Basically, Internet Explorer will connect to the internet by itself and go to multiple ad websites and look at advertisements. The only way I know it is happening is that some of the commercials forget to mute themselves and I hear music and such playing in the background when I literally have not opened any sites or programs. I ran suggested programs like MBAM and SUPERAntiSpyware to no avail. Upon scanning, it just deletes a bunch of cookies and doesn't solve the problem. Also, when I use firefox to web surf, google results are redirected to other websites. I placed a fake proxy under internet options (0.0.0.0 port 80) to stop IE from being able to connect to things. This seemed to have worked as a temporary workaround until recently. Now I get periodic IE error boxes saying "Stack overflow at line X" or "[random advertisement] click on this box to stay on this page!". I have process explorer up and don't see any IE programs running, but I still get the errors and messages.
Also, this is Vista 64 bit so I can't run the other logs. Thank you in advance!
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_29
Run by C1 at 9:26:04 on 2011-12-19
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.6133.1685 [GMT -5:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\amBX\System\amBX_Service.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\amBX\Device Drivers\Philips USB\Philips_amBX_USB_HAL.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\StkCSrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files (x86)\Belkin\F7D4101\V1\wlansrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\World of Warcraft\WoW.exe
C:\Windows\explorer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Settings,ProxyServer = 0.0.0.0:80
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.2.8.7.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
StartupFolder: C:\Users\C1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &D&ownload &with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe/AddAllLink.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.2.8.7.dll/206
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1 68.87.73.246 68.87.81.230
TCP: Interfaces\{06A6FA3E-DC2F-45C9-B331-6FACF0DB58CF} : DhcpNameServer = 192.168.1.1 68.87.73.246 68.87.81.230
TCP: Interfaces\{360D058F-560F-49CD-B344-88C1704163AF} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{6D2A77D9-5C41-437A-A96D-6F42EE70D4AA} : DhcpNameServer = 192.168.1.1 68.87.73.246 68.87.71.230
TCP: Interfaces\{7A993A6C-1091-4BD8-BCBA-6236B3EA305B} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{80058CD3-3736-4972-81B1-568D94549DF4} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{89EED8E8-4E5B-424E-B2EA-011E832DE078} : DhcpNameServer = 192.168.1.1 68.87.73.246 68.87.81.230
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: BitComet Helper: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.2.8.7.dll
BHO-X64: BitComet ClickCapture - No File
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
IE-X64: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.2.8.7.dll/206
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\C1\AppData\Roaming\Mozilla\Firefox\Profiles\prw99jkw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=100000000000000002&tb_oid=12-05-2010&tb_mrud=12-05-2010
FF - prefs.js: browser.search.selectedEngine - Wowhead
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/Djxyanyde
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=ZUGO&form=ZGAADF&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\Users\C1\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\C1\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\C1\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
============= SERVICES / DRIVERS ===============
.
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 amBX Service;amBX Service;C:\Program Files (x86)\amBX\System\amBX_Service.exe [2008-4-17 612864]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 IOCBIOS;IOCBIOS;C:\ProgramData\Intel\Extreme Tuning Utility\IOCbios\64bit\iOCbios.sys [2008-10-8 23000]
R2 Philips amBX USB HAL;Philips amBX USB HAL;C:\Program Files (x86)\amBX\Device Drivers\Philips USB\Philips_amBX_USB_HAL.exe [2008-6-9 540672]
R2 StkSSrv;Syntek AVStream USB2.0 ATV Service;C:\Windows\System32\StkCSrv.exe --> C:\Windows\System32\StkCSrv.exe [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdLH6.sys --> C:\Windows\system32\drivers\AtihdLH6.sys [?]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;C:\Windows\system32\DRIVERS\e1y60x64.sys --> C:\Windows\system32\DRIVERS\e1y60x64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-7 136176]
S3 BCMH43XX;N+ Wireless USB Adapter Driver;C:\Windows\system32\DRIVERS\bcmwlhigh664.sys --> C:\Windows\system32\DRIVERS\bcmwlhigh664.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-7 136176]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8187B.sys --> C:\Windows\system32\DRIVERS\RTL8187B.sys [?]
S3 StkCMini;Syntek AVStream USB2.0 ATV;C:\Windows\system32\Drivers\StkCMini.sys --> C:\Windows\system32\Drivers\StkCMini.sys [?]
S4 atashost;WebEx Service Host for Support Center;"C:\Windows\SysWOW64\atashost.exe" --> C:\Windows\SysWOW64\atashost.exe [?]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-9-16 89920]
S4 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-8-27 92008]
.
