doe Posted June 23, 2007 Report Posted June 23, 2007 as the topic !@#$%^&*le puts it I NEED HELP. ive been getting random pop ups. i know wuts causing them because my spyware found the problem the thing is that it cant fix it i ran HijackThis and this is what i got please help..here is the log of wut hijackthis came up with i dont know wuts good or bad Logfile of Trend Micro HijackThis v2.0.0 (BETA)Scan saved at 7:38:23 PM, on 3/22/2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: Normal Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\ls!@#$%^&*.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Java\jre1.5.0_11\bin\jusched.exeC:\Program Files\MarkAny\ContentSafer\MAAgent.exeC:\WINDOWS\system32\ctfmon.exeC:\WINDOWS\MCROSO~1.NET\winspool.exeC:\Program Files\Spyware Doctor\sdhelp.exeC:\WINDOWS\system32\wdfmgr.exeC:\WINDOWS\System32\alg.exeC:\Do!@#$%^&*ents and Settings\D03\My Do!@#$%^&*ents\?icrosoft\n?tepad.exeC:\Program Files\Yahoo!\Messenger\YahooMessenger.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\svchost.exeC:\PROGRA~1\Yahoo!\MESSEN~1\YServer.exeC:\Do!@#$%^&*ents and Settings\D03\Desktop\HiJackThis_v2.exeC:\WINDOWS\system32\wbem\wmiprvse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dslR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dslR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dslR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 69.88.144.161:R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: (no name) - H@497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: (no name) - {154D4FDA-A765-A591-4917-FB8DCA03D5C0} - C:\WINDOWS\system32\mbrh.dllO2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dllO2 - BHO: (no name) - {6C6B8C69-9285-4D94-8492-9E920C8C2B65} - C:\WINDOWS\System32\winhid64.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dllO2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dllO2 - BHO: (no name) - È?49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)O2 - BHO: (no name) - ø?B4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO4 - HKLM\..\Run: [s3TRAY2] S3tray2.exeO4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXEO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"O4 - HKLM\..\Run: [sMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exeO4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [Ahmp] "C:\WINDOWS\MCROSO~1.NET\winspool.exe" -vt yazbO4 - HKCU\..\Run: [Grbsadty] "C:\Do!@#$%^&*ents and Settings\D03\My Do!@#$%^&*ents\?icrosoft\n?tepad.exe"O4 - HKUS\S-1-5-18\..\Run: [spyware Doctor] (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [spyware Doctor] (User 'Default user')O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cabO16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dllO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jin...ows-i586-jc.cabO16 - DPF: {E5168F0C-8591-11D4-BCDF-006008B7FEA4} - http://aldine-platoweb.aldine.k12.tx.us/pa...ab/pwlninst.cabO22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dllO22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dllO23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: PC Tools Spyware Doctor (SDhelper) - Unknown owner - C:\Program Files\Spyware Doctor\sdhelp.exe --End of file - 4978 bytes
rootbear75 Posted June 23, 2007 Report Posted June 23, 2007 C:\Do!@#$%^&*ents and Settings\D03\My Do!@#$%^&*ents\?icrosoft\n?tepad.exe thats a false fileunless you had notepad running....delete that whole folder http://i157.photobucket.com/albums/t54/badgersocks/FHTG/FHTG%20-%20redone%20shizniz/tgmember11.pngrootbear75> here is me nude <spoiler tag: Pervert... how many of you actually clicked this?>Samapico> I actually clicked the spoiler before reading what it was Corey> I clicked it cause i read what sama said first. darkreb0rn> I clicked it because I wanted to see you naked... rootbear75> O.o __________________________________2:IdleRPG> Mr Snuffleluphagus walked face-first into a tree. This terrible calamity has slowed them 0 days, 00:01:22 from level 18.2:rootbear75> for fucks sake...
doe Posted June 24, 2007 Author Report Posted June 24, 2007 nevermind its ok i fixed it thanx n e ways
★ Dav Posted June 24, 2007 Report Posted June 24, 2007 1. moving to tech support (correct forum for this kind of thing) 2. Closed as problem solved. SSCC Desert Storm OwnerSSforum Admin
Recommended Posts