Hi! I'm new to the forum...I'm trying to help my grandmother out by fixing her computer. She has her homepage set to her ISP's homepage, but she has it set so that it shows all her links to her email and such. You can see them for the time that it's loading, but then once it's finished, it goes away and she's given a prompt to log in. When she logs in though, she still can't access that page with all the links on it. I have no ideas left; her computer doesn't have any system restore points set for her to go as far back before the problem began; there are no viruses on her computer, and i'm stumped!!! Please help! I don't know if this will give any help, but here is the HijakThis log:

Logfile of HijackThis v1.97.7
Scan saved at 5:20:08 PM, on 6/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\aim\aim.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Valued Customer\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r5.attbi.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {965A592F-8EFA-4250-8630-7960230792F1} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: auto.search.msn.com
O1 - Hosts:
O1 - Hosts: ieautosearch
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Farstone Url Blocker - {316AEF8D-3C37-423E-9E6E-13820A9DC37A} - C:\PROGRA~1\THESHI~1\HSmack\PROGRA~1\FarStone\HACKER~1\IrlOnIE.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar_en_2.0.111-big.dll
O2 - BHO: Farstone Popup Blocker - {E22F9B9D-1A1F-473E-BED6-D8BC152441F4} - C:\Program Files\FarStone\HackerSmacker\FarPopupBlocker.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1601.0\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar_en_2.0.111-big.dll
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe
O4 - HKLM\..\Run: [Mwsvm] C:\WINDOWS\mwsvm.exe
O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe
O4 - HKLM\..\Run: [bkh] C:\WINDOWS\bkh.exe
O4 - HKLM\..\Run: [LYIZP] C:\WINDOWS\LYIZP.exe
O4 - HKLM\..\Run: [TZJQW] C:\WINDOWS\TZJQW.exe
O4 - HKLM\..\Run: [CJPWAGNT] C:\WINDOWS\CJPWAGNT.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\aim\aim.exe -cnetwait.odl
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\VALUED~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar_en_2.0.111-big.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar_en_2.0.111-big.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar_en_2.0.111-big.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar_en_2.0.111-big.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar_en_2.0.111-big.dll/cmtrans.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: ICQ Lite (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O10 - Broken Internet access because of LSP provider 'farlsp.dll' missing
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) -
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {54771E6F-A5A2-4413-8FB8-7B8F85398174} -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) -
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/odc/SymAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D9701E87-A34D-11D4-BE29-000102598CE4} (VrUpdate Control) -
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -

Thanks!
rachelbolton

Dani AI

Generated

Symptom summary and quick assessment: the ISP landing page briefly renders, then switches to a login/walled page and never restores the expected links. The HijackThis output posted by shows multiple signs consistent with browser hijacking plus a corrupted or missing LSP/Winsock provider. That combination explains intermittent rendering (page loads, then a redirect or injected script replaces content) and persistent access failures after logging in.

What’s likely happening: a redirect (hosts/proxy/LSP manipulation) or an injected BHO/toolbar is replacing the visible page after the initial HTML loads. A broken LSP or altered network stack can cause DNS/connection inconsistencies that make the browser show a login prompt instead of the ISP content. ’s identification of spyware/trojan indicators is on point; removal requires both file/registry cleanup and repair of the networking catalog.

Practical, prioritized workflow:

  1. Isolate the PC from the Internet (disconnect network) to prevent further downloads or credential leakage.
  2. Boot to Safe Mode (minimal services) and run a full, up-to-date antivirus scan and one or more on-demand anti-malware scanners while offline.
  3. Close all browsers and rerun HijackThis (or an equivalent startup scanner) to let it clean autoruns/BHOs; back up the registry/hosts file before changes.
  4. Repair the network stack: on modern systems reset Winsock and TCP/IP; for example:
    netsh winsock reset
    sfc /scannow   (may request the Windows CD)

    If the platform predates those tools, use the official vendor Winsock fix or reinstall TCP/IP.

  5. Clear browser cache/cookies, create a fresh user profile to test, and if instability remains, back up personal data and perform a repair-install or clean OS reinstall.

Notes and cautions: always back up the hosts file and registry before edits. For an elderly user’s PC, prefer a clean image restore and standard (non-admin) daily account afterwards. The steps above complement ’s recommendations and prioritize network-stack repair in addition to spyware removal.

Recommended Answers

All 2 Replies

OK, you've got evidence of both "spyware" and a possibletrojan/virus in that log. You say that there are no viruses on the computer; did you use a good (Norton, McAffe, etc.) anti-virus program with the most current virus definition updates to thoroughly scan the system? If not, do so.

- Once you've doen a virus scan, read this thread to find out how to download and use Ad Aware, SpyBot, and other free utilities to clean the nasties out of your system.

- It appears that you had IE open when you ran HJT; HJT cannot fully do its job with the browser running. Close all open programs and run HJT again. Have it fix the following:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {965A592F-8EFA-4250-8630-7960230792F1} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: auto.search.msn.com
O1 - Hosts:
O1 - Hosts: ieautosearch
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe
O4 - HKLM\..\Run: [Mwsvm] C:\WINDOWS\mwsvm.exe
O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe
O4 - HKLM\..\Run: [bkh] C:\WINDOWS\bkh.exe
O4 - HKLM\..\Run: [LYIZP] C:\WINDOWS\LYIZP.exe
O4 - HKLM\..\Run: [TZJQW] C:\WINDOWS\TZJQW.exe
O4 - HKLM\..\Run: [CJPWAGNT] C:\WINDOWS\CJPWAGNT.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O10 - Broken Internet access because of LSP provider 'farlsp.dll' missing
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) -
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) -
O16 - DPF: {D9701E87-A34D-11D4-BE29-000102598CE4} (VrUpdate Control) -


- You should uninstall System Soap Pro, as it is ad-driven.

- Reboot and delete all of the files referenced in the "04" HJT entries above. Delete the entire GMT and slmss folders.

- Delete your cookies and the contents of your Temporary Internet FIles folder; purge your browser's cache.

- Empty your Recycle Bin.

Moving this to the Security forum...

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.