Over 1 million tech questions and answers.

[Solved] 4bf65.ilxt has invaded me

Q: [Solved] 4bf65.ilxt has invaded me

Hi guys

I've got the same prob as Petta808 in thread http://forums.techguy.org/showthread.php?t=248978
and I've tried to do what you suggested him to do, but without succes. Could sumone pleeeeeeeezzzzz help me. the PC's soon to be located in my backyard if this goes on much longer...

ty

IG

RELEVANCY SCORE 200
Preferred Solution: [Solved] 4bf65.ilxt has invaded me

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

A: [Solved] 4bf65.ilxt has invaded me

Read other 14 answers
RELEVANCY SCORE 133.2

so things are , aside from annoying 4bf65.ilxt start up page ( that fuc*** undeletable sp.html page and registry entrys ) i have one pop up everytime i close norton antivirus . Adware didn't work.
This is the hhjack log :

Logfile of HijackThis v1.98.0
Scan saved at 5:12:37, on 28/07/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Archivos de programa\Archivos comunes\Symantec Shared\ccSetMgr.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\Archivos de programa\Analog Devices\SoundMAX\SMAgent.exe
E:\Archivos de programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe
E:\WINDOWS\Explorer.EXE
E:\Archivos de programa\Archivos comunes\Symantec Shared\ccApp.exe
E:\Archivos de programa\DU Meter\DUMeter.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Archivos de programa\D-Tools\daemon.exe
E:\Archivos de programa\MYIE2\MyIE.exe
E:\Archivos de programa\ReGetDx\regetdx.exe
E:\WINDOWS\System32\dwwin.exe
E:\Archivos de programa\Winamp\winamp.exe
E:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://E:\DOCUME~1\q\CONFIG~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://E:\DOCUME~1\q\CONFIG~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Inter... Read more

A:[Solved] 4bf65.ilxt has invaded me

Read other 11 answers
RELEVANCY SCORE 94

I've seen a couple of other threads mentioning this same problem, but most advised starting a new one if you had the same problem, so here goes...

Four major things happen. Least annoying is that my homepage constantly resets to "about:blank" a 'my search' page of some description. (I never open my homepage, but from the little telstra button on the bottom right...)

Also, two entries constantly re-appear in my favourites after being deleted.

Finally, I get constant pop-ups screaming at me about spyware, and whenever I try to use hotmail it re-directs me to this search page... only hotmail though, no other sites.

I've got an up-to-date virus scanner and firewall, but nothing comes up...

So... can someone help an internet-illiterate fool fix his silly problem?

Oh yeah, I run Windows Xp, Internet explorer (the latest one I think... don't know what number...).
 

A:[Solved] Hijacked by http://4bf65.ilxt.info/

Read other 14 answers
RELEVANCY SCORE 94

I don´t know what to do! I´ve tried Spybot S&D but that doesn´t help, Ad-aware doesn´t either. Could anyone help me, it really bugs me!!!

Petta
 

A:[Solved] Hijacked by 4bf65.ilxt.info and c1dcon.d8t !?!

Read other 13 answers
RELEVANCY SCORE 86.8

Hi

My problem is the following:

Everytime i click in my browser on a link i get these annoying messages about spyware found on your pc etc. When i run adware it removes some files but every time the pc is restarted the problem occurs again. Now i found that there is a map in my history called 4bf65.ilxt.info which contains all those IE-windows.

I started searching for a sollution and ended up on this site and saw the thread about 4bf65 from today. I followed the first part of the instructions and made an hijack this log file:

Logfile of HijackThis v1.98.0
Scan saved at 20:11:55, on 13/07/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\KHOOKER.EXE
C:\PROGRAM FILES\PCI AUDIO APPLICATIONS\MIXER.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\UNLOAD\HPQCMON.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\ULEAD SYS... Read more

Read other answers
RELEVANCY SCORE 86.8

can anyone help?

Keep getting a popup about security risks on my PC. Even if off-line it still tries to open a browser window.

