39 www.google.at
    O1 - Hosts: 66.180.173.39 www.google.az
    O1 - Hosts: 66.180.173.39 www.google.be
    O1 - Hosts: 66.180.173.39 www.google.bi
    O1 - Hosts: 66.180.173.39 www.google.ca
    O1 - Hosts: 66.180.173.39 www.google.cd
    O1 - Hosts: 66.180.173.39 www.google.cg
    O1 - Hosts: 66.180.173.39 www.google.ch
    O1 - Hosts: 66.180.173.39 www.google.ci
    O1 - Hosts: 66.180.173.39 www.google.cl
    O1 - Hosts: 66.180.173.39 www.google.co.cr
    O1 - Hosts: 66.180.173.39 www.google.co.hu
    O1 - Hosts: 66.180.173.39 www.google.co.il
    O1 - Hosts: 66.180.173.39 www.google.co.in
    O1 - Hosts: 66.180.173.39 www.google.co.je
    O1 - Hosts: 66.180.173.39 www.google.co.jp
    O1 - Hosts: 66.180.173.39 www.google.co.ke
    O1 - Hosts: 66.180.173.39 www.google.co.kr
    O1 - Hosts: 66.180.173.39 www.google.co.ls
    O1 - Hosts: 66.180.173.39 www.google.co.nz
    O1 - Hosts: 66.180.173.39 www.google.co.th
    O1 - Hosts: 66.180.173.39 www.google.co.ug
    O1 - Hosts: 66.180.173.39 www.google.co.uk
    O1 - Hosts: 66.180.173.39 www.google.co.ve
    O1 - Hosts: 66.180.173.39 www.google.com
    O1 - Hosts: 66.180.173.39 www.google.com.ag
    O1 - Hosts: 66.180.173.39 www.google.com.ar
    O1 - Hosts: 66.180.173.39 www.google.com.au
    O1 - Hosts: 66.180.173.39 www.google.com.br
    O1 - Hosts: 66.180.173.39 www.google.com.co
    O1 - Hosts: 66.180.173.39 www.google.com.cu
    O1 - Hosts: 66.180.173.39 www.google.com.do
    O1 - Hosts: 66.180.173.39 www.google.com.ec
    O1 - Hosts: 66.180.173.39 www.google.com.fj
    O1 - Hosts: 66.180.173.39 www.google.com.gi
    O1 - Hosts: 66.180.173.39 www.google.com.gr
    O1 - Hosts: 66.180.173.39 www.google.com.gt
    O1 - Hosts: 66.180.173.39 www.google.com.hk
    O1 - Hosts: 66.180.173.39 www.google.com.ly
    O1 - Hosts: 66.180.173.39 www.google.com.mt
    O1 - Hosts: 66.180.173.39 www.google.com.mx
    O1 - Hosts: 66.180.173.39 www.google.com.my
    O1 - Hosts: 66.180.173.39 www.google.com.na
    O1 - Hosts: 66.180.173.39 www.google.com.nf
    O1 - Hosts: 66.180.173.39 www.google.com.ni
    O1 - Hosts: 66.180.173.39 www.google.com.np
    O1 - Hosts: 66.180.173.39 www.google.com.pa
    O1 - Hosts: 66.180.173.39 www.google.com.pe
