TechSpot

BEGIN2SEARCH- Help me get rid of this thing!

By cozza123
Nov 23, 2004
  1. Hey guys,

    Im new to this forum and I need some help with getting rid of this Begin2Search thing. I've run Spybot and Adware and cant seem to get rid of it. Here is my log from HijackThis:\

    Logfile of HijackThis v1.97.7
    Scan saved at 11:40:41 AM, on 24/11/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\System32\Ati2evxx.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    D:\Program Files\Norton Internet Security\NISUM.EXE
    D:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
    D:\Program Files\Norton Internet Security\ccPxySvc.exe
    D:\WINDOWS\system32\drivers\KodakCCS.exe
    D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
    D:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
    D:\Program Files\Norton AntiVirus\navapsvc.exe
    D:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
    D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
    D:\WINDOWS\System32\ScsiAccess.EXE
    D:\WINDOWS\System32\tcpsvcs.exe
    D:\WINDOWS\System32\snmp.exe
    D:\WINDOWS\System32\svchost.exe
    D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    D:\Program Files\Common Files\pestpatrol\PPMCActiveDetection.exe
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
    D:\WINDOWS\SOUNDMAN.EXE
    D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    D:\Program Files\QuickTime\qttask.exe
    D:\Program Files\Winamp\winampa.exe
    D:\Program Files\Java\j2re1.5.0\bin\jusched.exe
    D:\PROGRA~1\NEWMEN~1\Keyboard\Ikeymain.exe
    D:\PROGRA~1\NEWMEN~1\Mouse\Amoumain.exe
    D:\Program Files\Common Files\Real\Update_OB\realsched.exe
    D:\Program Files\Common Files\Symantec Shared\ccApp.exe
    D:\WINDOWS\System32\ctfmon.exe
    D:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    D:\WINDOWS\System32\wuauclt.exe
    D:\Documents and Settings\Chris\Desktop\HijackThis.exe
    D:\Program Files\Internet Explorer\IEXPLORE.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/sidesearch.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
    R3 - URLSearchHook: (no name) - - (no file)
    O1 - Hosts: ˜J1˜J1øË1øË1˜1˜1è]1ø[1¨1¨1XÈ1XÈ1¸1¸1À1À1È1È1Ð1Ð1Ø1Ø1à1à1è1è1ð1ð1ø1ø1 ˆ111èÞ1èÞ1*1*1¨1¨1°1°1¸1¸1À1À1È1È1Ð1Ð1Ø1Ø1à1à1è1è1ð1ð1ø1ø1
    O1 - Hosts: 1˜1˜1*1*1¨1¨1°1°1¸1¸1À1À1È1È1Ð1Ð1Ø1Ø1à1à1è1è1ð1ð1ø1ø1
    O1 - Hosts: ˜JF˜JFFF˜F˜FàÿFúF¨F¨F°F°FŒFŒFÀFÀFÈFÈF°·F°·FØFØFàFàFèFèFðFðFøFøF ˆFFF˜F˜F*F*F¨F¨F°F°F¸F¸FÀFÀFÈFÈFÐFÐFØFØFàFàFèFèFðFðFøFøF
    O1 - Hosts: ˜J_˜J___˜_˜_*_*_*b_*b_°_°_¸_¸_À_À_È_È_Ð_Ð_Ø_Ø_à_à_è_è_ð_ð_ø_ø_ ˆ___˜_˜_*_*_¨_¨_°_°_¸_¸_À_À_È_È_Ð_Ð_Ø_Ø_à_à_è_è_ð_ð_ø_ø_
    O1 - Hosts: _˜_˜_*_*_¨_¨_°_°_¸_¸_À_À_È_È_Ð_Ð_Ø_Ø_à_à_è_è_ð_ð_ø_ø_
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - D:\WINDOWS\System32\dsktrf.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.5.0\bin\jusched.exe
    O4 - HKLM\..\Run: [NewmenKeyboard] D:\PROGRA~1\NEWMEN~1\Keyboard\Ikeymain.exe
    O4 - HKLM\..\Run: [NewmenTechMouse] D:\PROGRA~1\NEWMEN~1\Mouse\Amoumain.exe
    O4 - HKLM\..\Run: [NeroCheck] D:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "D:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = D:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Downloads (HKLM)
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://download.macromedia.com/pub/shockwave/cabs/authorware/awswax65.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    Help would be great

    Cheers
     
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...