Forum Home
Press F1
 
Thread ID: 90475 2008-06-04 10:22:00 hijack this *take a look plz ACKS (11537) Press F1
Post ID Timestamp Content User
675558 2008-06-04 10:22:00 hi guys iv got a big problem when i start my computer i get unlimited ie pop ups can someone please help? . :help:




Logfile of Trend Micro HijackThis v2 . 0 . 2
Scan saved at 9:30:37 p . m . , on 4/06/2008
Platform: Windows Vista (WinNT 6 . 00 . 1904)
MSIE: Internet Explorer v7 . 00 (7 . 00 . 6000 . 16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm . exe
C:\Windows\system32\taskeng . exe
C:\Windows\Explorer . EXE
C:\Program Files\Windows Defender\MSASCui . exe
C:\Windows\System32\igfxtray . exe
C:\Windows\System32\hkcmd . exe
C:\Windows\System32\igfxpers . exe
C:\Windows\RtHDVCpl . exe
C:\Program Files\Toshiba\ConfigFree\NDSTray . exe
C:\Program Files\Synaptics\SynTP\SynTPEnh . exe
C:\Program Files\Toshiba\Power Saver\TPwrMain . exe
C:\Program Files\Toshiba\SmoothView\SmoothView . exe
C:\Program Files\Toshiba\FlashCards\TCrdMain . exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar . exe
C:\Program Files\iTunes\iTunesHelper . exe
C:\Program Files\Java\jre1 . 6 . 0_06\bin\jusched . exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient . exe
C:\Program Files\Windows Sidebar\sidebar . exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD . exe
C:\Program Files\Windows Live\Messenger\msnmsgr . exe
C:\Windows\ehome\ehtray . exe
C:\Windows\System32\rundll32 . exe
C:\Windows\System32\rundll32 . exe
C:\Windows\System32\rundll32 . exe
C:\Program Files\Windows Media Player\wmpnscfg . exe
C:\Windows\System32\rundll32 . exe
C:\Windows\ehome\ehmsas . exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN . exe
C:\Windows\system32\wbem\unsecapp . exe
C:\Windows\system32\igfxsrvc . exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr . exe
C:\Program Files\Mozilla Firefox\firefox . exe
C:\Program Files\Trend Micro\HijackThis\HijackThis . exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = * . local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch . dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper . dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1 . 6 . 0_06\bin\ssv . dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin . dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb . dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash . dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb . dll
O4 - HKLM\ . . \Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui . exe -hide
O4 - HKLM\ . . \Run: [IgfxTray] C:\Windows\system32\igfxtray . exe
O4 - HKLM\ . . \Run: [HotKeysCmds] C:\Windows\system32\hkcmd . exe
O4 - HKLM\ . . \Run: [Persistence] C:\Windows\system32\igfxpers . exe
O4 - HKLM\ . . \Run: [RtHDVCpl] RtHDVCpl . exe
O4 - HKLM\ . . \Run: [NDSTray . exe] NDSTray . exe
O4 - HKLM\ . . \Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh . exe
O4 - HKLM\ . . \Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain . EXE
O4 - HKLM\ . . \Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON . exe
O4 - HKLM\ . . \Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView . exe
O4 - HKLM\ . . \Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain . exe
O4 - HKLM\ . . \Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar . exe"
O4 - HKLM\ . . \Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper . exe"
O4 - HKLM\ . . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1 . 6 . 0_06\bin\jusched . exe"
O4 - HKLM\ . . \Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient . exe"
O4 - HKLM\ . . \Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan . exe
O4 - HKCU\ . . \Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar . exe /autoRun
O4 - HKCU\ . . \Run: [TOSCDSPD] TOSCDSPD . EXE
O4 - HKCU\ . . \Run: [EPSON Stylus CX5500 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIC AP . EXE /FU "C:\Windows\TEMP\E_SF10D . tmp" /EF "HKCU"
O4 - HKCU\ . . \Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr . Exe" /background
O4 - HKCU\ . . \Run: [ehTray . exe] C:\Windows\ehome\ehTray . exe
O4 - HKCU\ . . \Run: [cmds] rundll32 . exe C:\Users\Meryl\AppData\Local\Temp\ljJBtuSj . dll,c
O4 - HKCU\ . . \Run: [5c8c94a2] rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\xlxgoeiy . dll",b
O4 - HKCU\ . . \Run: [__c00F7509] rundll32 . exe "C:\Users\Meryl\AppData\Roaming\__c00F7509 . dat",B
O4 - HKCU\ . . \Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG . exe
O4 - HKCU\ . . \Run: [BM5fbfa73e] Rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\gspvybpk . dll",s
O4 - HKUS\S-1-5-19\ . . \Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar . exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\ . . \Run: [WindowsWelcomeCenter] rundll32 . exe oobefldr . dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\ . . \Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar . exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Adobe Gamma . lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader . exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all . htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link . htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb . dll/search . htm
O8 - Extra context menu item: Add to Windows &Live Favorites - . live . com/quickadd . aspx" target="_blank">favorites . live . com
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL . EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1 . 6 . 0_06\bin\ssv . dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1 . 6 . 0_06\bin\ssv . dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension . dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension . dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR . DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet . exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet . exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper . dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper . dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - . macromedia . com/get/flashplayer/current/swflash . cab" target="_blank">fpdownload2 . macromedia . com
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice . exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc . exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc . exe
O23 - Service: Apple Mobile Device - Apple, Inc . - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService . exe
O23 - Service: Bonjour Service - Apple Inc . - C:\Program Files\Bonjour\mDNSResponder . exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs . exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng . exe
O23 - Service: iPod Service - Apple Inc . - C:\Program Files\iPod\bin\iPodService . exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA . exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB . exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc . exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd . - C:\Program Files\Spybot - Search & Destroy\SDWinSec . exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv . exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv . exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv . exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv . exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc . - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr . exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon . exe

