<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Browser Hijack!! in Security</title>
<link>http://www.dslreports.com/forum/r8400055</link>
<description></description>
<language>en</language>
<pubDate>Mon, 09 Nov 2009 15:10:37 EDT</pubDate>
<lastBuildDate>Mon, 09 Nov 2009 15:10:37 EDT</lastBuildDate>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8412084</link>
<description><![CDATA[<A HREF="/useremail/u/156829"><b>Paul928</b></A> : Thanks for the help Zupe. I will run another scan on the system with the Symantec QHosts removal tool. When i did it the first time, it said that "there was no instance found of the Qhosts Trojan" Or something to that effect. I'll try running it again tonight and see what happens. You said to delete the files in that list with Hijack This tool, but one in particular that I know I need is <br>O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - &raquo;rd1.surfernetwork.com/surferplugin.ocx<br> This is for a radio plug-in that I listen to, but the other entries that you recommended deleting seem okay I guess.....Thanks for the help, and I'll post again later when I get home......Thank You!!<br><i>[text was edited by author 2003-11-04 12:52:00]</i><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8412084</guid>
<pubDate>Tue, 04 Nov 2003 12:51:08 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8403576</link>
<description><![CDATA[<A HREF="/useremail/u/525050"><b>Zupe</b></A> :  <BLOCKQUOTE><SMALL>said by  Paul928 <A HREF="/useremail/u/156829"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>O2 - BHO: DefaultSearch.SeekSeek - {5074851C-F67A-488E-A9C9-C244573F4068} - C:\WINDOWS\ieasst.dll<br><br>O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe<br><br>O4 - HKLM\..\Run: [Mwsvm] C:\WINDOWS\mwsvm.exe<br><br>O4 - HKLM\..\Run: [absr] C:\WINDOWS\mwsvm.exe <br><br>O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - &raquo;<A HREF="http://www.ipix.com/viewers/ipixx.cab" >www.ipix.com/viewers/ipixx.cab</A><br><br>O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - &raquo;<A HREF="http://rd1.surfernetwork.com/surferplugin.ocx" >rd1.surfernetwork.com/surferplugin.ocx</A><br><br>O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - &raquo;<A HREF="http://cs6b.instantservice.com/jars/customerxsigned35.cab" >cs6b.instantservice.com/jars/cus&middot;&middot;&middot;d35.cab</A><br><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{33480BEB-FB8D-465D-AE4A-6BB4469C927C}: NameServer = 216.127.92.38<br><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{3AB061A3-A055-43A0-9B3B-2003FA486F41}: NameServer = 216.127.92.38<br><br>O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com<br><br>O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 216.127.92.38<HR></BLOCKQUOTE>All of these should still be removed.<br><br>First, please re-rerun the Symantec QHosts removal tool, as to my knowledge it should get rid of those 017 entries.<br><br>Next, go to start->run and type <br><br>regsvr32 /u C:\WINDOWS\ieasst.dll<br><br>Then, in Hijack This, check off all of the above, hit "Fix Checked" and reboot, then rescan and post another log.<br><SMALL>--<br><I>Brain:</I> Pinky, are you pondering what I'm pondering?<BR><I>Pinky:</I> I think so, Brain, but "Snowball for Windows"?</SMALL><br><i>[text was edited by author 2003-11-03 16:18:45]</i>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8403576</guid>
<pubDate>Mon, 03 Nov 2003 16:15:47 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8403231</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : try downloading    adaware6    it really helps for getting rid of browser hijacks<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8403231</guid>
<pubDate>Mon, 03 Nov 2003 15:42:29 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8403170</link>
<description><![CDATA[<A HREF="/useremail/u/156829"><b>Paul928</b></A> : Logfile of HijackThis v1.97.3<br>Scan saved at 3:32:55 PM, on 11/3/2003<br>Platform: Windows XP  (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 (6.00.2600.0000)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\WINDOWS\System32\tbctray.exe<br>C:\Program Files\MSN Messenger\msnmsgr.exe<br>C:\Program Files\AOL Companion\companion.exe<br>C:\Program Files\America Online 9.0\aoltray.exe<br>C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe<br>C:\PROGRA~1\Grisoft\AVG6\avgserv.