| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 90475 | 2008-06-04 10:22:00 | hijack this *take a look plz | ACKS (11537) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 675558 | 2008-06-04 10:22:00 | hi guys iv got a big problem when i start my computer i get unlimited ie pop ups can someone please help? . :help: Logfile of Trend Micro HijackThis v2 . 0 . 2 Scan saved at 9:30:37 p . m . , on 4/06/2008 Platform: Windows Vista (WinNT 6 . 00 . 1904) MSIE: Internet Explorer v7 . 00 (7 . 00 . 6000 . 16643) Boot mode: Normal Running processes: C:\Windows\system32\Dwm . exe C:\Windows\system32\taskeng . exe C:\Windows\Explorer . EXE C:\Program Files\Windows Defender\MSASCui . exe C:\Windows\System32\igfxtray . exe C:\Windows\System32\hkcmd . exe C:\Windows\System32\igfxpers . exe C:\Windows\RtHDVCpl . exe C:\Program Files\Toshiba\ConfigFree\NDSTray . exe C:\Program Files\Synaptics\SynTP\SynTPEnh . exe C:\Program Files\Toshiba\Power Saver\TPwrMain . exe C:\Program Files\Toshiba\SmoothView\SmoothView . exe C:\Program Files\Toshiba\FlashCards\TCrdMain . exe C:\Program Files\Camera Assistant Software for Toshiba\traybar . exe C:\Program Files\iTunes\iTunesHelper . exe C:\Program Files\Java\jre1 . 6 . 0_06\bin\jusched . exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient . exe C:\Program Files\Windows Sidebar\sidebar . exe C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD . exe C:\Program Files\Windows Live\Messenger\msnmsgr . exe C:\Windows\ehome\ehtray . exe C:\Windows\System32\rundll32 . exe C:\Windows\System32\rundll32 . exe C:\Windows\System32\rundll32 . exe C:\Program Files\Windows Media Player\wmpnscfg . exe C:\Windows\System32\rundll32 . exe C:\Windows\ehome\ehmsas . exe C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN . exe C:\Windows\system32\wbem\unsecapp . exe C:\Windows\system32\igfxsrvc . exe C:\Program Files\Toshiba\ConfigFree\CFSwMgr . exe C:\Program Files\Mozilla Firefox\firefox . exe C:\Program Files\Trend Micro\HijackThis\HijackThis . exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = * . local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch . dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper . dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1 . 6 . 0_06\bin\ssv . dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin . dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb . dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash . dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb . dll O4 - HKLM\ . . \Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui . exe -hide O4 - HKLM\ . . \Run: [IgfxTray] C:\Windows\system32\igfxtray . exe O4 - HKLM\ . . \Run: [HotKeysCmds] C:\Windows\system32\hkcmd . exe O4 - HKLM\ . . \Run: [Persistence] C:\Windows\system32\igfxpers . exe O4 - HKLM\ . . \Run: [RtHDVCpl] RtHDVCpl . exe O4 - HKLM\ . . \Run: [NDSTray . exe] NDSTray . exe O4 - HKLM\ . . \Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh . exe O4 - HKLM\ . . \Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain . EXE O4 - HKLM\ . . \Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON . exe O4 - HKLM\ . . \Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView . exe O4 - HKLM\ . . \Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain . exe O4 - HKLM\ . . \Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar . exe" O4 - HKLM\ . . \Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper . exe" O4 - HKLM\ . . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1 . 6 . 0_06\bin\jusched . exe" O4 - HKLM\ . . \Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient . exe" O4 - HKLM\ . . \Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan . exe O4 - HKCU\ . . \Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar . exe /autoRun O4 - HKCU\ . . \Run: [TOSCDSPD] TOSCDSPD . EXE O4 - HKCU\ . . \Run: [EPSON Stylus CX5500 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIC AP . EXE /FU "C:\Windows\TEMP\E_SF10D . tmp" /EF "HKCU" O4 - HKCU\ . . \Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr . Exe" /background O4 - HKCU\ . . \Run: [ehTray . exe] C:\Windows\ehome\ehTray . exe O4 - HKCU\ . . \Run: [cmds] rundll32 . exe C:\Users\Meryl\AppData\Local\Temp\ljJBtuSj . dll,c O4 - HKCU\ . . \Run: [5c8c94a2] rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\xlxgoeiy . dll",b O4 - HKCU\ . . \Run: [__c00F7509] rundll32 . exe "C:\Users\Meryl\AppData\Roaming\__c00F7509 . dat",B O4 - HKCU\ . . \Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG . exe O4 - HKCU\ . . \Run: [BM5fbfa73e] Rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\gspvybpk . dll",s O4 - HKUS\S-1-5-19\ . . \Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar . exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\ . . \Run: [WindowsWelcomeCenter] rundll32 . exe oobefldr . dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\ . . \Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar . exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: Adobe Gamma . lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader . exe O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all . htm O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link . htm O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb . dll/search . htm O8 - Extra context menu item: Add to Windows &Live Favorites - . live . com/quickadd . aspx" target="_blank">favorites . live . com O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL . EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1 . 