Greetings...
i would need some help to restore my internet explorer.
here is the problem: when i using addresses from IE, it show me:
%65%68%74%74%70%2e%63%63/? and after this original address.
exmp:
%65%68%74%74%70%2e%63%63/?www.google.com...
i tried solve this problem with ad-aware, but after cleaning, "possible browser hijack attempt" (data miner) is back
for now, i can surf on internet, but this is realm pain in my eyes, and i afraid that something worse could happen?
this is my first "meeting" with hijacks, so i'm not sure did i propertly posted log:
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
23. 05. 04 18:40:11 - Scan started. (Smart mode)
Listing running processes
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
#:1 [kernel32.dll]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4279186995
Threads : 4
Priority : High
FileSize : 460 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright © Microsoft Corp. 1991-1999
CompanyName : Microsoft Corporation
FileDescription : Win32 Kernel core component
InternalName : KERNEL32
OriginalFilename : KERNEL32.DLL
ProductName : Microsoft® Windows® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:2 [msgsrv32.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294918747
Threads : 1
Priority : Normal
FileSize : 11 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright © Microsoft Corp. 1992-1998
CompanyName : Microsoft Corporation
FileDescription : Windows 32-bit VxD Message Server
InternalName : MSGSRV32
OriginalFilename : MSGSRV32.EXE
ProductName : Microsoft® Windows® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:3 [mprexe.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294931659
Threads : 1
Priority : Normal
FileSize : 28 KB
FileVersion : 4.10.1998
ProductVersion : 4.10.1998
Copyright : Copyright © Microsoft Corp. 1993-1998
CompanyName : Microsoft Corporation
FileDescription : WIN32 Network Interface Service Process
InternalName : MPREXE
OriginalFilename : MPREXE.EXE
ProductName : Microsoft® Windows® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:4 [mmtask.tsk]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294930307
Threads : 1
Priority : Normal
FileSize : 1 KB
FileVersion : 4.03.1998
ProductVersion : 4.03.1998
Copyright : Copyright
CompanyName : Microsoft Corporation
FileDescription : Multimedia background task support module
InternalName : mmtask.tsk
OriginalFilename : mmtask.tsk
ProductName : Microsoft Windows
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:5 [mstask.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294957059
Threads : 2
Priority : Normal
FileSize : 116 KB
FileVersion : 4.71.1959.1
ProductVersion : 4.71.1959.1
Copyright : Copyright © Microsoft Corp. 1997
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskScheduler
OriginalFilename : mstask.exe
ProductName : Microsoft
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:6 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294964391
Threads : 6
Priority : Normal
FileSize : 176 KB
FileVersion : 4.72.3110.1
ProductVersion : 4.72.3110.1
Copyright : Copyright © Microsoft Corp. 1981-1997
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft® Windows NT® Operating System
Created on : 23. 04. 99 20:22:00
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:7 [taskmon.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294841067
Threads : 1
Priority : Normal
FileSize : 28 KB
FileVersion : 4.10.1998
ProductVersion : 4.10.1998
Copyright : Copyright © Microsoft Corp. 1998
CompanyName : Microsoft Corporation
FileDescription : Task Monitor
InternalName : TaskMon
OriginalFilename : TASKMON.EXE
ProductName : Microsoft® Windows® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:8 [systray.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294851683
Threads : 2
Priority : Normal
FileSize : 32 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright © Microsoft Corp. 1993-1998
CompanyName : Microsoft Corporation
FileDescription : System Tray Applet
InternalName : SYSTRAY
OriginalFilename : SYSTRAY.EXE
ProductName : Microsoft® Windows® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:9 [sm56hlpr.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294864115
Threads : 1
Priority : Normal
FileSize : 404 KB
FileVersion : 4.10.80.4
ProductVersion : Release 4.10 AD04/AD05/AD06 Build 80.4
Copyright : Copyright
CompanyName : Motorola Inc.