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\wanmpsvc.exe<br>C:\My Music\hijackthis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://rd.yahoo.com/customize/ymsgr/defaults/*http://my.yahoo.com" >rd.yahoo.com/customize/ymsgr/def&middot;&middot;&middot;ahoo.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html" >rd.yahoo.com/customize/ymsgr/def&middot;&middot;&middot;rch.html</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://www.seekseek.com/quicksearch.asp?session=F499CA64-14E0-49C0-A08D-DB90AB254DC5&version_id=18" >www.seekseek.com/quicksearch.asp&middot;&middot;&middot;on_id=18</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm<br>O2 - BHO: DefaultSearch.SeekSeek - {5074851C-F67A-488E-A9C9-C244573F4068} - C:\WINDOWS\ieasst.dll<br>O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe<br>O4 - HKLM\..\Run: [Mwsvm] C:\WINDOWS\mwsvm.exe<br>O4 - HKLM\..\Run: [absr] C:\WINDOWS\mwsvm.exe <br>O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\System32\tbctray.exe<br>O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background<br>O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe<br>O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br>O9 - Extra button: AIM (HKLM)<br>O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)<br>O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)<br>O16 - DPF: Win32 Classes - <br>O16 - DPF: Yahoo! Pool 2 - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/potc_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;tc_x.cab</A><br>O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - &raquo;<A HREF="http://office.microsoft.com/templates/ieawsdc.cab" >office.microsoft.com/templates/ieawsdc.cab</A><br>O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - &raquo;<A HREF="http://www.ipix.com/viewers/ipixx.cab" >www.ipix.com/viewers/ipixx.cab</A><br>O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - &raquo;<A HREF="http://thesims.ea.com/teleport/hotdate/NPC/MaxisHotDateTeleX.cab" >thesims.ea.com/teleport/hotdate/&middot;&middot;&middot;eleX.cab</A><br>O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - &raquo;<A HREF="http://download.yahoo.com/dl/installs/yinst.cab" >download.yahoo.com/dl/installs/yinst.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/drakken/us/win/QuickTimeInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - &raquo;<A HREF="http://rd1.surfernetwork.com/surferplugin.ocx" >rd1.surfernetwork.com/surferplugin.ocx</A><br>O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - &raquo;<A HREF="http://aolcc.aol.com/computercheckup/qdiagcc.cab" >aolcc.aol.com/computercheckup/qdiagcc.cab</A><br>O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - &raquo;<A HREF="http://207.188.7.150/254e0d9dc812f8d03705/netzip/RdxIE601.cab" >207.188.7.150/254e0d9dc812f8d037&middot;&middot;&middot;E601.cab</A><br>O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} (MaxisSuperstarTeleX Control) - &raquo;<A HREF="http://thesims.ea.com/teleport/superstar/MaxisSuperstarTeleX.cab" >thesims.ea.com/teleport/supersta&middot;&middot;&middot;eleX.cab</A><br>O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - &raquo;<A HREF="http://cs6b.instantservice.com/jars/customerxsigned35.cab" >cs6b.instantservice.com/jars/cus&middot;&middot;&middot;ed35.cab</A><br>O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - &raquo;<A HREF="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi.dll" >us.dl1.yimg.com/download.yahoo.c&middot;&middot;&middot;mapi.dll</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;lash.cab</A><br>O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - &raquo;<A HREF="http://download.abacast.com/download/files/abasetup.cab" >download.abacast.com/download/fi&middot;&middot;&middot;etup.cab</A><br>O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - &raquo;<A HREF="http://fdl.msn.com/public/chat/msnchat45.cab" >fdl.msn.com/public/chat/msnchat45.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{33480BEB-FB8D-465D-AE4A-6BB4469C927C}: NameServer = 216.127.92.38<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{3AB061A3-A055-43A0-9B3B-2003FA486F41}: NameServer = 216.127.92.38<br>O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com<br>O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 216.127.92.38<br><br>This is my latest scan after doing what I was advised...does it look okay now?....thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8403170</guid>
<pubDate>Mon, 03 Nov 2003 15:35:39 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8402477</link>