6 . 0_06\bin\ssv . dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1 . 6 . 0_06\bin\ssv . dll O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension . dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension . dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR . DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet . exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet . exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper . dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper . dll O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - . macromedia . com/get/flashplayer/current/swflash . cab" target="_blank">fpdownload2 . macromedia . com O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice . exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc . exe O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc . exe O23 - Service: Apple Mobile Device - Apple, Inc . - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService . exe O23 - Service: Bonjour Service - Apple Inc . - C:\Program Files\Bonjour\mDNSResponder . exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs . exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng . exe O23 - Service: iPod Service - Apple Inc . - C:\Program Files\iPod\bin\iPodService . exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA . exe O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB . exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc . exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd . - C:\Program Files\Spybot - Search & Destroy\SDWinSec . exe O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv . exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv . exe O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv . exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv . exe O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc . - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr . exe O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon . exe -- End of file - 9886 bytes |
ACKS (11537) | ||
| 675559 | 2008-06-04 10:31:00 | Hmm might be a few nasties in there Run HJT again tick these then tick fix checked Close browsers O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\ . . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1 . 6 . 0_06\bin\jusched . exe" I would say these files are causing this O4 - HKCU\ . . \Run: [cmds] rundll32 . exe C:\Users\Meryl\AppData\Local\Temp\ljJBtuSj . dll,c O4 - HKCU\ . . \Run: [5c8c94a2] rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\xlxgoeiy . dll",b O4 - HKCU\ . . \Run: [__c00F7509] rundll32 . exe "C:\Users\Meryl\AppData\Roaming\__c00F7509 . dat",B O4 - HKCU\ . . \Run: [BM5fbfa73e] Rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\gspvybpk . dll",s Since you've got trojan remover run it update it click on scan, select all options under utilities Open my computer / highlight c / right mouse / scan with trojan remover . Scan the whole hdd . If ccleaner is installed run it and click on run cleaner |
Speedy Gonzales (78) | ||
| 675560 | 2008-06-05 21:15:00 | Hmm might be a few nasties in there Run HJT again tick these then tick fix checked Close browsers O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\ . . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1 . 6 . 0_06\bin\jusched . exe" I would say these files are causing this O4 - HKCU\ . . \Run: [cmds] rundll32 . exe C:\Users\Meryl\AppData\Local\Temp\ljJBtuSj . dll,c O4 - HKCU\ . . \Run: [5c8c94a2] rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\xlxgoeiy . dll",b O4 - HKCU\ . . \Run: [__c00F7509] rundll32 . exe "C:\Users\Meryl\AppData\Roaming\__c00F7509 . dat",B O4 - HKCU\ . . \Run: [BM5fbfa73e] Rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\gspvybpk . dll",s Since you've got trojan remover run it update it click on scan, select all options under utilities Open my computer / highlight c / right mouse / scan with trojan remover . Scan the whole hdd . If ccleaner is installed run it and click on run cleaner I can't do the trojan scan because trojan remover is experied and after doing the hijack step i'm getting some errors . :help: :help: :help: :help: :help: |
ACKS (11537) | ||
| 675561 | 2008-06-05 21:49:00 | From my sig, download all the cleaners, install /update and run, they should also detect and remove most if not all of the bugs. | wainuitech (129) | ||
| 1 | |||||