|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
heeeeelp
heeeeeeeeeeeeeeey guys!! im having a blast !! woohoo
im only rewriting this thread the third time!!! i mean writing a page long thread only to see enternet explored failed is quite normal isnt it??? oh wait no its NOT!!listen and plz help.. im gonna have a seizure: ( writing this third time and i dotn think the last ) i got a new comp.. with anti virus program, temperature alert, cd burning program, pop up blocker.. sounds nice doesnt it?? well woopti doo iv never seen a more virused piece of poo computer in my life!! jesus christ!!! listen: i try to make my hoempage something like www.spawn.com or wtvr.. ya great.. dont u expect spawn.com to pop up when u press open enternet explorer?? no i dont expect it to pop up.. what i expect is a stupid ugly porn site with tons of pop ups!! what the hell?? ya nice.. aha.. i out my homepage to spawn.com and i get a porn site..greaaaaaaaaaaat.. wtvr i chaneg my homepage to its still a porn site!! im tired of this!!! plz help!! now all the time i run my enternet chances are it will end up shutting down because it isnt responding!! like the 2 time siv been tryign to post this thread before!! wohoo!! and it will probably say enternet not responding now also so il have to do this the foruth time!! yaaaaaaaaaaay.. why does this happen?? when i open my computer or control panel chances are it will not respond soon either.. greaaaaaat comp i bet ur jelous.. and when i shut it down i get the end prgram messages.. and when i press them it says the programs arent respondign anyway.. rock on.. so i cant just press shut down computer and expect it to shut down i have to stay there and press the end prgram buttons.. and the prgrams arent responding anyway.. yaaaaaaaaaaaaaaaaaaaaaaaaaaaay and my msn messenger signs in whenever the hell it wants too.. ya my dad only payed more then a thousand cnd buks.. and i had this comp for only 3 months now.. ya thats so great.. anywaz my comp: 2.8 ghz 512 mb of ram ge force 5600 xt ( 256 mb ) plz heeeeeeeelp!! |
|
|
|
|
|
#2 |
|
Member (14 bit)
Join Date: Mar 1999
Location: Christmas, Florida
Posts: 10,661
|
ok theres no problem we can find the problem fo you if you calm down a bit and di exactly what we suggest.
first what are you useing for the O/S and how are you connected to the internet? you got infected and just need to clean it out |
|
|
|
|
|
#3 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
my dad says we have lan... we also have a router.. my dad says the lan works because of the router..
i myself dont even know what lan is whats an os?? if this tells u anything i have sympatico fast enternet.. and on ym moden thers 4 lights.. the ones glwoign are: pwr, dsl, and enet... so ya.. thats all i fgured out so far
|
|
|
|
|
|
#4 |
|
Member (14 bit)
Join Date: Mar 1999
Location: Christmas, Florida
Posts: 10,661
|
ok
that tells me a lot. you have a wideband connection, and the router is what lets all the computers on the lan ( local area network ) use the same internet connection. is this the only one computer on the network that is having the problem ? not that it really matters, but how many other computers is on the lan. are they all working ok ? it sounds like you got some virous, spyware or adware that is hyjacking your system and doing the things that your experiencing there. |
|
|
|
|
|
#5 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
no im the only lucky one to have this prob.. in my family..
what can i do?? i doubt my dad wants to see my homepage as a porn site.. so i hope he doesnt ouch my comp.. that would be embarassing |
|
|
|
|
|
#6 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
|
1. If this is Windows XP, enable the ICF (firewall) on your local area connection. Open Network and Internet Connections, right click on the local area connection, properties, advanced tab.
