Could someone look at this and tell me what is safe to delete? My homepage keeps getting hijacked to: http:\\freednshost . Logfile of HijackThis v1.97.7
Scan saved at 6:48:16 PM, on 4/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\System32\VTTimer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\Palm\hotsync.exe
C:\Program Files\interMute\SpamSubtract\SpamSub.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://freednshost.info/page/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://freednshost.info/page/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://freednshost.info/page/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://freednshost.infoR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://freednshost.infoR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://freednshost.info/page/R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://freednshost.info/page/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://freednshost.infoR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://freednshost.info/page/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://freednshost.info/page/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://freednshost.infoR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://freednshost.info/page/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://213.159.118.226/sp.phpO1 - Hosts: 213.159.118.226 collections.inhost.info
O1 - Hosts: 213.159.118.226 collections.inhost2.info
O1 - Hosts: 213.159.118.226 1-se.com
O1 - Hosts: 213.159.118.226 58q.com
O1 - Hosts: 213.159.118.226 aifind.cc
O1 - Hosts: 213.159.118.226 aifind.info
O1 - Hosts: 213.159.118.226 allneedsearch.com
O1 - Hosts: 213.159.118.226 approvedlinks.com
O1 - Hosts: 213.159.118.226 auto.ie.searchforge.com
O1 - Hosts: 213.159.118.226 awebfind.biz
O1 - Hosts: 213.159.118.226 best.royalsearch.net
O1 - Hosts: 213.159.118.226 cracks.am
O1 - Hosts: 213.159.118.226 default-homepage-network.com
O1 - Hosts: 213.159.118.226 find.microgirls.com
O1 - Hosts: 213.159.118.226 find4u.net
O1 - Hosts: 213.159.118.226 freshvideogals.com
O1 - Hosts: 213.159.118.226 i-lookup.com
O1 - Hosts: 213.159.118.226 ie-search.com
O1 - Hosts: 213.159.118.226 in.webcounter.cc
O1 - Hosts: 213.159.118.226 itseasy.us
O1 - Hosts: 213.159.118.226 just.find-itnow.com
O1 - Hosts: 213.159.118.226 link.startmake.com
O1 - Hosts: 213.159.118.226 mysearchnow.com
O1 - Hosts: 213.159.118.226 nativehardcore.com
O1 - Hosts: 213.159.118.226 qwertysearch123.biz
O1 - Hosts: 213.159.118.226 search.ieplugin.com
O1 - Hosts: 213.159.118.226 search.psn.cn
O1 - Hosts: 213.159.118.226 searchbar.findthewebsiteyouneed.com
O1 - Hosts: 213.159.118.226 searchcentrix.com
O1 - Hosts: 213.159.118.226 searchmyrequest.com
O1 - Hosts: 213.159.118.226 super-spider.com
O1 - Hosts: 81.211.105.49 greatsearch.biz
O1 - Hosts: 81.211.105.49
www.greatsearch.bizO1 - Hosts: 81.211.105.49 cashsearch.biz
O1 - Hosts: 81.211.105.49
www.cashsearch.bizO1 - Hosts: 213.159.118.226 t.rack.cc
O1 - Hosts: 213.159.118.226 teen-biz.com
O1 - Hosts: 213.159.118.226 teenhqpics.com
O1 - Hosts: 213.159.118.226 tits.hardcore4ever.net
O1 - Hosts: 213.159.118.226 webcoolsearch.com
O1 - Hosts: 213.159.118.226 wmmse.com
O1 - Hosts: 213.159.118.226
www.008i.comO1 - Hosts: 213.159.118.226
www.2fastsearch.netO1 - Hosts: 213.159.118.226
www.8095.comO1 - Hosts: 213.159.118.226