This came from the Norton log -

19/07/2004 20:07:29,Supervisor,http://4bf65.ilxt.info/popup2.php?pin=22,User Agent,Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1),"Private Data: Date Time: 19/07/2004 20:07:29 User: Supervisor Action: Permitted Type: User Agent URL: http://4bf65.ilxt.info/popup2.php?pin=22 Data: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) "

I've seen in the archive that someone has had this problem previously and I've downloaded HijackThis which gave the following.
Logfile of HijackThis v1.98.0
Scan saved at 21:35:42, on 19/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\sy... Read more

Read other answers
RELEVANCY SCORE 86.8

I know I am not the first one to have run into this popup and it has been driving me nuts... it does not always happen when i go online though... but when it does, it opens multiple windows until my resources are maxed up. I have run "Highjackthis" and have saved the log.

Your assistance on how to get rid of this problem will be appreciated
 

A:Need Help with 4bf65.ilxt.info

it was just today that i got rid of that, thanks to the help of the people here(now i have a virus infected files, but thats another story).

so, to save some steps -
1. download spybot search and destroy, update it, run a scan and let it fix all that's in red.
2. download FINDnFix. install it, click on the "LOG!Bat" file, and post the log here.
3. run again the HijeckThis and also post the log.

I wish i could help you from here, but that's for more expert people to do....
 

Read other 2 answers
RELEVANCY SCORE 86.8

I believe I have been hijacked by this. I just downloaded hijackthis and here is my scan. Can anyone check it out?
 

Read other answers
RELEVANCY SCORE 86

Hi!

My homepage had been changed, and I creat a hompage value (1) by regedit - it didn't work, and then, I found this forum!!

here is the HJT log:

Logfile of HijackThis v1.98.0
Scan saved at 1:20:07, on 2004-7-28
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
E:\Norton\Norton AntiVirus\navapsvc.exe
E:\Norton\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Hijack This\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Norton\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {F5E047D0-3D26-445D-865D-F9A201F87EE4} - C:\WINDOWS\System32\gad.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Norton\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDa... Read more

A:Help: Hijacked by 4bf65.ilxt.info

Read other 9 answers
RELEVANCY SCORE 86

I´ve tried Ad-aware 6.0 but that doesn´t help. Could anyone help me, it really bugs me!!!

I have Windows 2000 Professional, and Internet Explorer 6.0

Thank You,
Dorin
 

A:Hijacked by 4bf65.ilxt.info

Read other 11 answers
RELEVANCY SCORE 86

Can anybody help me with the above problem?
 

A:Hijacked by 4bf65.ilxt.info

Read other 14 answers
RELEVANCY SCORE 86

I am new to this so please bear with me, I have recently joined aol broadband with McAfee firewall and I use adaware. This has identified a popup which is rendering my internet unusable. I found some old threads on this site and have downloaded hijackthis which produces the log shown below:-

Can you help - I have been recommended purchasing Kaspersky - what do people think abpout this as a way of stopping theses problem

Logfile of HijackThis v1.97.7
Scan saved at 18:03:04, on 25/08/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\PDESK.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE
C:\PROGRAM FILES\BT VOYAGER 105 ADSL MODEM\DSLSTAT.EXE
C:\PROGRAM FILES\BT VOYAGER 105 ADSL MODEM\DSLAGENT.EXE
C:\PROGRAM FILES\VOYAGERTEST\FTS.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\NETSTAT.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\AOL SPYWARE PROTECTION\AOLSP SCHEDULER.EXE
C:\PROGRAM FILES\AOL 9.0\AOLTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
C:\WINDOWS\SYSTEM\DDH... Read more

A:Hijacjked by 4bf65.ilxt.info

Read other 10 answers
RELEVANCY SCORE 86

hi,

I have been having trouble with Internet Explorer; my default page has for some time been 'about:blank', even though I have repeatedly reset it using the "Use Blank' button. There was also 'searchdot.net'. More recently I have been bombarded by pop-ups, which I traced to 4bf65.ilxt.info. I assume you have heard this story before.