<description><![CDATA[<A HREF="/useremail/u/525050"><b>Zupe</b></A> :  <BLOCKQUOTE><SMALL>said by  Paul928 <A HREF="/useremail/u/156829"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = &raquo;<A HREF="http://tooncomics.com/main/sp.htm" >tooncomics.com/main/sp.htm</A><br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://tooncomics.com/main/sp.htm" >tooncomics.com/main/sp.htm</A><br><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://www.seekseek.com/quicksearch.asp?session=F499CA64-14E0-49C0-A08D-DB90AB254DC5&version_id=18" >www.seekseek.com/quicksearch.asp&middot;&middot;&middot;n_id=18</A><br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = &raquo;<A HREF="http://www.fastwebfinder.com/hp.php" >www.fastwebfinder.com/hp.php</A><br><br>R1 - HKCU\Software\Microsoft\Internet Explorer,Search = &raquo;<A HREF="http://out.true-counter.com/b/?101" >out.true-counter.com/b/?101</A> (obfuscated)<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer,Search = &raquo;<A HREF="http://out.true-counter.com/b/?101" >out.true-counter.com/b/?101</A> (obfuscated)<br><br>O1 - Hosts file is located at: C:\WINDOWS\help\hosts<br>O1 - Hosts: 88.88.88.88 elite<br>O1 - Hosts: 207.44.220.30 www.google.akadns.net<br>O1 - Hosts: 207.44.220.30 www.google.com<br>O1 - Hosts: 207.44.220.30 google.com<br>O1 - Hosts: 207.44.220.30 www.altavista.com<br>O1 - Hosts: 207.44.220.30 altavista.com<br>O1 - Hosts: 207.44.220.30 search.yahoo.com<br>O1 - Hosts: 207.44.220.30 uk.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 ca.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 jp.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 au.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 de.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 search.yahoo.co.jp<br>O1 - Hosts: 207.44.220.30 www.lycos.de<br>O1 - Hosts: 207.44.220.30 www.lycos.ca<br>O1 - Hosts: 207.44.220.30 www.lycos.jp<br>O1 - Hosts: 207.44.220.30 www.lycos.co.jp<br>O1 - Hosts: 207.44.220.30 alltheweb.com<br>O1 - Hosts: 207.44.220.30 web.ask.com<br>O1 - Hosts: 207.44.220.30 ask.com<br>O1 - Hosts: 207.44.220.30 www.ask.com<br>O1 - Hosts: 207.44.220.30 www.teoma.com<br>O1 - Hosts: 207.44.220.30 search.aol.com<br>O1 - Hosts: 207.44.220.30 www.looksmart.com<br>O1 - Hosts: 207.44.220.30 auto.search.msn.com<br>O1 - Hosts: 207.44.220.30 search.msn.com<br>O1 - Hosts: 207.44.220.30 ca.search.msn.com<br>O1 - Hosts: 207.44.220.30 fr.ca.search.msn.com<br>O1 - Hosts: 207.44.220.30 search.fr.msn.be<br>O1 - Hosts: 207.44.220.30 search.fr.msn.ch<br>O1 - Hosts: 207.44.220.30 search.latam.yupimsn.com<br>O1 - Hosts: 207.44.220.30 search.msn.at<br>O1 - Hosts: 207.44.220.30 search.msn.be<br>O1 - Hosts: 207.44.220.30 search.msn.ch<br>O1 - Hosts: 207.44.220.30 search.msn.co.in<br>O1 - Hosts: 207.44.220.30 search.msn.co.jp<br>O1 - Hosts: 207.44.220.30 search.msn.co.kr<br>O1 - Hosts: 207.44.220.30 search.msn.com.br<br>O1 - Hosts: 207.44.220.30 search.msn.com.hk<br>O1 - Hosts: 207.44.220.30 search.msn.com.my<br>O1 - Hosts: 207.44.220.30 search.msn.com.sg<br>O1 - Hosts: 207.44.220.30 search.msn.com.tw<br>O1 - Hosts: 207.44.220.30 search.msn.co.za<br>O1 - Hosts: 207.44.220.30 search.msn.de<br>O1 - Hosts: 207.44.220.30 search.msn.dk<br>O1 - Hosts: 207.44.220.30 search.msn.es<br>O1 - Hosts: 207.44.220.30 search.msn.fi<br>O1 - Hosts: 207.44.220.30 search.msn.fr<br>O1 - Hosts: 207.44.220.30 search.msn.it<br>O1 - Hosts: 207.44.220.30 search.msn.nl<br>O1 - Hosts: 207.44.220.30 search.msn.no<br>O1 - Hosts: 207.44.220.30 search.msn.se<br>O1 - Hosts: 207.44.220.30 search.ninemsn.com.au<br>O1 - Hosts: 207.44.220.30 search.t1msn.com.mx<br>O1 - Hosts: 207.44.220.30 search.xtramsn.co.nz<br>O1 - Hosts: 207.44.220.30 search.yupimsn.com<br>O1 - Hosts: 207.44.220.30 uk.search.msn.com<br>O1 - Hosts: 207.44.220.30 search.lycos.com<br>O1 - Hosts: 207.44.220.30 www.lycos.com<br>O1 - Hosts: 207.44.220.30 www.google.ca<br>O1 - Hosts: 207.44.220.30 google.ca<br>O1 - Hosts: 207.44.220.30 www.google.uk<br>O1 - Hosts: 207.44.220.30 www.google.co.uk<br>O1 - Hosts: 207.44.220.30 www.google.com.au<br>O1 - Hosts: 207.44.220.30 www.google.co.jp<br>O1 - Hosts: 207.44.220.30 www.google.jp<br>O1 - Hosts: 207.44.220.30 www.google.at<br>O1 - Hosts: 207.44.220.30 www.google.be<br>O1 - Hosts: 207.44.220.30 www.google.ch<br>O1 - Hosts: 207.44.220.30 www.google.de<br>O1 - Hosts: 207.44.220.30 www.google.se<br>O1 - Hosts: 207.44.220.30 www.google.dk<br>O1 - Hosts: 207.44.220.30 www.google.fi<br>O1 - Hosts: 207.44.220.30 www.google.fr<br>O1 - Hosts: 207.44.220.30 www.google.com.gr<br>O1 - Hosts: 207.44.220.30 www.google.com.hk<br>O1 - Hosts: 207.44.220.30 www.google.ie<br>O1 - Hosts: 207.44.220.30 www.google.co.il<br>O1 - Hosts: 207.44.220.30 www.google.it<br>O1 - Hosts: 207.44.220.30 www.google.co.kr<br>O1 - Hosts: 207.44.220.30 www.google.com.mx<br>O1 - Hosts: 207.44.220.30 www.google.nl<br>O1 - Hosts: 207.44.220.30 www.google.co.nz<br>O1 - Hosts: 207.44.220.30 www.google.pl<br>O1 - Hosts: 207.44.220.30 www.google.pt<br>O1 - Hosts: 207.44.220.30 www.google.com.ru<br>O1 - Hosts: 207.44.220.30 www.google.com.sg<br>O1 - Hosts: 207.44.220.30 www.google.co.th<br>O1 - Hosts: 207.44.220.30 www.google.com.tr<br>O1 - Hosts: 207.44.220.30 www.google.com.tw<br>O1 - Hosts: 207.44.220.30 go.google.com<br>O1 - Hosts: 207.44.220.30 google.at<br>O1 - Hosts: 207.44.220.30 google.be<br>O1 - Hosts: 207.44.220.30 google.de<br>O1 - Hosts: 207.44.220.30 google.dk<br>O1 - Hosts: 207.44.220.30 google.fi<br>O1 - Hosts: 207.44.220.30 google.fr<br>O1 - Hosts: 207.44.220.30 google.com.hk<br>O1 - Hosts: 207.44.220.30 google.ie<br>O1 - Hosts: 207.44.220.30 google.co.il<br>O1 - Hosts: 207.44.220.30 google.it<br><br>O2 - BHO: DefaultSearch.SeekSeek - {5074851C-F67A-488E-A9C9-C244573F4068} - C:\WINDOWS\ieasst.dll<br><br>O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe<br><br>O4 - HKLM\..\Run: [Mwsvm] C:\WINDOWS\mwsvm.exe<br><br>O4 - HKLM\..\Run: [absr] C:\WINDOWS\mwsvm.exe <br> <br>O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - &raquo;<A HREF="http://rd1.surfernetwork.com/surferplugin.ocx" >rd1.surfernetwork.com/surferplugin.ocx</A><br><br>O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - &raquo;<A HREF="http://cs6b.instantservice.com/jars/customerxsigned35.cab" >cs6b.instantservice.com/jars/cus&middot;&middot;&middot;d35.cab</A><br><br>O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com<br><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{33480BEB-FB8D-465D-AE4A-6BB4469C927C}: NameServer = 216.127.92.38<br><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{3AB061A3-A055-43A0-9B3B-2003FA486F41}: NameServer = 216.127.92.38<br><br>O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com<br><br>O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 216.127.92.38<br><br>O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com<br><br>O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 216.127.92.38<br><br>O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 216.127.92.38<br><br>O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp <HR></BLOCKQUOTE>You've got a whole bunch of spyware here, including Coolwebsearch, the QHosts trojan, and a newer one called seek-seek.  This will take a few steps to get rid of:<br><br>1) Download and run CWShredder from here: &raquo;<A HREF="http://www.spywareinfo.com/~merijn/cwschronicles.html" >www.spywareinfo.com/~merijn/cwsc&middot;&middot;&middot;les.html</A> (Direct Download: &raquo;<A HREF="http://www.spywareinfo.com/~merijn/files/cwshredder.zip" >www.spywareinfo.com/~merijn/file&middot;&middot;&middot;dder.zip</A> )<br><br>2) Download and run the QHosts removal tool from Symantec here: &raquo;<A HREF="http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.removal.tool.html" >securityresponse.symantec.com/av&middot;&middot;&middot;ool.html</A> (Direct Download: &raquo;<A HREF="http://www.symantec.com/avcenter/FixQhost.exe" >www.symantec.com/avcenter/FixQhost.exe</A> )<br><br>3) Go to the C:\Windows\Help directory and delete the file called "Hosts" there, then, as  pieter arntz <A HREF="/useremail/u/591564"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> suggested above, copy and paste this into notepad, save as restorehostspath.reg, doubleclick it and confirm that you want to merge it with the registry:<br><br>Windows Registry Editor Version 5.00<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]<br>"DataBasePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\<br>00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\<br>64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,65,00,74,00,63,00,00,00<br><br>4) Hit Ctrl-Alt-Del, highlight slmss.exe and hit "end Process".  Do the same for mwsvm.exe<br><br>5) With all browswer windows closed, re-scan with Hijack This and put a check next to any of the items I listed above that still remain, then click "Fix Checked",  Reboot and rescan with Hijack This and post your log again<br><br>6) Wait for someone to look over your log.  Assuming it's clean, you can then delete the following:<br><br>C:\WINDOWS\mwsvm.exe<br>C:\Program Files\Common Files\slmss\slmss.exe (possibly the whole slmss directory)<br>C:\WINDOWS\ieasst.dll<br><SMALL>--<br><I>Brain:</I> Pinky, are you pondering what I'm pondering?<BR><I>Pinky:</I> I think so, Brain, but "Snowball for Windows"?</SMALL><br><i>[text was edited by author 2003-11-03 14:21:41]</i>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8402477</guid>