2. Update your antivirus program and do a complete system scan. 3. Go to Windows Update (it's in your start menu) and download/install ALL critical updates. 4. Download Spybot Search & Destroy 1.3 from www.safer-networking.org, install it, run it, and repair all problems. See what that does, if you are still having problems we can proceed further. |
|
|
|
|
|
#7 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
OMG!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
**** this so much!!! i downlaoded a spybot and deletd all the problems and now i got more!!!! **** this!!!! jesus chist!!!!! my homepage is still a porn site, and now wtvr i type in my adress bar it will say the adress or path is wrong.. great!!1 its never been easier doing hoemwrk when ur enternet isnt working..heeeeeelp now plz!! also i downloaded a rar file and put .exe in front of it.. now it wotn delete.. it says another program is using it or person.. jesus ****!!! this computer wasnt worth my 1000 dollars!!! maybe a 20!!! |
|
|
|
|
|
#8 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
please calm down we are trying to help you
Please do this. Click here to download Hijack This. Save it to it’s own folder (not temporary files or the desktop). Close all open windows and open HIJACK THIS. Click “Scan” . When the scan is finished (it only takes a second), the scan button will change to“Save Log”. Click on“Save Log” and save it to NotePad. Copy the entire log and paste it here. DO NOT FIX ANYTHING YET , most items that appear in the log are harmless or even needed. Wait for someone to analyze the scan and advise. Last edited by Lobos; 05-24-2004 at 09:24 AM. |
|
|
|
|
|
#9 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
brb il do that.. im on ym dads comp sinse m enternet browser isnt working on my comp
|
|
|
|
|
|
#10 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
dude i cant paste it... its so anoying evry time i try to log onto this forum and reply to soemthign it says log on again as if i didnt log on before.. the only way to post is to use this reply box thingie.. anywaz how am i gonna shoe u my emsage?? i think its to big the enternet says it enctountered a problem and needs to close.. oh and it says its sorry for inconveinces.. lmoa better be sorry.. whats ur email i think i might be able to emailu the thing
|
|
|
|
|
|
#11 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
sorry im not usign the edit button, my enternet doesnt work dont ban me..
anywaz i send u the lgo by email.. did u get it?? if u didnt them well work on it more.. say msn messenger |
|
|
|
|
|
#12 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
|
Please calm down and try to use better English, you are very difficult to understand. Follow the instructions that our members are giving you and answer their questions.
If you continue swearing, you WILL be banned, so sit back and take a deep breath. I do have to say that you have brought all these problems on yourself - we aren't stupid, we KNOW what .rar files are and where they come from - if you keep frequenting those sites your problems are just going to get worse. |
|
|
|
|
|
#13 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
plz i still cant browse the enternet.. whaa i got homewrk to do for tomorow.. this needs to be fixed someone have mercy help me with my enternet browser..
sorry that i was swearing.. just wasnt in best mood ever.. soorry ![]() lol ok il shut up now.. rar files are models and skins arent they?? for ut2003??? ur not stupid and u know where rar files come from, but i am stupid and i dunno what rar files are so i thot the file would instal if i put .exe in front of it.. but it didnt now it wont delete.. plz help me out.. and i really dunno what sites ur takign aobut all i visist, is art forums to post my art, spawn.com, and video game sites.. oh and movie times for cinema sites.. thats it i swear... did my probs come from kazaa music?? im in canada im allowed to download lol
|
|
|
|
|
|
#14 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
ok well is there any computer that you can copy and paste
the hijack this log from i need that for me to tell you what to do next as for kazaa it doesn't matter where your from it loads so much junk on your computer that stuff like this could happen after three months there are way more safer programs for filesharing |
|
|
|
|
|
#15 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
i send u the log by email.. did u get it logos?? the subject was log..