I downloaded HijackThis and ran it. The log is pasted in below. Can you please tell me what to do next? Thanks you very much.

bgdog
Logfile of HijackThis v1.98.0
Scan saved at 12:07:58 PM, on 7/24/04
Platform: Windows NT 4 SP6 (WinNT 4.00.1381)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolss.exe
E:\quartus2we\bin\JTAGServer.exe
C:\WINNT\system32\RpcSs.exe
c:\winnt\system32\pstores.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\nutsrv4.exe
C:\WINNT\System32\nddeagnt.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\SysTray.Exe
C:\WINNT\System32\loadwc.exe
C:\WINNT\System32\CWB3DSnd.exe
C:\WINNT\System32\msrexe.exe
C:\Program Files\Linksys\WMP11 Config Utility\WMP11Cfg.exe
E:\p\XVision\Common files\Vision\vservice.exe
E:\Palm\HOTSYNC.EXE
E:\p\XVision\COMMON~1\Vision\dbserv.exe
C:\WINNT\System32\ddhelp.exe
C:\PROGRA~1\Plus!\MICROS~1\iexplore.exe
D:\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.searc... Read more

A:plagued by 4bf65.ilxt.info and others

Closing duplicate.

Reply here:

http://forums.techguy.org/showthread.php?p=1803341#post1803341
 

Read other 1 answers
RELEVANCY SCORE 84.8

my homepage is hijacked and i always get pop up menus everytime i start up IE. now it's gotten to the point where it'll shut IE down randomly. any help/guidance would be greatly appreciated. thanks in advance.

Logfile of HijackThis v1.98.0
Scan saved at 12:34:52 PM, on 7/17/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP1 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\APC\PowerChute Business Edition\agent\pbeagent.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\PROGRAM FILES\DELL\RESOLUTION ASSISTANT\COMMON\BIN\RxMon.exe
C:\PROGRA~1\NORTON~3\SPEEDD~1\nopdb.exe
C:\WINNT\System32\ZipToA.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\WINNT\System32\Atiptaxx.exe
C:\WINNT\System32\Promon.exe
C:\Program Files\S... Read more

A:about:blank,http://4bf65.ilxt thang

Closing duplicate.

Reply here:

http://forums.techguy.org/showthread.php?p=1788246#post1788246
 

Read other 1 answers
RELEVANCY SCORE 84.8

Hello. I am new to this site and found that it helped many people and was wondering if you could help me. As for me I am really lost when it comes to computers but I need it for work. Lately When I try and run Internet Explorer or my internet on AOL I get continuous popups. All of them are from the website http://4bf65.ilxt.info. I also get my homepage redirected to about:blank. I have no idea what this is but I am guessing it's a virus. Just to let you know I am using a Windows 98 and the Interent Explorer 6.0. I was also advisedby family to us AdAware and Spy Hunter but sadly this hasn't worked. Any help with this would be greatly appreciated. ~Snoopy
 

A:http://4bf65,ilxt.info & about:blank

Read other 16 answers
RELEVANCY SCORE 84.8

Hey there I have this stupid problem where my IE keeps redirecting me to 4bf65.ilxt.info pages.

I'm sure you're all familiar with it. I've downloaded Hijackthis and last time i tried it on my own and it didn't pan out. So if someone could help me please I've got a freelance project to finish and I really need to get in my email.

thanks... and here's my Log:
Logfile of HijackThis v1.97.7
Scan saved at 1:05:23 PM, on 04/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\program.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Adrian\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\AGE~1.ADR\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\AGE~1.ADR\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Mi... Read more

Read other answers
RELEVANCY SCORE 70

Here is my hijack log file ::

++++++++++++++++++++++++++++++++++++++++++++++

Logfile of HijackThis v1.98.2
Scan saved at 20:53:27, on 16-9-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Winamp\Winampa.exe
C:\PROGRA~1\GUITAR~1.18\uninstall.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Plextor\PlexTool.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Fil... Read more

Read other answers
RELEVANCY SCORE 66.4

Hello everyone !

i've just become a new member of this forum. i'm not exactly a computer wizard, so i hope somebody can help me. (my computer runs on Windows ME)

everytime i start up IE I get the same page "about.blank", followed by a pop-up "4bf65.ilxt.info" that says i have a spyware-problem and need to download a kind of program. i got suspicious and didn't do that. instead i started looking on google what links i could find about "about.blank" and "4bf65.ilxt.info".

this is my HJT-log.