<pubDate>Mon, 03 Nov 2003 14:05:57 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8402466</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> :  <BLOCKQUOTE><SMALL>said by  Paul928 <A HREF="/useremail/u/156829"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>Thanks for the help people. What I did was actually delete the whole host file,re-booted and everything was cool....thanks for all the help <HR></BLOCKQUOTE><br><br>It might pay you to read this: &raquo;<A HREF="http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html" >securityresponse.symantec.com/av&middot;&middot;&middot;sts.html</A><br><small>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8402466</guid>
<pubDate>Mon, 03 Nov 2003 14:04:32 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8402168</link>
<description><![CDATA[<A HREF="/useremail/u/528483"><b>Nam Vet</b></A> : I am going to defer here to someone more knowledgeable.<br>but look at you host file path (it's wrong)<br>and all the url's in the hosts file redirect you to 207.44.220.30<br>which is "ns1.sitething.net"<br><br><i>[text was edited by author 2003-11-03 13:25:36]</i><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8402168</guid>
<pubDate>Mon, 03 Nov 2003 13:22:56 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8402141</link>
<description><![CDATA[<A HREF="/useremail/u/156829"><b>Paul928</b></A> : Thanks for the help people. What I did was actually delete the whole host file,re-booted and everything was cool....thanks for all the help]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8402141</guid>
<pubDate>Mon, 03 Nov 2003 13:19:28 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8402060</link>
<description><![CDATA[<A HREF="/useremail/u/156829"><b>Paul928</b></A> : Here is my log file from Hijackthis...kind of a long one.<br><br>Logfile of HijackThis v1.97.3<br>Scan saved at 1:04:31 PM, on 11/3/2003<br>Platform: Windows XP  (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 (6.00.2600.0000)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\Program Files\Common Files\slmss\slmss.exe<br>C:\WINDOWS\mwsvm.exe<br>C:\WINDOWS\System32\tbctray.exe<br>C:\Program Files\AOL Companion\companion.exe<br>C:\Program Files\America Online 9.0\aoltray.exe<br>C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe<br>C:\PROGRA~1\Grisoft\AVG6\avgserv.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\wanmpsvc.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\My Music\hijackthis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = &raquo;<A HREF="http://tooncomics.com/main/sp.htm" >tooncomics.com/main/sp.htm</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://tooncomics.com/main/sp.htm" >tooncomics.com/main/sp.htm</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://rd.yahoo.com/customize/ymsgr/defaults/*http://my.yahoo.com" >rd.yahoo.com/customize/ymsgr/def&middot;&middot;&middot;ahoo.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html" >rd.yahoo.com/customize/ymsgr/def&middot;&middot;&middot;rch.html</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://www.seekseek.com/quicksearch.asp?session=F499CA64-14E0-49C0-A08D-DB90AB254DC5&version_id=18" >www.seekseek.com/quicksearch.asp&middot;&middot;&middot;on_id=18</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = &raquo;<A HREF="http://www.fastwebfinder.com/hp.php" >www.fastwebfinder.com/hp.php</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer,Search = &raquo;<A HREF="http://out.true-counter.com/b/?101" >out.true-counter.com/b/?101</A> (obfuscated)<br>R1 - HKLM\Software\Microsoft\Internet Explorer,Search = &raquo;<A HREF="http://out.true-counter.com/b/?101" >out.true-counter.com/b/?101</A> (obfuscated)<br>O1 - Hosts file is located at: C:\WINDOWS\help\hosts<br>O1 - Hosts: 88.88.88.88 elite<br>O1 - Hosts: 207.44.220.30 www.google.akadns.net<br>O1 - Hosts: 207.44.220.30 www.google.com<br>O1 - Hosts: 207.44.220.30 google.com<br>O1 - Hosts: 207.44.220.30 www.altavista.com<br>O1 - Hosts: 207.44.220.30 altavista.com<br>O1 - Hosts: 207.44.220.30 search.yahoo.com<br>O1 - Hosts: 207.44.220.30 uk.