this is my log frm hijackthis-v1.99.1.....some of the websites i browse get redirected to help internet optimizer page. Any idea how i can fix it? I deleted the file, but it still comes! Pls check this log too....


Logfile of HijackThis v1.99.1
Scan saved at 12:30:08 AM, on 3/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\atievxx.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\webHancer\Programs\whAgent.exe
C:\Program Files\webHancer\Programs\whSurvey.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Windows AdService\WinAdServ.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Ynfx\Eyau.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Windows AdService\WinAdSlave.exe
C:\WINDOWS\system32\svchost.exe
C:\HOTSYNC.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\CASEEEE\LOCALS~1\Temp\Temporary Directory 1 for hijackthis_199.zip\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O2 - BHO: MySearch Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MySearch\SrchAstt\1.bin\MYSRCHAS.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: GoogleCatch.clsIESpy - {4508E20C-ACAD-11D2-9FC0-00550076E06F} - C:\Program Files\2search\2search.dll
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_22.dll
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll
O2 - BHO: System Process - {C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB} - C:\WINDOWS\system32\navshext.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll
O3 - Toolbar: My Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [webHancer Agent] "C:\Program Files\webHancer\Programs\whAgent.exe"
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Windows AdService] C:\Program Files\Windows AdService\WinAdServ.exe
O4 - HKLM\..\Run: [2Search] C:\Program Files\2search\main.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Mtkifzu] C:\Program Files\Ynfx\Eyau.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: HotSync Manager.lnk = C:\HOTSYNC.EXE
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: &Search -
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by WebHancer
O16 - DPF: {20048BB3-DB68-11CF-9CAF-00AA006CB425} (007installer Control) -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com/PhotoUpload/MsnPUpld.cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\..\{E60C9609-F029-4E43-82C6-955D13BC2277}: NameServer =
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

Dani AI

Generated

Brief expert summary and targeted next steps (building on ’s suggestions): persistent redirects after a product is "uninstalled" usually mean something stayed behind and is intercepting name lookups or browser calls — common culprits are altered DNS/proxy settings, a modified hosts file, leftover BHOs/toolbars, Winsock/LSP hooks, or a resident service/startup entry. The HijackThis log already points to network- and add-on–type survivors, so priority is to remove the networking hooks first, then clean browser add-ons and startup items.

Safe, practical checklist (do these in order; create a System Restore point or full backup first):

  • Reboot to Safe Mode (F8) and run the anti‑malware scans requested by ; then run a current anti‑adware tool (Malwarebytes/AdwCleaner or equivalent) and a full antivirus scan.
  • Check and remove proxy/DNS tampering: Internet Options -> Connections -> LAN Settings -> ensure no proxy is set; then open the NIC TCP/IP properties and set DNS to "Obtain automatically" (or use a trusted public DNS).
  • Inspect the hosts file at C:\Windows\system32\drivers\etc\hosts and remove unexpected entries (keep only default comments and 127.0.0.1 localhost unless other entries are known).
  • Reset name resolution and socket hooks from an elevated command prompt:
ipconfig /flushdns
netsh winsock reset
ipconfig /registerdns

Reboot after running those.

Follow-up cleanup:

  • Remove leftover program folders under Program Files and any matching Run keys (HKLM/HKCU...\Run) or suspicious services; use msconfig/services.msc to identify unknown entries.
  • Use HijackThis only to FIX items that are confidently identified as malicious; save the original log and a copy of the "fixed" log for comparison. Do not randomly remove system entries.
  • If the router’s DNS has been changed, factory-reset the router and reconfigure; persistent redirection after cleaning the PC often comes from router-level DNS tampering.

Notes and cautions: back up the registry before manual edits. If uncertainty remains after these steps, post the new HijackThis and scanner logs so the surviving items can be identified precisely.

Recommended Answers

All 3 Replies

Whew...you have a whole slew of things that need to go...

Please look in Add/Remove Programs and uninstall any of the following

WebHancer
New.Net or NewDotNet
Internet Optimizer
MessengerPlus 3! (usually comes with Lop Infection)
Ares
Limewire
Windows AdService

Afterwords do these few scans for me
Download Spysweeper here
http://www.malwareteks.com/dload.php?action=download&file_id=5
-Update to the latest definitions and run it
-Please attach the log when returning

ISeeYou

-Reboot to Safe Mode
-Save to Desktop
-Double Click ISeeYou.bat
-In 20-30 seconds a log will generate
-Save it for me and attach when you return

So I need the following logs when you return

Spysweeper
ISeeYou
HijackThis

Tks so much! There's one problem though. Using Hijackthis, i 'fixed' internet optimizer and then i deleted it from it's folder. From add/remove programs it said that it's already uninstalled and it asked me whether i would like to remove it. I said yes. However, some websites STILL get redirected to the help internet optimizer home page! :S what do i do?! Pls some one help!!

Thats fine for now, just carry out the rest of my Instructions by doing the Spysweeper and ISeeYou scans and attaching the three logs.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.