Logfile of HijackThis v1.98.2
Scan saved at 8:41:09, on 18/08/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\DEVGULP.EXE
C:\CPQS\BWTOOLS\SCCENTER.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\AVCONSO... Read more

A:"about.blank" + "4bf65.ilxt.info" = help me !

is there anybody out there who can help? thanks !
 

Read other 2 answers
RELEVANCY SCORE 52.8

Hi everybody.

I have a problem with pop ups. something called 38155ilxt.info is making a lot of noise. There always a pop up informing me that my pc is full of spyware. My homepage is always redirect to about:blank

I read something on this ilxt but I'm not able to solve the problem.

Please help me
 

A:[Solved] Hijacked by ilxt

Read other 16 answers
RELEVANCY SCORE 52.8

Hello,

Whenever I'm logged into Hotmail and click to go to another page, I always get a pop-up from ilxt.info informing me my computer is full of spyware. I also get various run time errors frequently and my computer runs very slowly. I have followed advice from archive threads and achieved the following using HijackThis:

Logfile of HijackThis v1.97.7
Scan saved at 20:10:31, on 24/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\WINDOWS\System32\msblast.exe
C:\Downloads\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Darryn\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Darryn\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Darryn\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Darryn\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Darryn\LO... Read more

A:[Solved] ilxt.info pop-ups

Read other 15 answers
RELEVANCY SCORE 52

i cant seem to open my hotmail n yahoo email account..
instead my IE was brought to the about:blank page..
i'm new here..
cud sumone guide me to get rid of tht thing
this is my hijackthis log...
Logfile of HijackThis v1.97.7
Scan saved at 3:20:55 PM, on 7/30/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Java\j2re1.4.2\bin\javaw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\rsvp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Y... Read more

A:[Solved] ilxt.info..help plss!!

Read other 15 answers
RELEVANCY SCORE 52

I,

my default search page is sp.html and i can't remove it. If someone can help me, you'll find above the log file from Hijack this :

Logfile of HijackThis v1.98.2
Scan saved at 00:09:03, on 19/08/2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\FICHIERS COMMUNS\EPSON\EBAPI\SAGENT2.EXE
C:\PROGRAM FILES\FICHIERS COMMUNS\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\FICHIERS COMMUNS\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\ADVTOOLS\NPROTECT.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\TPPALDR.EXE
C:\PROGRAM FILES\FICHIERS COMMUNS\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\PWSTRAY.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\INETSRV\PWS.EXE
C:\PROGRAM FILES\EPSON\EPSON SMART PANEL FOR SCANNER\ESPMAIN.EXE
C:\WINDOWS\SYSTEM\INETSRV\INETINFO.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,Search = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blan... Read more

A:[Solved] Hijacked by ilxt.info please Help

Read other 12 answers
RELEVANCY SCORE 51.6

I just stumbled across your forums while I was looking for a fix for the ilxt.info problem I've been having since a few days ago. I was wondering if somebody could help me fix this. I've already done some of the steps as I read them here, http://forums.techguy.org/showthread.php?p=1810313 . Please walk me through the rest of the steps...

I first did Hijack This... here's the log file...

Logfile of HijackThis v1.97.7
Scan saved at 5:56:21 PM, on 8/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\... Read more

A:[Solved] Yet another ilxt.info victim.... please help asap!

Read other 15 answers
RELEVANCY SCORE 51.6

Windows XP
Dell Inspiron 5100
Internet explorer

This has happened before to others but im still not sure how to go about fixing it. Every so often when i click a link it brings me to the address:
http://296f8.ilxt.info/index.php?aid=632
and a pop-up appears telling me that my computer is infected with spyware...

Ive run ad-aware and here is the log-file from HJT...Please help me to understand!:

Logfile of HijackThis v1.98.2
Scan saved at 4:14:19 PM, on 8/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\... Read more

A:[Solved] Problem with ilxt.info popups...please help?

Read other 11 answers
RELEVANCY SCORE 50.4

PLS HELP~~

-------------------------------------------

Logfile of HijackThis v1.98.0
Scan saved at AM 12:28:53, on 2004/8/2
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\POPROXY.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\HSM-6108\SHWICON.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
E:\WIN98 RESOURCE\HIJACKTHIS_LAST.EXE
C:\WINDOWS\NOTEPAD.EXE

R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D... Read more

A:[Solved] Annoying ilxt.info... popup, stealing my about:blank, HELP.

Read other 10 answers
RELEVANCY SCORE 48.4

In spite of all the security software I have, it appears that my system may have been invaded once more Symptons: 1. Virus Program (AVG) gets stuck in the middle of a scan and cannot progress (I have to close it manually). 2. Everything is VERY slow (yes, I did defrag recently). 3. System won't re-start (I have to hold the power button in to shut it down and restart. 4. A short time ago, the system went into a "coma" and wouldn't even re-start while holding the power button in; I had to actually unplug the power supply and plug it in to get it to restart. I did recently download updates from Microsoft, but I was having these problems before that.

A scan from HijackThis follows. As always, any help will be greatly appreciated

Logfile of HijackThis v1.99.1
Scan saved at 12:41:35 PM, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\L... Read more

A:Solved: Invaded Again?

Read other 7 answers
RELEVANCY SCORE 48.4

Hello,
I have been infected by many viruses and I can't seem to get rid of them. I run Ad-aware SE profess., Spybot, but to no avail. I recently downloaded Hijack this and ran it. Can anyone help me please?

Logfile of HijackThis v1.99.1
Scan saved at 12:55:42 PM, on 3/17/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\CTNOTIFY.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\3DFX INTERACTIVE\3DFX TOOLS\APPS\3DFXMAN.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\MEDIADET.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\CMD32.EXE
C:\WINDOWS\SYSTEM\MSMSGS.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IMGICON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SYSNT.EXE
C:\WINDOWS\SYSTEM\SYSNT.EXE
C:\WINDOW... Read more

A:Solved: I was invaded and need help

Read other 16 answers
RELEVANCY SCORE 47.6

I was having trouble accessing the web, and I was trying to get an Ethernet network (my computer and my wife's) to work. I looked in Network connections and I found these two: www.ecestudents.ul.ie\course_pages and www.visitscarlett.com. Neither my wife nor I are connecting to those sites, and both of our IE were not open, so I assume this means my network is open and being used by at least two people. I run AVG, Tiny Firewall, and Counterspy on real time. I scanned the computer using Panda Activescan and did not find anything. Process Explorer does not show anything unusual.

Here is the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 7:39:33 AM, on 1/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\PFShared\UmxCfg.exe
C:\Program Files\Tiny Firewall\UmxFwHlp.exe
C:\Program Files\Common Files\PFShared\UmxPol.exe
C:\Program Files\Tiny Firewall\UmxAgent.exe
C:\Program Files\Tiny Firewall\UmxTray.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Prog... Read more

A:Solved: Help! My network is invaded from outside!

Read other 7 answers
RELEVANCY SCORE 47.6

Hi, I'm new here and am just about computer literate - I get by in other words - just! I've had absolutely no problems with my computer until yesterday. I suddenly started receiving alerts informing me that AVAST 4.5 had detected a virus. I sent it to the virus chest in AVAST and deleted it. This happened about 12 more times! I then ran SpyBot S&D and deleted what it detected, and did the same with ADAWARE. I am still receiving virus alerts intermittently from AVAST, and am still having to delete them as above. The virus is Win32:Trojan-gen. How do I get rid of it from my computer???

Below is the HijackThis logfile from today. I would be grateful for any help - please!!!!!!

Logfile of HijackThis v1.98.2
Scan saved at 15:01:23, on 04/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\evn... Read more

A:Solved: Invaded by Trojan

Read other 9 answers
RELEVANCY SCORE 47.6

semi experienced user using Win 98 SE

I have been taken over by banner ads

I have adwared and spybot search and destroyed as per instructed by previous victims

here is my hijack log

Logfile of HijackThis v1.98.2
Scan saved at 3:28:58 PM, on 8/15/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\MOTIVE\MOTIVEASSISTANT\MOTMON.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\HPZTSB08.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOTDD01.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\HIJACK THIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_... Read more

A:[Solved] I have been invaded by Bannerfarm.Ace

Read other 13 answers
RELEVANCY SCORE 47.6

It seems I have an unwanted visitor on my system. You folks helped me out last time so I hope you can do so again.

I am occassionally getting pop-ups that inform me of a security breach in my Windows Messenger Service (which I never use) with the recommendation that I go to Windows-patch.info. This site (visit if if you like), informs the user of the details of the security breach and directs you to a downloadable patch for 19.95!

Obviously, someone has dumped something onto my system. (Interestingly, the first time this popped up is when I was reloading Norton Internet Security! Ironic...)

Anyone recognize this, and have a way to get rid of it?

Thanks again,
Pradhan
 

A:[Solved] My computer has been invaded

Read other 16 answers
RELEVANCY SCORE 47.6

Damn I tried to download a plugin for WMP, but got more then I bargined for, please check my hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 11:34:36 PM, on 3/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Video Access ActiveX Object\isamntr.exe
C:\Program Files\Video Access ActiveX Object\pmsnrr.exe
C:\Program Files\Video Access ActiveX Object\isamini.exe
C:\Program Files\Video Access ActiveX Object\pmmnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Thomas\Desktop\HijackThis.exe

R1 - HKCU\Software\... Read more

A:Solved: My Laptop is invaded

Read other 14 answers
RELEVANCY SCORE 47.6

Hello to all,
It's nice to be back. Simply put, I seem to have been "invaded" by weird snippets of news broadcasts both national and international, some of which are overlaid with others or music and verbal together. This has occured at the desktop screen with nothing else running, while running a simple Disk Cleanup utility, or just suddenly while surfing the web etc. I've run my Avast virus program, my Ad-Aware as well and nothing has turned up. The constant audio is fast becoming really annoying until I just turn off the speakers for good. Can we eliminate whatever gremlins I've incurred here??

Thanks in advance,
Pete C.
 

A:Solved: Invaded by Radio in XP

Read other 16 answers
RELEVANCY SCORE 47.6

Microsoft Windows, SpyBot, and Norton all sent a deluge of windows saying they had detected changes. SpyBot sent 7-10 warnings, one of them saying "SpyBot. Search & Destroy has detected an important registry item entry that has been changed. Catagory: System Startup global entry; Change: Value deleted; Entry: elkfqxcj; Old data: c:\windows\elkfqxcj.exe; [allow change][Deny change].
Each of these SpyBot notices had a different entry. Since then my computer is extremely slow, freezes up when left for any time. A window pops us when opening and when changing applications titled "16 bit Windows Subsystem", saying:
C:\Windows\System32\AutoExec.NT. The system file is not suitable for running MS-DOS and Microsoft Window's applications. Choose 'close' to terminate application. [close] [ignore]
I was very confused to begin with, not knowing whether to close or ignore. I had had a window saying that AdAware might not like some SpyBot changes, so I'm not sure if I ignored or closed the first SpyBot window. But when I received so many I chose 'close'. I have been able to use some applications, slowly, but some not at all. I'm afraid to send anyone e-mail for fear of sending anyone else the problem.
Can anyone tell me how to restore my computer. I have tried "restore" with nothing gained. Thanks for any help. lilart
 

A:Solved: Worm? Something has invaded my PC

Read other 16 answers
RELEVANCY SCORE 47.6

Hello,

A friend of mine brought me they're machine complaining that he has trojans on his machine. His AVG free keeps finding and deleting them, but they return on each restart. I installed and ran AVG anti-spyware in Safemode and found a few entries which I deleted. I also rebooted and ran AVG Anti-RootKit which found nothing, however when the search got to 96% complete, it triggered AVG anti-virus to detect the Trojan 'Collected.11.B' which it deleted, however the problem remains - I know this because IE and Firefox keeps trying to open werid URLs.

I searched your posts and found one about this torjan, but the instructions are specific to that user; I hope you can help. I already downloaded HijackThis and did a scan. Please see the report below. I should mention that the machine is a Dell Desktop running XP Home SP2.

Thanks in advance for any help!

HijackThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 9:27:35 AM, on 5/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc... Read more

A:Solved: Invaded by a Torjan

Read other 16 answers
RELEVANCY SCORE 47.6

My computer just got loads of spywares and viruses and i need help.

I've fixed alot of the problems but one that bugs me. IE is messed up and whenever I try to click on something using Javascript, a window will open and either never load, or show up and then say 404 error and close right away.

Logfile of HijackThis v1.99.1
Scan saved at 12:10:27 AM, on 8/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Aqua Dock\Aqua Dock.exe
C:\Program Files\Common Files\{302C8A4D-0B6E-1033-10... Read more

A:Solved: I've Been Invaded (hjt log inside)

Read other 16 answers
RELEVANCY SCORE 47.2

I recently downloaded CCleaner and was invaded by several hijack programs. They are Trovi, searchnu and rocket-find. They do not appear on my program list nor can I find them when I do a search but they pop up constantly, especially in Google Chrome. They have also invaded IE 8 running on WindowsXP. I would appreciate any help I can get in getting rid of these pests and any help on how to spot them prior to downloading any software. Thank you.

A:[SOLVED] Hijackers have invaded my computer

Hello and Welcome to TSF.

If you haven't already, please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

We want all our members to perform the steps outlined here:

NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help - Tech Support Forum

After running through all the steps, you shall have a proper set of logs. Please post/attach the logs in your next reply.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

------------------------------------------------------

Read other 3 answers
RELEVANCY SCORE 46.8

My winxp pro (sp3) system has been hit by pests, I wish I could identify.
Here're the symptoms:
1. Once in while, a few minutes when the computer is idle, longer intervals when active, a blue screen appears. The blue screen isn't a blue screen of death. It doesn't require rebooting. Activitiy can be restored either automatically, or by hitting CR. The STOP messages are diverse, some conventional but some like "systeminternals_great_site", or "Bogus_Driver". The sys files reported are almost any sys file on my system (and I suspect, even nonexisting sys files).
2. My Brother MFC-5440cn printer, USB connected, is unavailable. When I try reinstalling it, it's not recognized by the system. A few days ago it seemed like installation succeeded, but it failed since it failed to identify the legitimate port.
3. A few cases of host hosts file problems occurred, a situation which disconnected my browser's connectivity (MS Outlook continued without problems). Running smitfraudfix solves this problem.

Here's my hijachthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:19:35, on 11/07/2008
Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\sys... Read more

Read other answers
RELEVANCY SCORE 46

I get frequent requests on my XP-based PC to connect to the internet, via Nortons Antivirus software. I continue to select block but the requests to access do not stop.

Below is my Hijackthis file. Can someone provide guidance?

Thx,
GlennU.

Logfile of HijackThis v1.99.1
Scan saved at 7:28:03 PM, on 7/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Co... Read more

A:Solved: Thnall1ac and Kwcygyxeha have invaded my computer. Need assistance

Read other 16 answers
RELEVANCY SCORE 45.6
Q: 4bf65

Dear helper(s),
i have been infected by "4bf65.ilxt.info" (no better name!). I dowloaded "hijackthis" and here is the log:

Logfile of HijackThis v1.97.7
Scan saved at 09:42:22, on 04-09-16
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\DENILDIRECT\CRYPTO\BACKUP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHE... Read more

RELEVANCY SCORE 45.2

Hi,

I have read that you have solved other people's problems concerning the about:blank and then the 4bf65 pop ups. Unfortunately I am unable to stop this happening everytime I open Internet Explorer. When I change my home page to say Yahoo, everytime it goes automatically back to [email protected] then I get the 4bf65 pop up saying my system is infected, it's so annoying.

I have run one of those logs you have advised other people to do and here it is....Please help!!
»»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»»
The list will produce a small database of files that will match certain criteria.
Ex: read only files, s/h files, last modified date. size, etc.
The filters provided and registry scan should match the
corresponding file(s) listed.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Unless the file match the entire criteria, it should not be pointed to remove
without attempting to confirm it's nature!
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
At times there could be several (legit) files flagged, and/or duplicate culprit file(s)!
If in doubt, always search the file(s) and properties according to criteria!

The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder

______________________________________________________________________________
***YOU NEED TO DISABLE YOUR ACTIVE ANTI VIRUS PROTECTION TO AVOID CONFLICTS!***
____... Read more

A:4bf65 Problem

Read other 7 answers
RELEVANCY SCORE 45.2

I'm using Win 2000 and have been hijacked by the 4bf65 pop up error msg. I have read some posts here & have installed and run CWShredder, Ad-Aware, Spybot and Hijack this. The problem goes away and then comes back. I believe there is a hidden dll somewhere because I also get low virtual memory msgs as well. To follow is my hjt file. Any help would be appreciated.

Logfile of HijackThis v1.98.2
Scan saved at 11:31:32 AM, on 9/11/2004
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\SYSTEM32\3cmlink.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\America Online 9.0a\aoltray.exe
C:\Program Files\AOL Companion\companion.exe
C:\WINDOWS\SYSTEM32\3cshtdwn.exe
C:\WINDOWS\SYSTEM32\3cmlink.exe
C:\Program Files\Microsoft Great Plains Support Tuner\bin\mad.exe
C:\Quickenw\Qwdlls.exe
C:\Program Files\Microsoft Office\Office\1033\msoffic... Read more

A:Hijacked by 4bf65

Read other 6 answers
RELEVANCY SCORE 44.4

I've tried everything short of formating my computer. I keep getting about:blank and 4bf65.ilix.info pop ups whenever I use Yahoo! Messenger. Here is my HJT log....

Logfile of HijackThis v1.98.2
Scan saved at 1:32:01 AM, on 9/25/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSGLOOP.EXE
C:\WINDOWS\SYSTEM\MSG32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\ISP50\BIN\BARTSHEL.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\ISP50\BIN\PPSHARED.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\ISP50\BIN\BARTSHEL.EXE
C:\PROGRAM FILES\ISP50\DIALER\DIALER.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU... Read more

A:4bf65.ilix hijack

Read other 6 answers
RELEVANCY SCORE 43.2

I'm new to this site. Following advise given to anoher new user by flrman I'm posting my log file from Hijack This below. Can you help me get rid of ilxt pop ups?

Logfile of HijackThis v1.98.2
Scan saved at 8:12:30 PM, on 9/7/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\Explorer.EXE
C:\WINNT\system32\RUNDLL32.EXE
C:\WINNT\system32\pctspk.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINNT\system32\PRPCUI.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\SBC Yahoo!\Connection Manager\ConnectionManager.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\NavNT\vptray.exe
C:\WINNT\system32\hhtvrxkw.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\WIN... Read more

A:ilxt pop ups

Hi a1966f100, Welcome to TSG!!

If you still need help please post another HJT log for review.
 

Read other 1 answers
RELEVANCY SCORE 42.8

I am really an amateur and to be honest i am so lost is all this tech talk, but i have a problem which just WILL NOT go away. When i browse the net, my address bar keeps getting redirected to http://296f8.ilxt.info/index.php?aid=632. I mean, This ALWAYS happens. i cant open my mail account, cant search for anything really. Please help me cuz my pc is quite new, i really can't afford a new one. oh yeah, also, my homepage is changed to http://www.windowws.cc/hp.htm?id=632 all the time which is so annoying. I will leave it to your expertise to advise me (hopefully in laymans terms) on what to do. Thanks SO much!!!
 

A:ilxt has me at my wits end!!

Read other 9 answers
RELEVANCY SCORE 42.8

Hi! We have a computer whose IE had not been updated lately. It's been hijacked by ilxt.info. We have been unsuccessful in getting rid of it using ad-aware and spybots though they both find suspicious files and registry entries which are subsuqently removed. Unfortunately the next time a browser is opened those files and entries reappear.

Any help would be appreciated greatly. Thanks!
 

A:Hijacked by ilxt

Read other 11 answers