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 ca.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 jp.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 au.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 de.search.yahoo.com<br>O1 - Hosts: 207.44.220.30 search.yahoo.co.jp<br>O1 - Hosts: 207.44.220.30 www.lycos.de<br>O1 - Hosts: 207.44.220.30 www.lycos.ca<br>O1 - Hosts: 207.44.220.30 www.lycos.jp<br>O1 - Hosts: 207.44.220.30 www.lycos.co.jp<br>O1 - Hosts: 207.44.220.30 alltheweb.com<br>O1 - Hosts: 207.44.220.30 web.ask.com<br>O1 - Hosts: 207.44.220.30 ask.com<br>O1 - Hosts: 207.44.220.30 www.ask.com<br>O1 - Hosts: 207.44.220.30 www.teoma.com<br>O1 - Hosts: 207.44.220.30 search.aol.com<br>O1 - Hosts: 207.44.220.30 www.looksmart.com<br>O1 - Hosts: 207.44.220.30 auto.search.msn.com<br>O1 - Hosts: 207.44.220.30 search.msn.com<br>O1 - Hosts: 207.44.220.30 ca.search.msn.com<br>O1 - Hosts: 207.44.220.30 fr.ca.search.msn.com<br>O1 - Hosts: 207.44.220.30 search.fr.msn.be<br>O1 - Hosts: 207.44.220.30 search.fr.msn.ch<br>O1 - Hosts: 207.44.220.30 search.latam.yupimsn.com<br>O1 - Hosts: 207.44.220.30 search.msn.at<br>O1 - Hosts: 207.44.220.30 search.msn.be<br>O1 - Hosts: 207.44.220.30 search.msn.ch<br>O1 - Hosts: 207.44.220.30 search.msn.co.in<br>O1 - Hosts: 207.44.220.30 search.msn.co.jp<br>O1 - Hosts: 207.44.220.30 search.msn.co.kr<br>O1 - Hosts: 207.44.220.30 search.msn.com.br<br>O1 - Hosts: 207.44.220.30 search.msn.com.hk<br>O1 - Hosts: 207.44.220.30 search.msn.com.my<br>O1 - Hosts: 207.44.220.30 search.msn.com.sg<br>O1 - Hosts: 207.44.220.30 search.msn.com.tw<br>O1 - Hosts: 207.44.220.30 search.msn.co.za<br>O1 - Hosts: 207.44.220.30 search.msn.de<br>O1 - Hosts: 207.44.220.30 search.msn.dk<br>O1 - Hosts: 207.44.220.30 search.msn.es<br>O1 - Hosts: 207.44.220.30 search.msn.fi<br>O1 - Hosts: 207.44.220.30 search.msn.fr<br>O1 - Hosts: 207.44.220.30 search.msn.it<br>O1 - Hosts: 207.44.220.30 search.msn.nl<br>O1 - Hosts: 207.44.220.30 search.msn.no<br>O1 - Hosts: 207.44.220.30 search.msn.se<br>O1 - Hosts: 207.44.220.30 search.ninemsn.com.au<br>O1 - Hosts: 207.44.220.30 search.t1msn.com.mx<br>O1 - Hosts: 207.44.220.30 search.xtramsn.co.nz<br>O1 - Hosts: 207.44.220.30 search.yupimsn.com<br>O1 - Hosts: 207.44.220.30 uk.search.msn.com<br>O1 - Hosts: 207.44.220.30 search.lycos.com<br>O1 - Hosts: 207.44.220.30 www.lycos.com<br>O1 - Hosts: 207.44.220.30 www.google.ca<br>O1 - Hosts: 207.44.220.30 google.ca<br>O1 - Hosts: 207.44.220.30 www.google.uk<br>O1 - Hosts: 207.44.220.30 www.google.co.uk<br>O1 - Hosts: 207.44.220.30 www.google.com.au<br>O1 - Hosts: 207.44.220.30 www.google.co.jp<br>O1 - Hosts: 207.44.220.30 www.google.jp<br>O1 - Hosts: 207.44.220.30 www.google.at<br>O1 - Hosts: 207.44.220.30 www.google.be<br>O1 - Hosts: 207.44.220.30 www.google.ch<br>O1 - Hosts: 207.44.220.30 www.google.de<br>O1 - Hosts: 207.44.220.30 www.google.se<br>O1 - Hosts: 207.44.220.30 www.google.dk<br>O1 - Hosts: 207.44.220.30 www.google.fi<br>O1 - Hosts: 207.44.220.30 www.google.fr<br>O1 - Hosts: 207.44.220.30 www.google.com.gr<br>O1 - Hosts: 207.44.220.30 www.google.com.hk<br>O1 - Hosts: 207.44.220.30 www.google.ie<br>O1 - Hosts: 207.44.220.30 www.google.co.il<br>O1 - Hosts: 207.44.220.30 www.google.it<br>O1 - Hosts: 207.44.220.30 www.google.co.kr<br>O1 - Hosts: 207.44.220.30 www.google.com.mx<br>O1 - Hosts: 207.44.220.30 www.google.nl<br>O1 - Hosts: 207.44.220.30 www.google.co.nz<br>O1 - Hosts: 207.44.220.30 www.google.pl<br>O1 - Hosts: 207.44.220.30 www.google.pt<br>O1 - Hosts: 207.44.220.30 www.google.com.ru<br>O1 - Hosts: 207.44.220.30 www.google.com.sg<br>O1 - Hosts: 207.44.220.30 www.google.co.th<br>O1 - Hosts: 207.44.220.30 www.google.com.tr<br>O1 - Hosts: 207.44.220.30 www.google.com.tw<br>O1 - Hosts: 207.44.220.30 go.google.com<br>O1 - Hosts: 207.44.220.30 google.at<br>O1 - Hosts: 207.44.220.30 google.be<br>O1 - Hosts: 207.44.220.30 google.de<br>O1 - Hosts: 207.44.220.30 google.dk<br>O1 - Hosts: 207.44.220.30 google.fi<br>O1 - Hosts: 207.44.220.30 google.fr<br>O1 - Hosts: 207.44.220.30 google.com.hk<br>O1 - Hosts: 207.44.220.30 google.ie<br>O1 - Hosts: 207.44.220.30 google.co.il<br>O1 - Hosts: 207.44.220.30 google.it<br>O2 - BHO: DefaultSearch.SeekSeek - {5074851C-F67A-488E-A9C9-C244573F4068} - C:\WINDOWS\ieasst.dll<br>O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe<br>O4 - HKLM\..\Run: [Mwsvm] C:\WINDOWS\mwsvm.exe<br>O4 - HKLM\..