more "home search assistent" fun...

Reply

Join Date: Feb 2004
Posts: 10,030
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 761
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: more "home search assistent" fun...

 
0
  #11
Dec 31st, 2004
Happy New Year to you too .
Also, please do not use inappropriate language in the forums. We cater for all ages here, being a public forum.

I wouldn't worry about what you could not fix . Just post another hijackthis log.

Download LSPfix from here
On the opening screen, click the "I know what I'm doing" checkbox.Then click Finish.

Hopefully that will restore the internet connection.
Reply With Quote Quick reply to this message  
Join Date: Dec 2004
Posts: 16
Reputation: Troels is an unknown quantity at this point 
Solved Threads: 0
Troels Troels is offline Offline
Newbie Poster

Re: more "home search assistent" fun...

 
0
  #12
Dec 31st, 2004
will try. Sleep later.. Sorry about the ****. I live in Denmark and **** is a part of the normal language.... Maybe i should only curse in danish... skupokkerdaogså...

Troels Mejer
Reply With Quote Quick reply to this message  
Join Date: Dec 2004
Posts: 16
Reputation: Troels is an unknown quantity at this point 
Solved Threads: 0
Troels Troels is offline Offline
Newbie Poster

Re: more "home search assistent" fun...

 
0
  #13
Jan 2nd, 2005
Hi again.

I ran the web-virus-search-thing and it found 15 things. I deleted (spelling?) all 15. The HJ-log after reboot is as follows:

Logfile of HijackThis v1.99.0
Scan saved at 16:36:16, on 02-01-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spyware Doctor\spydoctor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\TEXTware\HotKey\Twalink.exe
C:\PROGRA~1\ICQ\ICQ.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\WINDOWS\System32\wuauclt.exe
C:\TempVirusRemoval\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\da\msntb.dll (file missing)
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: HotKey.lnk = C:\Program Files\TEXTware\HotKey\Twalink.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1098647918263
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/...sh/swflash.cab
O23 - Service: Panda Firewall Service - Unknown - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
O23 - Service: Panda anti-virus service - Unknown - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe

Troels
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,030
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 761
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: more "home search assistent" fun...

 
0
  #14
Jan 2nd, 2005
Did you manage to get the PC back on-line?

Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.

O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: (HKLM)

You will need to reboot and check if those 015 entries come back. Let me know .
Reply With Quote Quick reply to this message  
Join Date: Dec 2004
Posts: 16
Reputation: Troels is an unknown quantity at this point 
Solved Threads: 0
Troels Troels is offline Offline
Newbie Poster

Re: more "home search assistent" fun...

 
0
  #15
Jan 2nd, 2005
Hi.

Yes I´m back online and all seems to be in perfect order. Allmost.

All the "015´s" are gone, but Spyware Doctor finds a tracking coockie after every reboot.

I don´t know if there´s any connections to the HomeSearch-thing? I cant get any more info on the cookie and it didnt help to delete all cookies in IE.

Thanks for all your help. I will try to deal with the tracking cookie later. Any ideas on how to find out more obuet the cookie and how to remove it?

Troels
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,030
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 761
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: more "home search assistent" fun...

 
0
  #16
Jan 2nd, 2005
You can try to clear it out manually by going to C:\Documents and Settings\Administrator\Cookies and deleting them manually. If you have spywareblaster you can set it to block tracking cookies.
Also you can set IE up to prompt you every time a site tries to set a cookie. Go to Internet Properties in IE then go to Privacy>Advanced. Select override automatic cookie handling and set both to prompt.
Reply With Quote Quick reply to this message  
Join Date: Dec 2004
Posts: 16
Reputation: Troels is an unknown quantity at this point 
Solved Threads: 0
Troels Troels is offline Offline
Newbie Poster

Re: more "home search assistent" fun...

 
0
  #17
Jan 3rd, 2005
I now get anywhere from 1 to 3 new cookies on every startup. Here´s a list of the ones that look´s od:

troels@cgi-bin[1]
troels@mediaplex
troels@tribalfusion
troels@as-us.falkag
troels@imho

Any ideas? I will install all the programs listet at: http://www.daniweb.com/techtalkforums/thread5690.html

But I fear that they will only prevent new cookies from being installed.

Troels
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,030
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 761
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: more "home search assistent" fun...

 
0
  #18
Jan 3rd, 2005
Did you do what I suggested above? If you did, you should be able to delete those cookies and the only way they can come back is if you let them.
Reply With Quote Quick reply to this message  
Join Date: Dec 2004
Posts: 16
Reputation: Troels is an unknown quantity at this point 
Solved Threads: 0
Troels Troels is offline Offline
Newbie Poster

Re: more "home search assistent" fun...

 
0
  #19
Jan 3rd, 2005
Hi.

I did as you suggested and it seems that some of those cookies come from my hotmail-account... they are now blocked.

I ran Adaware once more and it found 5 things which are now deleted.
I guess that the PC is OK now, and I very greatfull for all your help.

Troels
Reply With Quote Quick reply to this message  
Join Date: Dec 2004
Posts: 16
Reputation: Troels is an unknown quantity at this point 
Solved Threads: 0
Troels Troels is offline Offline
Newbie Poster

Re: more "home search assistent" fun...

 
0
  #20
Jan 3rd, 2005
wait a minute...

As i was posting my last reply the "tribal-cookie" asked for permission... Does that mean that it is comming from daniweb?

Troels
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC