Welcome! Register for a free account (or login) > How does it work?
|
|


Nov 1 2009, 09:49 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 21-July 09 Member No.: 86,869 Operating System: XP |
My roommate doesn't know which porn sites are safe to browse and what isn't.
Here's what I've got so far. 1. Some pages hesitate to load, or don't load at all. 2. Random pop up ads that are almost always the same. 3. Everyone once in a while it will redirect me to a random website while going to something. Here's the HiJackThis Log. Thanks in advance to anyone who helps. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:48:03 PM, on 11/1/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16850) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe C:\WINDOWS\system32\pctspk.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [83099938] C:\Documents and Settings\All Users\Application Data\83099938\83099938.exe O4 - HKLM\..\Run: [02480418] C:\Documents and Settings\All Users\Application Data\02480418\02480418.exe O4 - HKLM\..\Run: [43850323] C:\Documents and Settings\All Users\Application Data\43850323\43850323.exe O4 - HKLM\..\Run: [10111610] C:\Documents and Settings\All Users\Application Data\10111610\10111610.exe O4 - HKLM\..\Run: [36329730] C:\Documents and Settings\All Users\Application Data\36329730\36329730.exe O4 - HKLM\..\Run: [67978643] C:\Documents and Settings\All Users\Application Data\67978643\67978643.exe O4 - HKLM\..\Run: [87967239] C:\DOCUME~1\ALLUSE~1\APPLIC~1\87967239\87967239.exe O4 - HKLM\..\Run: [36214723] C:\Documents and Settings\All Users\Application Data\36214723\36214723.exe O4 - HKLM\..\Run: [34489432] C:\Documents and Settings\All Users\Application Data\34489432\34489432.exe O4 - HKLM\..\Run: [88727638] C:\Documents and Settings\All Users\Application Data\88727638\88727638.exe O4 - HKLM\..\Run: [07905324] C:\Documents and Settings\All Users\Application Data\07905324\07905324.exe O4 - HKLM\..\Run: [motivijis] Rundll32.exe "c:\windows\system32\wamepesi.dll",a O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{0D4CE743-A9FD-4C88-86F7-DC289838F413}: NameServer = 10.106.128.1 O20 - AppInit_DLLs: laladujo.dll c:\windows\system32\wamepesi.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O21 - SSODL: sariyitol - {9e0dfd42-afa2-4037-a96e-a0b90e959c13} - c:\windows\system32\wamepesi.dll O22 - SharedTaskScheduler: tokatiluy - {9e0dfd42-afa2-4037-a96e-a0b90e959c13} - c:\windows\system32\wamepesi.dll O23 - Service: Avira AntiVir Scheduler (antivirschedulerservice) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (antivirservice) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\ O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\ -- End of file - 7214 bytes |
|
|
|
Blindsided623 [Closed] Hijack This Log Nov 1 2009, 09:49 PM
OCD Hello Blindsided623,
Welcome to What the Tech.
My... Nov 3 2009, 09:03 PM
OCD Hello Blindsided623,
You may want to print out the... Nov 3 2009, 09:55 PM
Blindsided623 DDS (Ver_09-10-26.01) - NTFSx86
Run by Paul at 2... Nov 3 2009, 11:42 PM
OCD Hi Blindsided623,
Please download ComboFix from o... Nov 4 2009, 05:23 PM
Blindsided623 ComboFix 09-11-04.02 - Paul 11/04/2009 20:06.3.1 -... Nov 4 2009, 09:55 PM
OCD Hi Blindsided623,
We will be using Combofix again... Nov 5 2009, 11:28 AM
OCD Hello Blindsided623,
It's been a few days, I ... Nov 8 2009, 11:36 AM
OCD Reason for edit: posted in wrong thread Nov 10 2009, 09:23 PM
Tomk Due to inactivity this topic will be closed.
If yo... Nov 10 2009, 10:46 PM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
3 | whiteheadw | 104 | Today, 02:50 AM Last post by: oldman960 |
|||
![]() |
3 | TCHal | 85 | Yesterday, 09:13 PM Last post by: inzanity |
|||
![]() |
4 | livewiredrinker | 61 | Yesterday, 08:26 AM Last post by: SweetTech |
|||
![]() |
13 | Demos30 | 549 | 13th March 2010 - 09:24 AM Last post by: jpshortstuff |
|||
|
Time is now: 15th March 2010 - 01:27 PM |