Thread: hijackthis help
View Single Post
Old 19-08-2004, 02:16 PM   #4 (permalink)
Apex
Monkey
 
Apex's Avatar
 
Join Date: Jul 2003
Location: RobertTown, Liversedge, West Yorkshire
Posts: 3,066
Thanks: 37
Thanked 4 Times in 4 Posts
Apex's system
Code:
O2 - BHO: (no name) - {1AA43E7A-E849-74B6-DB55-67557CAC2D3D} - C:\WINDOWS\System32\twb.dll
O2 - BHO: (no name) - {1EFE3420-E810-21BC-D555-67557CAC2D3D} - C:\WINDOWS\System32\ftfwf.dll
Code:
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
They look a bit sus to me

Code:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://education.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost;
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://education.dellnet.com/ 
Nothing too bad...but doesn not tell us why you get the site you are.

Can you post what is in your host file ?

it is located in

Code:
C:\WINDOWS\system32\drivers\etc\
and it's called "Hosts"

If you carn't view it you might have to turn show "system files" on

Andrew

Apex is offline   Reply With Quote