\Run: [absr] C:\WINDOWS\mwsvm.exe  <br>O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\System32\tbctray.exe<br>O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background<br>O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe<br>O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br>O9 - Extra button: AIM (HKLM)<br>O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)<br>O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)<br>O16 - DPF: Win32 Classes - <br>O16 - DPF: Yahoo! Pool 2 - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/potc_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;tc_x.cab</A><br>O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - &raquo;<A HREF="http://office.microsoft.com/templates/ieawsdc.cab" >office.microsoft.com/templates/ieawsdc.cab</A><br>O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - &raquo;<A HREF="http://www.ipix.com/viewers/ipixx.cab" >www.ipix.com/viewers/ipixx.cab</A><br>O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - &raquo;<A HREF="http://thesims.ea.com/teleport/hotdate/NPC/MaxisHotDateTeleX.cab" >thesims.ea.com/teleport/hotdate/&middot;&middot;&middot;eleX.cab</A><br>O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - &raquo;<A HREF="http://download.yahoo.com/dl/installs/yinst.cab" >download.yahoo.com/dl/installs/yinst.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/drakken/us/win/QuickTimeInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - &raquo;<A HREF="http://rd1.surfernetwork.com/surferplugin.ocx" >rd1.surfernetwork.com/surferplugin.ocx</A><br>O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - &raquo;<A HREF="http://aolcc.aol.com/computercheckup/qdiagcc.cab" >aolcc.aol.com/computercheckup/qdiagcc.cab</A><br>O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - &raquo;<A HREF="http://207.188.7.150/254e0d9dc812f8d03705/netzip/RdxIE601.cab" >207.188.7.150/254e0d9dc812f8d037&middot;&middot;&middot;E601.cab</A><br>O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} (MaxisSuperstarTeleX Control) - &raquo;<A HREF="http://thesims.ea.com/teleport/superstar/MaxisSuperstarTeleX.cab" >thesims.ea.com/teleport/supersta&middot;&middot;&middot;eleX.cab</A><br>O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - &raquo;<A HREF="http://cs6b.instantservice.com/jars/customerxsigned35.cab" >cs6b.instantservice.com/jars/cus&middot;&middot;&middot;ed35.cab</A><br>O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - &raquo;<A HREF="http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi.dll" >us.dl1.yimg.com/download.yahoo.c&middot;&middot;&middot;mapi.dll</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;lash.cab</A><br>O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - &raquo;<A HREF="http://download.abacast.com/download/files/abasetup.cab" >download.abacast.com/download/fi&middot;&middot;&middot;etup.cab</A><br>O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - &raquo;<A HREF="http://fdl.msn.com/public/chat/msnchat45.cab" >fdl.msn.com/public/chat/msnchat45.cab</A><br>O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{33480BEB-FB8D-465D-AE4A-6BB4469C927C}: NameServer = 216.127.92.38<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{3AB061A3-A055-43A0-9B3B-2003FA486F41}: NameServer = 216.127.92.38<br>O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com<br>O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 216.127.92.38<br>O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com<br>O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 216.127.92.38<br>O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 216.127.92.38<br>O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8402060</guid>
<pubDate>Mon, 03 Nov 2003 13:07:13 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8401300</link>
<description><![CDATA[<A HREF="/useremail/u/459195"><b>Reverend Ike</b></A> : <br>It wouldn't hurt to post the HijackThis log. There could be other more subtle parasites present, or some housecleaning needed. I think the assumption here is Qhosts, but if it wasn't, it would be helpful to see what the various Search registry keys are pointing to. If a search option is hijacked to point at hijacksearchadware.com and that address is being blocked by the Hosts file (so the "cannot be displayed" screen would appear), the user wouldn't want to alter their Hosts file, but fix the registry keys instead ...<br><SMALL><br><i>[text was edited by author 2003-11-03 11:22:36]</i><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8401300</guid>
