|
Posted by Sebastian Gottschalk on May 22, 2006, 8:46 am
If you were Registered and logged in, you could reply and use other advanced thread options
Tim Difford wrote:
> When I try to access some sites my address bar briefly flashes up an msn
> authosearch address before then landing on a yahoo autsearch page. Either
> way, I can't reach my URL.
MSN Autoseach... are you misusing IE as a webbrowser? If so, then you
shouldn't wonder at all.
> I know this is malware and have had it before.
So you've failed again.
> Can anyone help me fix it please.
Fixing it == flatten and rebuild
We can just help you identifying the problem(s).
BTW, it looks much more like a DNS problem.
> My log from Hijack This is below:
For the next time: Upload it somewhere and reference it.
BTW, there is a semi-automatic evaluation at http://www.hijackthis.de.
> Platform: Windows XP SP1 (WinNT 5.01.2600)
> MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
BIG BIG PROBLEM!
> C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
> C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
> C:\Program Files\Norton Internet Security\Norton
> AntiVirus\navapsvc.exe
> C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Bad.
> C:\Program Files\Eset\nod32krn.exe
You're running 2 virus scanners at the same time? Stupid idea.
> C:\WINDOWS\System32\nvsvc32.exe
> C:\WINDOWS\System32\MsPMSPSv.exe
> C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
> C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
> C:\Program Files\Common Files\Real\Update_OB\realsched.exe
> C:\Program Files\QuickTime\qttask.exe
> C:\Program Files\iTunes\iTunesHelper.exe
> C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
> C:\Program Files\WinZip\WZQKPICK.EXE
Superfluos.
> C:\Program Files\Spam Inspector Outlook Express\Spam Inspector Outlook
> Express Edition\piiserviceOE.exe
And you're also misusing Outlook Express as a mail client. And you
really wonder that you catched malware?
> C:\Program Files\Java\j2re1.4.2_08\bin\jusched.exe
Update this ASAP!
> C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
Dangerous.
> O2 + O3 + O8 + O9 + O16
They're all bad!
> O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
WTF?
Shit, how could you fuck up you system so much? Now even as I can't see
any malware from this, you should immediately flatten and rebuild!
|