Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.![]() ![]() |
Jan 5 2009, 05:10 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 5-January 09 Member No.: 278,686 |
1/5/09 I come to this website in need of help for my computer becuase I keep getting pop up advertisements. The pop ups came from website files with: 70.38.98.32 77.93.75.150 <http://77.93.75.150/dot.gif/?ver=112&cmp.> When I yahoo searched for help, i came up with some websites which I listed below. The website at : http://www.bleepingcomputer.com/forums/ind...p;#entry1034487 said to repost this.. I got the same problem.. check out also yahoo http://answers.yahoo.com/question/index?qi...01162651AA1r54z The answer for yahoo isn't too great. I followed the instructions and was told to post the DDS file not the ATTACH file. On a side note: I could not download : Malwarebytes ... but i downloaded SUperAntiSpyware. Ill let everybody if it works.. so far it looks like SAS is the way to go! Here's the DDS file [[[[[[[[ DDS (Version 1.1.0) - NTFSx86 Run by computer user at 16:40:29.53 on Mon 01/05/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.138 [GMT -5:00] AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\System32\QCONSVC.EXE C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\System32\TPHDEXLG.EXE C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe C:\WINDOWS\system32\wscntfy.exe C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLIcon.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~2\VPTray.exe C:\JayPrograms\Office\Calendar\TaskPlusFiles\taskplus0.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Yahoo!\Common\YMailAdvisor.exe C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\JayPrograms\Media\iTunes\iTunesHelper.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe C:\Program Files\iPod\bin\iPodService.exe C:\JayPrograms\Media\Winamp\Winampfiles\winamp.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\JayPrograms\InstallationFiles\Internet\Spybot\PopupProblemBleepingComputer\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.umdnj.edu/ uSearch Page = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html mDefault_Page_URL = hxxp://www.yahoo.com mStart Page = hxxp://www.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: NoExplorer - No File BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\wvUnOGyy.dll BHO: {cfb399d9-6aae-0efa-1a84-541a0848b2f7}: {7f2b8480-a145-48a1-afe0-eaa69d993bfc} - c:\windows\system32\xelevy.dll BHO: {a442c522-319a-4866-8a35-7f39509adee1} - c:\windows\system32\hgGwwuVL.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe uRun: [YSearchProtection] c:\program files\yahoo!\search protection\SearchProtection.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor mRun: [QCTray] c:\progra~1\thinkpad\connec~1\QCTray.exe mRun: [QCWLIcon] c:\progra~1\thinkpad\connec~1\QCWLIcon.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~2\VPTray.exe mRun: [TaskPlus] c:\jayprograms\office\calendar\taskplusfiles\taskplus0.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe" mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\jayprograms\internet\aimfiles\aim.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_02\bin\npjpi150_02.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll Notify: QConGina - QConGina.dll Notify: tphotkey - tphklock.dll Notify: wvUnOGyy - wvUnOGyy.dll AppInit_DLLs: xelevy.dll SEH: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\wvUnOGyy.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll LSA: Authentication Packages = msv1_0 c:\windows\system32\hgGwwuVL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\comput~1\applic~1\mozilla\firefox\profiles\y02c0tr1.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\program files\mozilla firefox\\components\jar50.dll ATTENTION: FIREFOX POLICES IS IN FORCE c:\program files\mozilla firefox\\greprefs\all.js - pref("backups.number_of_prefs_copies", 1); c:\program files\mozilla firefox\\greprefs\all.js - pref("browser.link.open_newwindow.ui", 3); // prefs UI version c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.closed", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.document", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.frames", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.history", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.length", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.opener", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.parent", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.self", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.top", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.default.Window.window", "allAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.mailnews.DOMParser,parseFromString", "noAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("capability.policy.mailnews.DOMParser,parseFromStream", "noAccess"); c:\program files\mozilla firefox\\greprefs\all.js - pref("dom.disable_window_open_feature.status", false); c:\program files\mozilla firefox\\greprefs\all.js - pref("advanced.always_load_images", true); c:\program files\mozilla firefox\\greprefs\all.js - pref("network.protocol-handler.external.help", false); c:\program files\mozilla firefox\\greprefs\all.js - pref("network.http.connect.timeout", 30); // in seconds c:\program files\mozilla firefox\\greprefs\all.js - pref("network.http.request.timeout", 120); // in seconds c:\program files\mozilla firefox\\greprefs\all.js - pref("network.IDN_show_punycode", true); c:\program files\mozilla firefox\\greprefs\all.js - pref("network.image.imageBehavior", 0); // 0-Accept, 1-dontAcceptForeign, 2-dontUse c:\program files\mozilla firefox\\greprefs\all.js - pref("network.cookie.cookieBehavior", 3); // 0-Accept, 1-dontAcceptForeign, 2-dontUse, 3-p3p c:\program files\mozilla firefox\\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom c:\program files\mozilla firefox\\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("app.id", "{ec8030f7-c20a-464f-9b0e-13a3a9e97384}"); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("app.version", c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("app.extensions.version", "1.0"); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("app.build_id", c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("app.update.autoUpdateEnabled", true); // Whether or not background app updates c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("app.update.url", "chrome://mozapps/locale/update/update.properties"); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("app.update.updatesAvailable", false); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("app.update.lastUpdateDate", 0); // UTC offset when last App update was c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("app.update.performed", false); // Whether or not an update has been c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("extensions.update.autoUpdateEnabled", true); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("extensions.update.autoUpdate", false); // Automatically download and install c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("extensions.update.interval", 604800000); // Check for updates to Extensions and c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("extensions.update.lastUpdateDate", 0); // UTC offset when last Extension/Theme c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("extensions.update.severity.threshold", 5);// The number of pending Extension/Theme c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("extensions.update.count", 0); // The number of extension/theme/etc c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("update.interval", 3600000); // Check each of the above intervals c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("update.showSlidingNotification", true); // Windows-only slide-up taskbar c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("update.severity", 0); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("general.useragent.vendor", "Firefox"); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("general.useragent.vendorSub", c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("browser.update.resetHomepage", false); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("browser.startup.homepage_override.1", false); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("browser.turbo.enabled", false); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://browser/content/searchconfig.properties"); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://browser/content/searchconfig.properties"); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("update_notifications.enabled", true); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("update_notifications.provider.0.frequency", 7); // number of days c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("browser.xul.error_pages.enabled", false); c:\program files\mozilla firefox\\defaults\pref\firefox.js - pref("pfs.datasource.url", "chrome://mozapps/locale/plugins/plugins.properties"); ============= SERVICES / DRIVERS =============== R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [2005-5-20 59776] R0 TPDiskPM;TPDiskPM;c:\windows\system32\drivers\TPDiskPM.sys [2005-5-20 14208] R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2005-5-20 11520] R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2005-5-20 2432] R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968] R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2005-5-20 4608] R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2005-5-20 4442] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-12-2 99376] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090104.003\naveng.sys [2009-1-4 89104] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090104.003\navex15.sys [2009-1-4 876112] R3 TPInput;TPInput;c:\windows\system32\drivers\TPInput.sys [2005-5-20 6016] R4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160] R4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632] R4 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-9-27 1813232] R4 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.sys [2005-5-20 12288] S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-9-27 116464] =============== Created Last 30 ================ 2009-01-05 12:54 <DIR> --d----- c:\windows\pss 2009-01-04 18:17 1,307,356 ---sh--- c:\windows\system32\cgidvhsd.ini 2009-01-04 18:17 72,704 a------- c:\windows\system32\dshvdigc.dll 2009-01-04 18:17 129,024 a------- c:\windows\system32\xelevy.dll 2009-01-04 18:17 129,024 a------- c:\windows\system32\xvcecauy.dll 2009-01-04 18:15 6,224 a--sh--- c:\windows\system32\LVuwwGgh.ini2 2009-01-04 18:15 6,224 a--sh--- c:\windows\system32\LVuwwGgh.ini 2009-01-04 18:15 302,592 a------- c:\windows\system32\hgGwwuVL.dll 2009-01-04 18:10 69,814 a------- c:\windows\system32\awtUkJyx.dll 2009-01-04 18:10 34,816 a------- c:\windows\system32\wvUnOGyy.dll 2009-01-04 18:09 22,016 a------- c:\windows\system32\~.exe 2008-12-29 15:20 <DIR> --d--r-- c:\docume~1\comput~1\applic~1\Brother 2008-12-29 15:20 426 a------- c:\windows\BRWMARK.INI 2008-12-29 15:20 34 a------- c:\windows\system32\BD2040.DAT 2008-12-22 13:28 <DIR> --d----- c:\program files\MSECache 2008-12-16 16:36 <DIR> --d----- c:\program files\iPod 2008-12-16 16:36 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2008-12-16 16:34 <DIR> --d----- c:\program files\Bonjour 2008-12-12 11:50 25,856 a------- c:\windows\system32\drivers\usbprint.sys 2008-12-12 11:50 25,856 a------- c:\windows\system32\dllcache\usbprint.sys ==================== Find3M ==================== 2008-12-05 12:34 262,144 a------- C:\ntuser.dat 2008-10-24 06:10 453,632 -------- c:\windows\system32\dllcache\mrxsmb.sys 2008-10-16 14:13 1,809,944 a------- c:\windows\system32\dllcache\wuaueng.dll 2008-10-16 14:13 202,776 a------- c:\windows\system32\dllcache\wuweb.dll 2008-10-16 14:12 323,608 a------- c:\windows\system32\dllcache\wucltui.dll 2008-10-16 14:12 561,688 a------- c:\windows\system32\dllcache\wuapi.dll 2008-10-16 14:09 92,696 a------- c:\windows\system32\dllcache\cdm.dll 2008-10-16 14:09 51,224 a------- c:\windows\system32\dllcache\wuauclt.exe 2008-10-16 14:08 34,328 a------- c:\windows\system32\dllcache\wups.dll 2008-10-15 11:57 332,800 -------- c:\windows\system32\dllcache\netapi32.dll ============= FINISH: 16:42:25.23 =============== ]]]] Edit: Moved topic from Web Browsing/Email and Other Internet Applications to the more appropriate forum. ~ Animal This post has been edited by Orange Blossom: Jan 18 2009, 03:38 PM
Reason for edit: Deactivate link. ~ OB
|
|
|
|
Jan 5 2009, 07:28 PM
Post
#2
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,634 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
I have moved your Topic that includes a HijackThis log here to the Misplaced HJT Logs forum. You posted your log in a forum not intended for HijackThis logs analysis and probably missed the directions we provide to those who require assistance. We can only allow topics with such logs in the HijackThis Logs and Malware Removal forum. This restriction is to ensure you get the best help available, from those who specialize in malware anlaysis and removal. It also should prevent you from receiving ineffective or even potentially dangerous advice, whether well meaning or not.
Prior to posting a HJT log, we ask that you please read and follow all instructions in the pinned topic titled Preparation Guide For Use Before Posting A Hijackthis Log. Following the steps in this Guide will allow the HJT Team to quickly help you with specific fixes for what may remain on your system. Please complete all the steps in the Guide. If you can't perform a step, then skip it and continue with the next. In Step 6 there are instructions for downloading and running DDS which will create a Psuedo HJT Report as part of its log. When you have completed those steps, start a new topic in the HijackThis Logs and Malware Removal forum as directed in the Prep Guide to post a new log. Please DO NOT post any more logs to this topic, or post a log again in the wrong forum. The Misplaced HJT Logs forum is strictly a holding area where the BC Staff can assist you with preparations for and to properly post your log. If you have a question or encounter a problem in the Prep Guide, please do post back to this topic; that is what it is here for. When your new DDS/HJT log is posted in the proper forum, please reply to this topic with a link to your new topic. Once that is done, a Member of the HJT Team will analyze your log and assist you with step by step instructions to clean your computer or otherwise advise what needs to be done. Thanks for your cooperation and good luck. The BC Staff -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 21st November 2009 - 11:17 PM |