if u didnt recieve it then.. im scrued.. plz tell me u got it |
|
|
|
|
|
#16 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
part1:
Logfile of HijackThis v1.97.7 Scan saved at 8:48:52 PM, on 24/05/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe |
|
|
|
|
|
#17 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
part2:
C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\dl.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\MSI\Core Center\CoreCenter.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe C:\Program Files\NetAssistant\bin\mpbtn.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\x0r\svshost.exe |
|
|
|
|
|
#18 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
part3:
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\System32\HPZipm12.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\user\My Documents\blah\HijackThis.exe |
|
|
|
|
|
#19 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
thers more but when i post it my browser shuts down
|
|
|
|
|
|
#20 |
|
I like monkeys
Join Date: Jul 2003
Location: The South
Posts: 2,512
|
Hey,
pavel (manslauter) sent me this and asked me to post it for him. Whenever he tries his browser shuts down. Here you go. Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\dl.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\MSI\Core Center\CoreCenter.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe C:\Program Files\NetAssistant\bin\mpbtn.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\x0r\svshost.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\System32\HPZipm12.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\user\My Documents\blah\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://your-searcher.com/sp.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://your-searcher.com/sp.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://your-searcher.com/index.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#10213 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#10213 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://your-searcher.com/sp.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://your-searcher.com/index.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe O4 - HKLM\..\Run: [Microsoft Update] wumgrd.exe O4 - HKLM\..\Run: [Dial32] C:\WINDOWS\dl.exe O4 - HKLM\..\Run: [ist service uninstall] C:\WINDOWS\mssys.exe /u O4 - HKLM\..\Run: [xor] C:\WINDOWS\System32\x0r\svshost.exe O4 - HKLM\..\RunServices: [Microsoft Update] wumgrd.exe O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Swrr] C:\Documents and Settings\user\Application Data\pber.exe O4 - HKCU\..\Run: [WNST] C:\WINDOWS\System32\wnsapicc.exe O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Microsoft Update] wumgrd.exe O4 - HKCU\..\Run: [dllhelp] c:\windows\dllhelp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Startup: PowerReg Scheduler V3.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe O4 - Global Startup: officejet 6100.lnk = ? O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: AOL Instant Messenger (TM) (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O13 - DefaultPrefix: O13 - WWW Prefix: O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://cashsearch.biz/legal/x.chm::/load.exe O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab |
|
|
|
|
|
#21 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
thank u tomster.. heres the thign u wanted lobos.. i really hope we cna do soemthign about my comp
|
|
|
|
|
|
#22 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
yep you have alittle bit of everything
going through your log now |
|
|
|
|
|
#23 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
Download
CWShredder by Merijn Bellekom, the creator of Hijack This install it into its own folder update it Run it, press 'Fix', and allow it to fix all it finds. And remember to click "Fix" (Not "Scan only") Reboot ----------------------------------------------------------------------- next run hijack this put a check next to these close all browsers and click fix Make sure not to miss one R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://your-searcher.com/sp.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://your-searcher.com/sp.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://your-searcher.com/index.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%00@<a href="htt...cc/search/</a> (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%00@<a href="htt...cc/search/</a> (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%00@<a href="htt...cc/search/</a> (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%00@<a href="htt...cc/search/</a> (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#10213 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#10213 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%00@<a href="htt...cc/search/</a> (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://your-searcher.com/sp.htm R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://your-searcher.com/index.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://homepage.com%00@<a href="htt...cc/search/</a> (obfuscated) O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe O4 - HKLM\..\Run: [Microsoft Update] wumgrd.exe O4 - HKLM\..\Run: [Dial32] C:\WINDOWS\dl.exe O4 - HKLM\..\Run: [ist service uninstall] C:\WINDOWS\mssys.exe /u O4 - HKLM\..\Run: [xor] C:\WINDOWS\System32\x0r\svshost.exe O4 - HKLM\..\RunServices: [Microsoft Update] wumgrd.exe O4 - HKCU\..\Run: [Swrr] C:\Documents and Settings\user\Application Data\pber.exe O4 - HKCU\..\Run: [WNST] C:\WINDOWS\System32\wnsapicc.exe O4 - HKCU\..\Run: [Microsoft Update] wumgrd.exe O4 - Startup: PowerReg Scheduler V3.exe O13 - DefaultPrefix: O13 - WWW Prefix: O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://cashsearch.biz/legal/x.chm::/load.exe O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab Next Open My Computer. Go to Tools, Folder Options and click on the View tab. Make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files". Now click"Apply to all folders" Click "Apply" then "OK reboot into safe mode How to boot into safe mode Delete what is in Bold C:\PROGRA~1\Lycos folder C:\WINDOWS\System32\x0r folder C:\WINDOWS\alchem.exe file C:\WINDOWS\system32\wumgrd.exe file C:\WINDOWS\dl.exe file C:\WINDOWS\mssys.exe file C:\Documents and Settings\user\Application Data\pber.exe file C:\WINDOWS\System32\wnsapicc.exe file come back and post a fresh log Last edited by Lobos; 05-25-2004 at 12:02 AM. |
|
|
|
|
|
#24 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
|
As a note - you can't change a rar file into an exe and expect it to run - you have to have a rar file utility such as Winrar to open it. Are you with me? A rar is a compressed archive similar to a zip file and Windows has no native support for rar. Your best bet to delete it is reboot into safe mode.
