PDA

View Full Version : Google


w1che
January 13th, 2004, 11:43 PM
What happen to google? I can't log on to it any more.. Any of you guys having that problem? If not what address are you using? Thanx.. Ya'll :no:

Harrie
January 13th, 2004, 11:56 PM
No problem here, w1che, I cleared my cache before to make sure, too. Just www.google.com (http://www.google.com) :(

lufbra
January 14th, 2004, 01:43 AM
Works just fine here, just typed in Goodie Twins, they're still with Buzz!! :p

rockboy
January 14th, 2004, 04:22 AM
It's likely been hijacked. Download the latest version of HijackThis and run a scan. Post the log and someone will take a look and help you fix it.

http://www.spywareinfo.com/files/hijackthis.zip

If you do a search in the Cyber Safety Forum I think you'll find you're not the first. You might find enough info there to fix it yourself if you want.

w1che
January 14th, 2004, 09:54 PM
Thanks Guys & Girls..Sorry it took so long.. Still no google..
My Highjack log file..
>>>>>>>>Logfile of HijackThis v1.97.7
Scan saved at 10:54:23 AM, on 1/14/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 SP2 (5.00.3314.2100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\MINILOG.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\MY DOWNLOAD FILES\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: 63.111.66.11 earthlink.weather.com #Home Page
O1 - Hosts: 207.200.89.193 home.netscape.com #Search Page
O1 - Hosts: 207.188.7.80 stations.real.com #.url
O1 - Hosts: 207.46.230.219 www.microsoft.com #.url
O1 - Hosts: 129.42.16.103 www.us.pc.ibm.com #.url
O1 - Hosts: 207.217.114.100 start.earthlink.net #.url
O1 - Hosts: 216.94.197.227 www.nakednews.com #.url
O1 - Hosts: 216.239.39.100 www.google.com #.url
O1 - Hosts: 64.33.3.26 www.romulus2.com #.url
O1 - Hosts: 209.123.109.175 www.dslreports.com #.url
O1 - Hosts: 63.240.4.200 www.americanheritage.com #.url
O1 - Hosts: 216.122.209.152 www.laughmyassoff.com #.url
O1 - Hosts: 128.11.45.142 updates.zdnet.com #.url
O1 - Hosts: 206.144.247.65 www.speakout.com #.url
O1 - Hosts: 65.197.21.130 www.thetrip.com #.url
O1 - Hosts: 209.240.140.19 123greetings.com #.url
O1 - Hosts: 64.225.254.104 www.musl.com #.url
O1 - Hosts: 209.158.194.111 ap.tbo.com #.url
O1 - Hosts: 207.217.98.30 home.earthlink.net #.url
O1 - Hosts: 64.70.15.38 www.imira.com #.url
O1 - Hosts: 64.124.237.148 nortonweb.zdnet.com #.url
O1 - Hosts: 24.94.23.174 korfin.dns2go.com #.url
O1 - Hosts: 207.188.7.117 realguide.real.com #.url
O1 - Hosts: 207.217.114.200 www.earthlink.net #.url
O1 - Hosts: 207.188.7.125 www.real.com #RealPlayer
O1 - Hosts: 206.79.171.51 www.lycos.com #.url
O1 - Hosts: 209.202.221.11 news.lycos.com #.url
O1 - Hosts: 216.115.102.77 www.yahoo.com #.url
O1 - Hosts: 216.115.102.78 ibm.yahoo.com #.url
O1 - Hosts: 206.79.171.196 personal.lycos.com #.url
O1 - Hosts: 206.253.217.21 www.metaspy.com #Home Page
O1 - Hosts: 204.30.121.37 villagegreenapts.net #.url
O1 - Hosts: 209.133.53.130 www.annoyances.org #.url
O2 - BHO: (no name) - {1678F7E1-C422-11D0-AD7D-00400515CAAA} - (no file)
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {7559B76E-0222-4d77-9499-CCE9EB4EDC2F} - C:\PROGRA~1\ADSHIELD\ADSHIELD\ADSHIELD.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\NORTON~2\NAVAPW32.EXE
O4 - HKLM\..\Run: [CookieWall] C:\PROGRAM FILES\ANALOGX\COOKIEWALL\COOKIE.EXE
O4 - HKLM\..\Run: [Omnipage] c:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [MiniLog] C:\WINDOWS\SYSTEM\ZONELABS\MINILOG.EXE -service
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsm32.exe
O4 - Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: Add to filterlist (WebWasher) - http://-Web.Washer-/ie_add
O8 - Extra context menu item: Add to &Block List... - C:\PROGRA~1\ADSHIELD\ADSHIELD\suppress.htm
O8 - Extra context menu item: &Maintain Block List... - C:\PROGRA~1\ADSHIELD\ADSHIELD\maintain.htm
O8 - Extra context menu item: AdShield Option &Settings... - C:\PROGRA~1\ADSHIELD\ADSHIELD\settings.htm
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: AdShield (HKCU)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {0FF3E97F-433D-11D2-B31A-00A0C9B135DB} (CoDetectDigitalRiver Class) - http://www.digitalriver.com/v2.0-doc/dlwizard/wizard3.0.3.5.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://ftp.hp.com/pub/automatic/player/isetup.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security2.norton.com/SSC/SharedContent/sc/bin/cabsa.cab
O16 - DPF: {D6016EE7-A8FF-11D1-B37E-A4759ECD7909} (AxPulse Class) - http://www.mtv.com/mtv/tubescan/animation/vbill/install/Plugins/AxPulse.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security2.norton.com/us/nav/common/common/bin/AvSniff.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {1A4DA620-6217-11CF-BE62-0080C72EDD2D} (MarqueeCtl Object) - http://activex.microsoft.com/activex/controls/iexplorer/x86/marquee.cab
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://www.photoparade.com/autoinstall/phpsetup.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://download.macromedia.com/pub/shockwave/cabs/authorware/awswaxf.cab
O16 - DPF: {713AE1D4-897C-11D2-B2A0-00C04F94B4D5} (WUCorpSuppControl Class) - http://corporate.windowsupdate.microsoft.com/en/wucorpct.CAB
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://204.49.70.59/activex/AxisCamControl.ocx
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003012801/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37865.2803819444
O16 - DPF: {EE2589EB-7FC8-44DB-A892-573F2C4B41E0} - http://pdf.forbes.com/forbesnews/triggernews/ForbesDownloaderSigned.cab
O16 - DPF: {3717DF57-0396-463D-98B7-647C7DC6898A} - http://delivery.inet-traffic.com/intdel.exe
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