FileDescription : SM56 Modem Win32 Utility
InternalName : SM56 Modem Helper
OriginalFilename : SM56HLPR.EXE
ProductName : Motorola SM56 PCI Modem
Created on : 12. 05. 12 13:23:20
Last accessed : 22. 05. 04 22:00:00
Last modified : 11. 11. 99 17:29:06
#:10 [internat.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294871819
Threads : 1
Priority : Normal
FileSize : 28 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright © Microsoft Corp. 1998
CompanyName : Microsoft Corporation
FileDescription : Keyboard Language Indicator Applet
InternalName : INTERNAT
OriginalFilename : INTERNAT.EXE
ProductName : Microsoft® Windows® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:11 [ddhelp.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294834763
Threads : 6
Priority : Realtime
FileSize : 31 KB
FileVersion : 4.08.01.0881
ProductVersion : 4.08.01.0881
Copyright : Copyright
CompanyName : Microsoft Corporation
FileDescription : Microsoft DirectX Helper
InternalName : DDHelp.exe
OriginalFilename : DDHelp.exe
ProductName : Microsoft
Created on : 30. 10. 01 06:10:00
Last accessed : 22. 05. 04 22:00:00
Last modified : 30. 10. 01 06:10:00
#:12 [wmiexe.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294892715
Threads : 3
Priority : Normal
FileSize : 16 KB
FileVersion : 5.00.1755.1
ProductVersion : 5.00.1755.1
Copyright : Copyright © Microsoft Corp. 1981-1998
CompanyName : Microsoft Corporation
FileDescription : WMI service exe housing
InternalName : wmiexe
OriginalFilename : wmiexe.exe
ProductName : Microsoft® Windows NT® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:13 [rnaapp.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294808319
Threads : 3
Priority : Normal
FileSize : 44 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright © Microsoft Corp. 1992-1996
CompanyName : Microsoft Corporation
FileDescription : Dial-Up Networking Application
InternalName : RNAAPP
OriginalFilename : RNAAPP.EXE
ProductName : Microsoft® Windows® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:14 [tapisrv.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294697315
Threads : 5
Priority : Normal
FileSize : 120 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright © Microsoft Corp. 1994-1998
CompanyName : Microsoft Corporation
FileDescription : Microsoft
InternalName : Telephony Service
OriginalFilename : TAPISRV.EXE
ProductName : Microsoft® Windows® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:15 [pstores.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294715543
Threads : 3
Priority : Normal
FileSize : 79 KB
FileVersion : 5.00.1877.3
ProductVersion : 5.00.1877.3
Copyright : Copyright © Microsoft Corp. 1981-1998
CompanyName : Microsoft Corporation
FileDescription : Protected storage server
InternalName : Protected storage server
OriginalFilename : Protected storage server
ProductName : Microsoft® Windows NT® Operating System
Created on : 01. 01. 01
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:16 [iexplore.exe]
FilePath : C:\PROGRAM FILES\INTERNET EXPLORER\
ProcessID : 4294810979
Threads : 10
Priority : Normal
FileSize : 76 KB
FileVersion : 5.00.2614.3500
ProductVersion : 5.00.2614.3500
Copyright : Copyright © Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Microsoft Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Microsoft® Windows ® 2000 Operating System
Created on : 23. 04. 99 20:22:00
Last accessed : 22. 05. 04 22:00:00
Last modified : 23. 04. 99 20:22:00
#:17 [ad-aware.exe]
FilePath : D:\LAVASOFT\AD-AWARE 6\
ProcessID : 4294759239
Threads : 2
Priority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 12. 05. 12 18:00:10
Last accessed : 22. 05. 04 22:00:00
Last modified : 12. 07. 03 20:00:20
Memory scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0
Started registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0
Started deep registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"
Possible browser hijack attempt : .Default\Software\Microsoft\Internet Explorer\MainStart Pageabout:blank
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_USERS
Object : .Default\Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"
Deep registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 2
Objects found so far: 2