    O1 - Hosts: 66.180.173.39 www.google.com.ph
    O1 - Hosts: 66.180.173.39 www.google.com.pk
    O1 - Hosts: 66.180.173.39 www.google.com.pr
    O1 - Hosts: 66.180.173.39 www.google.com.py
    O1 - Hosts: 66.180.173.39 www.google.com.sa
    O1 - Hosts: 66.180.173.39 www.google.com.sg
    O1 - Hosts: 66.180.173.39 www.google.com.sv
    O1 - Hosts: 66.180.173.39 www.google.com.tr
    O1 - Hosts: 66.180.173.39 www.google.com.tw
    O1 - Hosts: 66.180.173.39 www.google.com.ua
    O1 - Hosts: 66.180.173.39 www.google.com.uy
    O1 - Hosts: 66.180.173.39 www.google.com.vc
    O1 - Hosts: 66.180.173.39 www.google.com.vn
    O1 - Hosts: 66.180.173.39 www.google.de
    O1 - Hosts: 66.180.173.39 www.google.dj
    O1 - Hosts: 66.180.173.39 www.google.dk
    O1 - Hosts: 66.180.173.39 www.google.es
    O1 - Hosts: 66.180.173.39 www.google.fi
    O1 - Hosts: 66.180.173.39 www.google.fm
    O1 - Hosts: 66.180.173.39 www.google.fr
    O1 - Hosts: 66.180.173.39 www.google.gg
    O1 - Hosts: 66.180.173.39 www.google.gl
    O1 - Hosts: 66.180.173.39 www.google.gm
    O1 - Hosts: 66.180.173.39 www.google.hn
    O1 - Hosts: 66.180.173.39 www.google.ie
    O1 - Hosts: 66.180.173.39 www.google.it
    O1 - Hosts: 66.180.173.39 www.google.kz
    O1 - Hosts: 66.180.173.39 www.google.li
    O1 - Hosts: 66.180.173.39 www.google.lt
    O1 - Hosts: 66.180.173.39 www.google.lu
    O1 - Hosts: 66.180.173.39 www.google.lv
    O1 - Hosts: 66.180.173.39 www.google.mn
    O1 - Hosts: 66.180.173.39 www.google.ms
    O1 - Hosts: 66.180.173.39 www.google.mu
    O1 - Hosts: 66.180.173.39 www.google.mw
    O1 - Hosts: 66.180.173.39 www.google.nl
    O1 - Hosts: 66.180.173.39 www.google.no
    O1 - Hosts: 66.180.173.39 www.google.off.ai
    O1 - Hosts: 66.180.173.39 www.google.pl
    O1 - Hosts: 66.180.173.39 www.google.pn
    O1 - Hosts: 66.180.173.39 www.google.pt
    O1 - Hosts: 66.180.173.39 www.google.ro
    O1 - Hosts: 66.180.173.39 www.google.ru
    O1 - Hosts: 66.180.173.39 www.google.rw
    O1 - Hosts: 66.180.173.39 www.google.se
    O1 - Hosts: 66.180.173.39 www.google.sh
    O1 - Hosts: 66.180.173.39 www.google.sk
    O1 - Hosts: 66.180.173.39 www.google.sm
    O1 - Hosts: 66.180.173.39 www.google.td
    O1 - Hosts: 66.180.173.39 www.google.tm