AnnMarie
January 14th, 2004, 10:10 PM
Hi w1che - close IE and run Hijack This again. Check the below entries and click on Fix Checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O1 - Hosts: 63.111.66.11 earthlink.weather.com #Home Page
O1 - Hosts: 207.200.89.193 home.netscape.com #Search Page
O1 - Hosts: 207.188.7.80 stations.real.com #.url
O1 - Hosts: 207.46.230.219 www.microsoft.com #.url
O1 - Hosts: 129.42.16.103 www.us.pc.ibm.com #.url
O1 - Hosts: 207.217.114.100 start.earthlink.net #.url
O1 - Hosts: 216.94.197.227 www.nakednews.com #.url
O1 - Hosts: 216.239.39.100 www.google.com #.url
O1 - Hosts: 64.33.3.26 www.romulus2.com #.url
O1 - Hosts: 209.123.109.175 www.dslreports.com #.url
O1 - Hosts: 63.240.4.200 www.americanheritage.com #.url
O1 - Hosts: 216.122.209.152 www.laughmyassoff.com #.url
O1 - Hosts: 128.11.45.142 updates.zdnet.com #.url
O1 - Hosts: 206.144.247.65 www.speakout.com #.url
O1 - Hosts: 65.197.21.130 www.thetrip.com #.url
O1 - Hosts: 209.240.140.19 123greetings.com #.url
O1 - Hosts: 64.225.254.104 www.musl.com #.url
O1 - Hosts: 209.158.194.111 ap.tbo.com #.url
O1 - Hosts: 207.217.98.30 home.earthlink.net #.url
O1 - Hosts: 64.70.15.38 www.imira.com #.url
O1 - Hosts: 64.124.237.148 nortonweb.zdnet.com #.url
O1 - Hosts: 24.94.23.174 korfin.dns2go.com #.url
O1 - Hosts: 207.188.7.117 realguide.real.com #.url
O1 - Hosts: 207.217.114.200 www.earthlink.net #.url
O1 - Hosts: 207.188.7.125 www.real.com #RealPlayer
O1 - Hosts: 206.79.171.51 www.lycos.com #.url
O1 - Hosts: 209.202.221.11 news.lycos.com #.url
O1 - Hosts: 216.115.102.77 www.yahoo.com #.url
O1 - Hosts: 216.115.102.78 ibm.yahoo.com #.url
O1 - Hosts: 206.79.171.196 personal.lycos.com #.url
O1 - Hosts: 206.253.217.21 www.metaspy.com #Home Page
O1 - Hosts: 204.30.121.37 villagegreenapts.net #.url
O1 - Hosts: 209.133.53.130 www.annoyances.org #.url