www.alfa-search.comO1 - Hosts: 213.159.118.226
www.boredlife.comO1 - Hosts: 213.159.118.226
www.couldnotfind.comO1 - Hosts: 213.159.118.226
www.cracks.amO1 - Hosts: 213.159.118.226
www.daum.netO1 - Hosts: 213.159.118.226
www.dreamwiz.comO1 - Hosts: 213.159.118.226
www.find-itnow.comO1 - Hosts: 213.159.118.226
www.find-itnow.comO1 - Hosts: 213.159.118.226
www.find4u.netO1 - Hosts: 213.159.118.226
www.firstbookmark.comO1 - Hosts: 213.159.118.226
www.gajai.comO1 - Hosts: 213.159.118.226
www.hand-book.comO1 - Hosts: 213.159.118.226
www.hao123.comO1 - Hosts: 213.159.118.226
www.hotsearchbox.comO1 - Hosts: 213.159.118.226
www.hotwebsearch.comO1 - Hosts: 213.159.118.226
www.hugesearch.netO1 - Hosts: 213.159.118.226
www.iquicksearch.comO1 - Hosts: 213.159.118.226
www.lookfor.ccO1 - Hosts: 213.159.118.226
www.maxxxhosters.comO1 - Hosts: 213.159.118.226
www.naver.comO1 - Hosts: 213.159.118.226
www.nkvd.usO1 - Hosts: 213.159.118.226
www.nova[censored].com
O1 - Hosts: 213.159.118.226
www.ohcorea.comO1 - Hosts: 213.159.118.226
www.omega-search.comO1 - Hosts: 213.159.118.226
www.onet.plO1 - Hosts: 213.159.118.226
www.power-search.infoO1 - Hosts: 213.159.118.226
www.rightfinder.netO1 - Hosts: 213.159.118.226
www.search-1.netO1 - Hosts: 213.159.118.226
www.search-and-go.comO1 - Hosts: 213.159.118.226
www.search-dot.comO1 - Hosts: 213.159.118.226
www.search-space.comO1 - Hosts: 213.159.118.226
www.searchforge.comO1 - Hosts: 213.159.118.226
www.searching-the-net.comO1 - Hosts: 213.159.118.226
www.searchv.comO1 - Hosts: 213.159.118.226
www.searchxl.comO1 - Hosts: 213.159.118.226
www.seznam.czO1 - Hosts: 213.159.118.226
www.slotch.comO1 - Hosts: 213.159.118.226
www.spidersearch.comO1 - Hosts: 213.159.118.226
www.startium.comO1 - Hosts: 213.159.118.226
www.therealsearch.comO1 - Hosts: 213.159.118.226
www.ttjj.comO1 - Hosts: 213.159.118.226
www.viewpornkey.comO1 - Hosts: 213.159.118.226
www.wazzupnet.comO1 - Hosts: 213.159.118.226
www.websearch.comO1 - Hosts: 213.159.118.226
www.windowws.ccO1 - Hosts: 213.159.118.226
www.xgmm.comO1 - Hosts: 213.159.118.226 xwebsearch.biz
O1 - Hosts: 213.159.118.226 yourbookmarks.ws
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Network Service] C:\WINDOWS\svchost.exe -sr -0
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Network Service] C:\WINDOWS\svchost.exe -sr -0
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\hotsync.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sell Future Payment -
http://213.159.118.226/tools.php?qq=Sell+F...+Future+PaymentO8 - Extra context menu item: Time Clock -
http://213.159.118.226/tools.php?qq=Time+ClockO8 - Extra context menu item: Tramadol -
http://213.159.118.226/tools.php?qq=TramadolO9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra 'Tools' menuitem: Time Clock (HKLM)
O9 - Extra 'Tools' menuitem: Tramadol (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra 'Tools' menuitem: Sell Future Payment (HKLM)
O10 - Broken Internet access because of LSP provider 'spsublsp.dll' missing
O13 - DefaultPrefix:
http://freednshost.info/page/O13 - WWW Prefix:
http://freednshost.info/page/O16 - DPF: {11111111-1111-1111-1111-111111111147} - file://C:\Program Files\Internet Explorer\2466.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{F22FEEDC-2317-4EFC-BEC0-3D59DA3AAFFA}: NameServer = 66.133.191.35 170.215.255.114
Thanks, Mary