--
End of file - 9886 bytes
ACKS (11537)
675559 2008-06-04 10:31:00 Hmm might be a few nasties in there

Run HJT again tick these then tick fix checked

Close browsers

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\ . . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1 . 6 . 0_06\bin\jusched . exe"

I would say these files are causing this

O4 - HKCU\ . . \Run: [cmds] rundll32 . exe C:\Users\Meryl\AppData\Local\Temp\ljJBtuSj . dll,c

O4 - HKCU\ . . \Run: [5c8c94a2] rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\xlxgoeiy . dll",b

O4 - HKCU\ . . \Run: [__c00F7509] rundll32 . exe "C:\Users\Meryl\AppData\Roaming\__c00F7509 . dat",B

O4 - HKCU\ . . \Run: [BM5fbfa73e] Rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\gspvybpk . dll",s

Since you've got trojan remover run it update it click on scan, select all options under utilities

Open my computer / highlight c / right mouse / scan with trojan remover .

Scan the whole hdd . If ccleaner is installed run it and click on run cleaner
Speedy Gonzales (78)
675560 2008-06-05 21:15:00 Hmm might be a few nasties in there

Run HJT again tick these then tick fix checked

Close browsers

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\ . . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1 . 6 . 0_06\bin\jusched . exe"

I would say these files are causing this

O4 - HKCU\ . . \Run: [cmds] rundll32 . exe C:\Users\Meryl\AppData\Local\Temp\ljJBtuSj . dll,c

O4 - HKCU\ . . \Run: [5c8c94a2] rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\xlxgoeiy . dll",b

O4 - HKCU\ . . \Run: [__c00F7509] rundll32 . exe "C:\Users\Meryl\AppData\Roaming\__c00F7509 . dat",B

O4 - HKCU\ . . \Run: [BM5fbfa73e] Rundll32 . exe "C:\Users\Meryl\AppData\Local\Temp\gspvybpk . dll",s

Since you've got trojan remover run it update it click on scan, select all options under utilities

Open my computer / highlight c / right mouse / scan with trojan remover .

Scan the whole hdd . If ccleaner is installed run it and click on run cleaner

I can't do the trojan scan because trojan remover is experied and after doing the hijack step i'm getting some errors .

:help: :help: :help: :help: :help:
ACKS (11537)
675561 2008-06-05 21:49:00 From my sig, download all the cleaners, install /update and run, they should also detect and remove most if not all of the bugs. wainuitech (129)
1