O2 - BHO: (no name) - {1678F7E1-C422-11D0-AD7D-00400515CAAA} - (no file)

O16 - DPF: {3717DF57-0396-463D-98B7-647C7DC6898A} - http://delivery.inet-traffic.com/intdel.exe

Reboot and see if you can access Google now.

w1che
January 14th, 2004, 11:55 PM
Thanks AnnMarie and everyone else that responded. I don't know what we did but it worked.. I have my google back.. :D

AnnMarie, I'ed take you out to dinner but I know that dang chicken would get jealous and I would have to put up with him.. :glug: :D

AnnMarie
January 15th, 2004, 12:06 AM
Glad we could help w1che :D

Heh, couldnt we take the chicken too, y,know, roasted with gravy http://www.boomspeed.com/anniefriday/rofl.gif

Harrie
January 15th, 2004, 12:20 AM
Take me out instead then, w1che, he won't be jealous then! He thinks of me as a nutter, not sexy! :p

PS: Oh, ya'll are gonna roast him! Well in that case, take BOTH of us out and we can all enjoy that!

lufbra
January 15th, 2004, 03:49 AM
OY, ya wingnut. Harrie, I never said you weren't sexy!!! :(

Okay, yer a sexy nutter, is that allright for ya's!! ;)

As for you two, AnnMarie n' WD40.......Ya can both go get knotted!! :p

Harrie
January 15th, 2004, 04:26 AM
Okay, yer a sexy nutter, is that allright for ya's!! ;)

:D :D :D :D :D :D :D :D

YES!!

w1che
January 15th, 2004, 04:39 AM
:D .. Hey AM.. I like that roasted Chicken idea... Of course you're sexy Harrie the problem is all that Chicken can see is someone trying to get his beer stash...To him beer is sexy... :p :D

lufbra
January 15th, 2004, 04:45 AM
Yer just jealous, WD40, see how I called Harrie a wingnut, then a sexy nutter, and it got her all excited?

What would the Goodie Twins have said to ya, if ya's said the same things to them, not that the Goodie Twins could have replied, since they're dolls with "Made In Taiwan" tattooed on they're ankles!! :p

AnnMarie
January 15th, 2004, 11:51 AM
As for you two, AnnMarie n' WD40.......Ya can both go get knotted!!

Awwww, Dave, ya hurt my feelings :(
















Hehehehe http://www.boomspeed.com/anniefriday/rofl.gif

zipulrich
January 15th, 2004, 05:13 PM
This leaves the Jokes forum as the only place without HijackThis logs. Hey modmidget, got any good Hijack jokes? ;)

dammit
January 15th, 2004, 06:13 PM
Hey zip.....I've seen a few logs that SHOULD be in the jokes forum!! :D

lufbra
January 16th, 2004, 01:08 AM
This leaves the Jokes forum as the only place without HijackThis logs. Hey modmidget, got any good Hijack jokes? ;)
When did ya last look? ;)