after logging on after a few seconds my computer screen goes blue and shuts down.
im on an IBM thinkpad R52 running Windows XP
also if my computer runs long enough for me to see the desktop icons saying pornotube.com, youporn.com and nudetube.com appear and when i delete them they just reappear later.
i don't quite know what other information to post sorry, ask me anything and i'll tell you what you need me too.
help would be appreciated and i have run a Hijack this log and i am posting it here:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:15:01 PM, on 20/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Safari\Safari.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\smss.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\System32\reader_s.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Mitchell\reader_s.exe
C:\WINDOWS\system32\D.tmp
C:\WINDOWS\system32\restorer64_a.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\restorer64_a.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\fonts\services.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\A5.tmp
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\restorer64_a.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\drivers\smss.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {42D26868-25C3-4be1-8652-559E76B25B77} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {78D48D53-58D1-4614-B47B-4AA5CEDBF0EA} - (no file)
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [5648] C:\WINDOWS\system32\D.tmp.exe
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKLM\..\Run: [restorer64_a] C:\WINDOWS\system32\restorer64_a.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [ter8m] RUNDLL32.EXE C:\WINDOWS\system32\msxm192z.dll,w
O4 - HKLM\..\Run: [servises] C:\WINDOWS\system32\servises.exe
O4 - HKLM\..\RunOnce: [áN@] áN@
O4 - HKLM\..\RunOnce: [ÑN@] ÑN@
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix
O4 - HKLM\..\RunOnce: [SpybotDeletingA6784] command.com /c del "C:\WINDOWS\system32\servises.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5701] cmd.exe /c del "C:\WINDOWS\system32\servises.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5043] command.com /c del "C:\Documents and Settings\Mitchell\reader_s.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8392] cmd.exe /c del "C:\Documents and Settings\Mitchell\reader_s.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5811] command.com /c del "C:\WINDOWS\System32\reader_s.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2469] cmd.exe /c del "C:\WINDOWS\System32\reader_s.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATnotes.exe] C:\Program Files\ATnotes\ATnotes.exe
O4 - HKCU\..\Run: [sys64_nov] C:\Documents and Settings\Mitchell\sys64_nov.exe
O4 - HKCU\..\Run: [zmmclr] C:\WINDOWS\system32\ncmdds.exe
O4 - HKCU\..\Run: [mqlwindl] C:\WINDOWS\system32\lsprcxs.exe
O4 - HKCU\..\Run: [wesspell] C:\WINDOWS\system32\qazbrnn.exe
O4 - HKCU\..\Run: [restorer32_a] C:\Documents and Settings\Mitchell\restorer32_a.exe
O4 - HKCU\..\Run: [crsmons] C:\WINDOWS\system32\iomssls.exe
O4 - HKCU\..\Run: [opqlsys] C:\WINDOWS\system32\velplsme.exe
O4 - HKCU\..\Run: [xisbcom] C:\WINDOWS\system32\lmssspr.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB7518] command.com /c del "C:\WINDOWS\system32\servises.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1033] cmd.exe /c del "C:\WINDOWS\system32\servises.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1945] command.com /c del "C:\Documents and Settings\Mitchell\reader_s.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4355] cmd.exe /c del "C:\Documents and Settings\Mitchell\reader_s.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7852] command.com /c del "C:\WINDOWS\System32\reader_s.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1006] cmd.exe /c del "C:\WINDOWS\System32\reader_s.exe"
O4 - HKLM\..\Policies\Explorer\Run: [exec] C:\WINDOWS\fonts\services.exe
O4 - HKLM\..\Policies\Explorer\Run: [servises] C:\WINDOWS\system32\servises.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Mitchell\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [servises] C:\WINDOWS\system32\servises.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [reader_s] C:\Documents and Settings\Mitchell\reader_s.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [servises] C:\WINDOWS\system32\servises.exe (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - {EE31AE88-AE7A-4C52-9330-A0A3B3468C02} - (no file)
O20 - AppInit_DLLs: visoziyo.dll c:\windows\system32\linanotu.dll c:\windows\system32\ c:\windows\system32\namiroto.dll tidadegi.dll c:\windows\system32\ramuzovi.dll c:\docume~1\alluse~1\applic~1\bohupota\bohupota.dll c:\windows\system32\jejuvusu.dll c:\windows\system32\nozapuso.dll
O21 - SSODL: numazatir - {30424edb-e777-4f38-807c-1179dc194391} - c:\windows\system32\linanotu.dll (file missing)
O21 - SSODL: vulibaguh - {18e3fe43-2227-4b9f-9d79-5ddd1bdb9e20} - c:\windows\system32\namiroto.dll (file missing)
O21 - SSODL: teyikadat - {0ecc48ff-ab97-4234-9638-155bedb05322} - (no file)
O21 - SSODL: tebikugad - {2062905d-f85a-4bae-872d-4c2f73e3a340} - (no file)
O21 - SSODL: hiyedebul - {c9443155-e02f-439f-81f1-a70e0c36f646} - (no file)
O21 - SSODL: gipalowig - {286a85cc-6e80-4aa0-98a7-87764ce24670} - c:\windows\system32\ramuzovi.dll (file missing)
O21 - SSODL: huzebalan - {11fc3c24-235b-430b-814b-81c35177e7c5} - c:\docume~1\alluse~1\applic~1\bohupota\bohupota.dll (file missing)
O21 - SSODL: korotofaj - {79c3f9bb-8bd0-42ca-9743-8cd26fd64fa5} - c:\windows\system32\jejuvusu.dll (file missing)
O21 - SSODL: vafikewet - {242a4be7-6229-4a75-9c54-639c7f308d5d} - c:\windows\system32\nozapuso.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {30424edb-e777-4f38-807c-1179dc194391} - c:\windows\system32\linanotu.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {18e3fe43-2227-4b9f-9d79-5ddd1bdb9e20} - c:\windows\system32\namiroto.dll (file missing)
O22 - SharedTaskScheduler: mujuzedij - {0ecc48ff-ab97-4234-9638-155bedb05322} - (no file)
O22 - SharedTaskScheduler: mujuzedij - {2062905d-f85a-4bae-872d-4c2f73e3a340} - (no file)
O22 - SharedTaskScheduler: gahurihor - {c9443155-e02f-439f-81f1-a70e0c36f646} - (no file)
O22 - SharedTaskScheduler: gahurihor - {286a85cc-6e80-4aa0-98a7-87764ce24670} - c:\windows\system32\ramuzovi.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {11fc3c24-235b-430b-814b-81c35177e7c5} - c:\docume~1\alluse~1\applic~1\bohupota\bohupota.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {79c3f9bb-8bd0-42ca-9743-8cd26fd64fa5} - c:\windows\system32\jejuvusu.dll (file missing)
O22 - SharedTaskScheduler: tokatiluy - {242a4be7-6229-4a75-9c54-639c7f308d5d} - c:\windows\system32\nozapuso.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: System32 Service (service) - Unknown owner - C:\WINDOWS\system32\service.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
--
End of file - 11983 bytes