    If PeoplePC are no longer your ISP, fix these entries
    O2 - BHO: PeoplePC FixedBandBHO - {3DE88907-3E38-11D4-BEB2-CBE76C0598DD} - C:\PROGRAM FILES\ISP50\BIN\BANDOBJECT.DLL
    O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP50\hta\station.sbrt

    O2 - BHO: (no name) - {5483427F-93B8-1470-5A89-E6B56484CDB2} - C:\WINDOWS\TEMP\qlgcqjjkltg.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL (file missing)
    O4 - HKLM\..\Run: [scrsvc] C:\WINDOWS\SYSTEM\SCRSVC.EXE
    O4 - HKLM\..\Run: [bootpd.exe] C:\WINDOWS\SYSTEM\BOOTPD.EXE

    Click Fix Checked

    Then boot into Safe Mode and ensure that you are showing Hidden Files and Folders.

    Delete the following files and folders:
    C:\WINDOWS\SYSTEM\SCRSVC.EXE
    C:\WINDOWS\SYSTEM\BOOTPD.EXE

    Reboot and post a fresh log

  3. #3
    homeuzr is offline Newbie
    Wow!

    I followed your instructions--all worked to the tee as you described. Thanks for the detail.

    When I rebooted and re-ran Hijack This, I still found all the Google entries as before, along with bootpd.exe. So, I took a chance and re-checked those entries, ran fix, rebooted in Safe mode, didn't find the bootpd.exe file again. Rebooted in Normal mode, re-ran Hijack This and the log looks much better. No Google entries and my broswer loads to the home page of my choice now. Wow!

    I'm posting a fresh log anyway to ask if you can let me know if you see anything else suspicious.

    Logfile of HijackThis v1.99.1
    Scan saved at 9:36:48 PM, on 3/27/2005
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\SSDPSRV.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
    C:\WINDOWS\DELAYRUN.EXE
    C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
    C:\WINDOWS\SYSTEM\HPZTSB04.EXE
    C:\WINDOWS\SYSTEM\HPHMON03.EXE
    C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\PHOTOSMART\PHOTO IMAGING\HPI_MONITOR.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\PHOTOSMART\HP SHARE-TO-WEB\HPGS2WND.EXE
    C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\PHOTOSMART\HP SHARE-TO-WEB\HPGS2WNF.EXE
    C:\PROGRAM FILES\ISP50\BIN\BARTSHEL.EXE
    C:\WINDOWS\RunDLL.exe
    C:\WINDOWS\RUNDLL32.EXE
    C:\HPDESK\HPPDDIR.EXE
    C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
    C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
    C:\WINDOWS\SYSTEM\HPHIPM09.EXE
    C:\PROGRAM FILES\ISP50\BIN\PPSHARED.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\PROGRAM FILES\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wowway.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msnmember.msn.com
    O2 - BHO: PeoplePC FixedBandBHO - {3DE88907-3E38-11D4-BEB2-CBE76C0598DD} - C:\PROGRAM FILES\ISP50\BIN\BANDOBJECT.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\PROGRA~1\Google\GoogleToolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\PROGRA~1\Google\GoogleToolbar1.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
    O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
    O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb04.exe
    O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\SYSTEM\HPHMON03.EXE
    O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
    O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
    O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP50\hta\station.sbrt
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
    O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
    O4 - HKCU\..\Run: [OfotoNow USB Detection] C:\WINDOWS\RunDLL32.exe C:\PROGRA~1\OFOTO\OFOTONOW\OFUSBS.DLL,WatchForConn ection OfotoNow
    O4 - Startup: Document Assistant.lnk = C:\HPDESK\HPPDDIR.exe
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://msnmember.msn.com
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/...2/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/...16/mcgdmgr.cab

    Already I can't thank you enough for your help. Truly amazing.

    P.S. I've read your tips on 'Preventing It Returning' and am wondering how I can tell which Windows Updates are critical. Are they just the one's that say 'critical' (duh) or would I be better served to download all? I haven't paid attention to these in a while and have quite some catch up to do, I'm afraid.

    Thanks again.


  4. #4
    owen is offline D-A-L Team Member (UK)
    Hiya,
    Wise move fixing those entries that returned. As for the Critical Updates, look at the attached image below. If you go to Windows Update, click Scan For Updates. Then just click Review and Install Updates as shown. All Critical Updates are automatically selected for you. Simply click Install Updates.

    Attached Images

  5. #5
    homeuzr is offline Newbie
    Owen,
    Thanks so much for your support. The Google Browser Hijack problem is gone and I am ever grateful. Not only was your advice good for that particular problem, but I have also received such valuable information about how to keep my PC safer.

    I've yet to do the critical updates, but will be getting to that more easily in the near future with the guidance you provided.

    I'll certainly share my good experience with others. I'm off to the donation area to see how I can send my thanks that way also.

    Ta ta for now...again, many thanks!

  6. #6
    owen is offline D-A-L Team Member (UK)
    Save 20% on AVG Internet Security 2012 Suite!
    Thanks for the contribution toward the site

+ Reply to Thread