I think you have viruses in there too - you are going to have to do some kind of virus scan with an updated program. You also need to get all critical system updates from Windows Update. Stay calm - Lobos has you in good hands, this has to be taken a step at a time. What you see on Kazaa and *think* is music is not always so - a lot of those files are just disguised viruses. You need to virus scan EVERY file you download before you try to open it. |
|
|
|
|
|
#25 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
hey guys.. thank god my enternet works now
i love u guys u rock!! thank u a lot..still problems: my homepage still a porn site.. my links open in tiny windows that rar file i downloaded still wont delete now plz tell me how to keep my healthier comp clean all i know is: dont download music dont go to porn sites update ur spybto and anti virus evryday any other tips?? Last edited by manslauter; 05-25-2004 at 04:48 PM. |
|
|
|
|
|
#26 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
new log:
Logfile of HijackThis v1.97.7 Scan saved at 5:36:14 PM, on 25/05/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\MSI\Core Center\CoreCenter.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\NetAssistant\bin\mpbtn.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\WINDOWS\system.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\user\My Documents\blah\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [dllhelp] c:\windows\dllhelp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe O4 - Global Startup: officejet 6100.lnk = ? O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: AOL Instant Messenger (TM) (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab |
|
|
|
|
|
#27 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
if this doesnt get rid of your hijacker were going to have to try something else
as for your file you cannot delete try this handy little program Move on boot -------------------------------------------------------------------------- CWShredder Run it, press 'Fix', and allow it to fix all it finds. And remember to click "Fix" (Not "Scan only") ----------------------------------------------------------------------- next run hijack this put a check next to these close all browsers and click fix Make sure not to miss one R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php O4 - HKCU\..\Run: [dllhelp] c:\windows\dllhelp.exe Next Open My Computer. Go to Tools, Folder Options and click on the View tab. Make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files". Now click"Apply to all folders" Click "Apply" then "OK reboot into safe mode Delete what is in Bold c:\windows\dllhelp.exe --------------------------------------------------------------------------------------------------------- CWShredder Run it, press 'Fix', and allow it to fix all it finds. And remember to click "Fix" (Not "Scan only") come back and post a fresh log Lobos Last edited by Lobos; 05-25-2004 at 05:50 PM. |
|
|
|
|
|
#28 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
yo man to tell u the truth im stupid so here goes:
Open My Computer. Go to Tools, Folder Options and click on the View tab. Make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files". Now click"Apply to all folders" Click "Apply" then "OK i alredy did that.. does that mean i can put it back to normal when its fixed?? also i dotng et the reboot into safe mode part.. ims tupid.. and the deleting thing.. where do ig o to delete the bold?? im stupid man lol |
|
|
|
|
|
#29 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
yes you can this just unhides files especially malware files that like to hide
when we get you cleaned back up you can rehide them |
|
|
|
|
|
#30 |
|
Member (8 bit)
Join Date: Feb 2004
Posts: 134
|
this is evil man.. my homepage is still porn..
cries*new log: Logfile of HijackThis v1.97.7 Scan saved at 8:21:17 PM, on 25/05/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\MSI\Core Center\CoreCenter.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\NetAssistant\bin\mpbtn.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\user\My Documents\blah\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [dllhelp] c:\windows\dllhelp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe O4 - Global Startup: officejet 6100.lnk = ? O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: AOL Instant Messenger (TM) (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|