Hi, can anyone help, have tried using ad-aware, cwshredder, spybot search and destroy clearing out the windows temp folder and more with no joy. have just run hijack this and got the following results

Logfile of HijackThis v1.97.7
Scan saved at 20:43:57, on 26/09/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\E_S10IC2.EXE
C:\WINDOWS\SYSTEM\E_S10IC2.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\SERVICES\MSXMIDI.EXE
C:\WINDOWS\DXSOUND.EXE
C:\WINDOWS\APPLICATION DATA\TSEO.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\MSXMIDI.EXE
C:\MY DOCUMENTS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://lookfor.cc/sp.php?pin=29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://lookfor.cc/sp.php?pin=29126
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://lookfor.cc/sp.php?pin=29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://lookfor.cc/sp.php?pin=29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://lookfor.cc/sp.php?pin=29126
F1 - win.ini: run=C:\WINDOWS\SYSTEM\SERVICES\MSXMIDI.EXE
O2 - BHO: (no name) - {722E8B26-1C44-460F-88BB-50C82B20E30E} - C:\WINDOWS\SYSTEM\MSQSB.DLL
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\BXXS5.DLL
O3 - Toolbar: Neo Toolbar - {722E8B26-1C44-460F-88BB-50C82B20E30E} - C:\WINDOWS\SYSTEM\MSQSB.DLL
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\BXXS5.DLL,DllRun
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copy 2)] C:\WINDOWS\SYSTEM\E_S10IC2.EXE /P28 "EPSON Stylus CX3200 (Copy 2)" /O7 "EPUSB1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\SYSTEM\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O7 "EPUSB1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [xpsystem] C:\WINDOWS\SYSTEM\SERVICES\MSXMIDI.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKCU\..\Run: [Service Manager] C:\windows\dxsound.exe
O4 - HKCU\..\Run: [Nbcs] C:\WINDOWS\Application Data\tseo.exe
O4 - HKCU\..\Run: [xpsystem] C:\WINDOWS\SYSTEM\SERVICES\MSXMIDI.EXE
O4 - HKLM\..\RunOnce: [ICDRegOCX0] rundll32.exe advpack.dll,RegisterOCX C:\WINDOWS\DOWNLOADED PROGRAM FILES\SyncroAdX.dll
O8 - Extra context menu item: Web Rebates - file://C:\PROGRAM FILES\WEB_REBATES\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} -
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

can anybody help, please

Dani AI

Generated

Brief expert summary and immediate plan (for — thread moved by and with ’s earlier advice to re-post a fresh HijackThis log in the Security forum):

This is a classic persistent browser‑hijack scenario that often requires an ordered, hands‑on cleanup: isolate the PC, run targeted removal utilities for the hijack family, follow with a full anti‑malware sweep, then make careful manual repairs only from a saved HijackThis log. HijackThis is primarily a diagnostic tool — using its “Fix” blindly can break a working system — so save backups and logs before making changes. (malwarebytes.com)

Practical, safe sequence to follow (order matters):

  1. Back up personal files (do not back up executables). Disconnect from the network or pull the cable to stop reinfection.
  2. On a clean PC, download the removers and place them in a single folder (examples historically effective against CWS‑type hijacks: CWShredder and About:Buster) plus a current anti‑malware scanner. Copy the folder to the infected PC on removable media. (support.moonpoint.com)
  3. Boot the infected PC into Safe Mode (F8), run the specialized removers first (CWShredder/About:Buster), then run a full on‑demand anti‑malware scan (Malwarebytes or Microsoft Safety Scanner). Reboot normally and re‑scan.
  4. Run HijackThis from its own folder, save the logfile and do not apply fixes unless the entries are confirmed malicious — post the logfile in the Security forum for guided fixes. (en.wikipedia.org)

If the hijack returns or critical system files are damaged, look for hidden processes, randomly named DLLs in system folders, scheduled tasks and altered “Trusted” sites; an offline rescue scan (bootable AV rescue media) or a clean OS reinstall is sometimes the only reliable cure for aggressive variants. Change any passwords used on the machine after it’s clean. Historical variants of this hijacker were especially persistent and sometimes required tool combinations or full rebuilds. (wired.com)

Notes and cautions: work methodically, keep a copy of every logfile, and avoid manual registry edits unless comfortable with restoring the registry.

Recommended Answers

All 2 Replies

Hi cs, welcome to DaniWeb! You must not have noticed the announcement at the top of the forum requesting all hijackthis logs be posted in the Security forum. :)

There are some things you should do, however, before posting your log there. First, have a look at this thread:
http://www.daniweb.com/techtalkforums/thread5690.html

I see you have already done several things to try to get rid of this, but there are a few more. You should also have free online scans done from and
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

If the problem still hasn't been resolved, update hijackthis using either the Update feature within it or from here: http://www.softpedia.com/progDownload/x-Download-5034.html
Also, hijackthis should be in it's own folder to save backups in a centralized location (like c:\hjt\hijackthis.exe)

Close all windows, scan with hjt, save the log and post it in the Security forum, again describing the problem you're still having and the steps you've already taken to try to fix it.

Moving to the Security forum now...

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.