=============== Created Last 30 ================
.
2011-12-18 22:17:35 466456 ----a-w- C:\Windows\System32\wrap_oal.dll
2011-12-18 22:17:35 122904 ----a-w- C:\Windows\System32\OpenAL32.dll
2011-12-18 22:17:35 -------- d-----w- C:\Program Files (x86)\OpenAL
2011-12-17 11:01:54 -------- d-----w- C:\Users\C1\AppData\Local\LogMeIn Hamachi
2011-12-17 11:01:22 -------- d-----w- C:\Program Files (x86)\LogMeIn Hamachi
2011-12-17 05:53:50 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{951A4D95-FE9E-478F-B51F-E72AEAE5236A}\offreg.dll
2011-12-17 05:02:12 -------- d-----w- C:\Program Files\Microsoft Xbox 360 Accessories
2011-12-16 16:27:08 78680 ----a-w- C:\Windows\System32\XAPOFX1_4.dll
2011-12-16 16:27:08 530776 ----a-w- C:\Windows\System32\XAudio2_6.dll
2011-12-16 16:27:05 2582888 ----a-w- C:\Windows\System32\D3DCompiler_42.dll
2011-12-16 16:27:05 1974616 ----a-w- C:\Windows\SysWow64\D3DCompiler_42.dll
2011-12-16 16:27:02 2475352 ----a-w- C:\Windows\System32\D3DX9_42.dll
2011-12-16 16:27:02 1892184 ----a-w- C:\Windows\SysWow64\D3DX9_42.dll
2011-12-16 15:47:42 74072 ----a-w- C:\Windows\SysWow64\XAPOFX1_4.dll
2011-12-16 15:47:42 528216 ----a-w- C:\Windows\SysWow64\XAudio2_6.dll
2011-12-16 15:47:42 238936 ----a-w- C:\Windows\SysWow64\xactengine3_6.dll
2011-12-16 15:47:41 22360 ----a-w- C:\Windows\SysWow64\X3DAudio1_7.dll
2011-12-16 15:47:30 -------- d-----w- C:\Program Files (x86)\Microsoft XNA
2011-12-16 07:12:29 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{951A4D95-FE9E-478F-B51F-E72AEAE5236A}\mpengine.dll
2011-12-14 15:24:52 -------- d-----w- C:\Users\C1\AppData\Local\ArmA 2 Free
2011-12-14 11:10:40 -------- d-----w- C:\Program Files (x86)\Bohemia Interactive
2011-12-13 06:41:42 -------- d-----w- C:\Program Files (x86)\AMD APP
2011-12-01 12:21:13 627600 ----a-w- C:\Windows\System32\deployJava1.dll
2011-11-26 00:46:48 -------- d-----w- C:\Users\C1\AppData\Roaming\SUPERAntiSpyware.com
2011-11-26 00:45:41 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-11-26 00:45:41 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-11-24 01:27:29 65736 ----a-w- C:\Windows\System32\drivers\pxrts.sys
2011-11-24 01:27:27 -------- d-----w- C:\Program Files\Prevx
2011-11-24 01:26:55 -------- d-----w- C:\ProgramData\PrevxCSI
2011-11-24 00:19:23 -------- d-----w- C:\Windows\pss
.
==================== Find3M ====================
.
2011-12-18 22:17:35 444952 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2011-12-18 22:17:35 109080 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2011-11-21 03:13:59 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-28 14:34:12 39192 ----a-w- C:\Windows\System32\Partizan.exe
2011-10-28 14:32:04 2 --shatr- C:\Windows\winstart.bat
2011-10-26 02:21:54 66560 ----a-w- C:\Windows\System32\OpenVideo64.dll
2011-10-26 02:21:48 56832 ----a-w- C:\Windows\SysWow64\OpenVideo.dll
2011-10-26 02:21:40 66560 ----a-w- C:\Windows\System32\OVDecoder64.dll
2011-10-26 02:21:34 56832 ----a-w- C:\Windows\SysWow64\OVDecoder.dll
2011-10-26 02:21:24 16991744 ----a-w- C:\Windows\System32\amdocl64.dll
2011-10-26 02:20:42 13950464 ----a-w- C:\Windows\SysWow64\amdocl.dll
2011-10-03 09:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-09-20 21:06:18 1426304 ----a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 9:34:18.52 ===============
Attached File(s)
-
Attach.txt (8.12K)
Number of downloads: 0

Help
This topic is locked


Back to top