<pubDate>Mon, 03 Nov 2003 11:20:40 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8401275</link>
<description><![CDATA[<A HREF="/useremail/u/591564"><b>pieter arntz</b></A> : It was my understanding, that win9x computers were not vulnerable to the hosts location change, only NT based were.<br>Which might account for mistaking them for two different hijacks.<br>But I could well be lagging in this regard.<br><small>--<br>Metallica rulez</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8401275</guid>
<pubDate>Mon, 03 Nov 2003 11:16:18 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8401033</link>
<description><![CDATA[<A HREF="/useremail/u/525050"><b>Zupe</b></A> : I think there are actually two variants of the search engine hijack seen in connection with the QHosts trojan.  The first just modifies the standard Hosts file, so all that needs to be done is to remove the entries.  The second, which is what  pieter arntz <A HREF="/useremail/u/591564"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> is referring to, actually changes the path that windows uses for the hosts file, and then places a hijacking hosts file in the C:\Windows\Help directory.<br><SMALL>--<br><I>Brain:</I> Pinky, are you pondering what I'm pondering?<BR><I>Pinky:</I> I think so, Brain, but "Snowball for Windows"?</SMALL><br><i>[text was edited by author 2003-11-03 10:37:42]</i><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8401033</guid>
<pubDate>Mon, 03 Nov 2003 10:36:57 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8400845</link>
<description><![CDATA[<A HREF="/useremail/u/591564"><b>pieter arntz</b></A> : Not quite. Since he is using XP, Windows will be looking in the wrong location for the Hosts file.<br>Copy and paste the following into notepad, name it restorehostspath.reg, doubleclick it and confirm that you want to merge it with the registry:<br><br><B>Windows Registry Editor Version 5.00<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]<br>"DataBasePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\<br>00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\<br>64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,65,00,74,00,63,00,00,00<br></B><br><small>--<br>Metallica rulez</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8400845</guid>
<pubDate>Mon, 03 Nov 2003 10:08:29 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8400732</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : I agree with Nam Vet. He only has to edit his Hosts File.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8400732</guid>
<pubDate>Mon, 03 Nov 2003 09:51:52 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8400289</link>
<description><![CDATA[<A HREF="/useremail/u/423197"><b>RankAmateur</b></A> : &raquo;<A HREF="http://mjc1.com/mirror/hjt/" >mjc1.com/mirror/hjt/</A> Explains "HiJackThis" program and gives a link to download it. Post the log from that program back here for more help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8400289</guid>
<pubDate>Mon, 03 Nov 2003 08:31:38 EDT</pubDate>
</item>

<item>
<title>Re: Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8400254</link>
<description><![CDATA[<A HREF="/useremail/u/528483"><b>Nam Vet</b></A> : check your hosts file!!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8400254</guid>
<pubDate>Mon, 03 Nov 2003 08:21:18 EDT</pubDate>
</item>

<item>
<title>Browser Hijack!!</title>
<link>http://www.dslreports.com/forum/remark,8400055</link>
<description><![CDATA[<A HREF="/useremail/u/156829"><b>Paul928</b></A> : Hoping someone here can help me, or lead me in the right direction. I had my browser hijacked, where I couldn't change my homepage. It was like some search engine hijack, and I don't remember the name of it, but I ran Spy Bot, and it detected the hijack files, and I got rid of them. I now have my homepage back normally, but I still can't use any search engines (Yahoo, Google) Every time I go to use the search engines I get "page can't be displayed" BTW this was using IE 6 and Windows XP pro. I downloaded Mozilla, and tried using the search engines using that, with the same results. I think there has to be a system file or registry entry that is duped. I don't remember the name of the hijack, so that's my problem...I can't look for registry entries referring to it.....can anyone make any suggestions?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8400055</guid>
<pubDate>Mon, 03 Nov 2003 07:27:24 EDT</pubDate>
</item>

</channel>
</rss>
