In need of help old comrade's.

Having software/hardware problems? Get help here!

In need of help old comrade's.

Postby Spadess » Sun Apr 19, 2009 7:43 pm

Hello me old chumlys! Im in need of some help..

Im nearlly at the end of my studying time for this year and im in need of some urgent help. My computer is a mess and with no cd for a clean re-boot for the OS im stuck trying to fix my problem. All the time my computer is really slow and advert windows pop up constantly.. I have a high jack this report list if It can help with getting my pc better again.

Beside's that I hope I can play some time with you guys soon. I had to put my laptop on hold because of expenses with uni so Now unfortunatley I wont get a lovely high end rig I was hoping more like a practical laptop but hopefull one that lets me play anywhere I can with you.

Logfile of HijackThis v1.99.1
Scan saved at 21:25:21, on 19/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\Program Files\Belkin\F5D7051\WLService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Belkin\F5D7051\WLanCfgG.exe
D:\BT Common Client\btomosrv.exe
D:\Program Files\Kontiki\KService.exe
D:\WINDOWS\system32\PnkBstrA.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\Program Files\Spyware Terminator\sp_rsser.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Razer\DeathAdder\razerhid.exe
D:\Program Files\Ideazon\ZEngine\Zboard.exe
D:\Program Files\Canon\MyPrinter\BJMyPrt.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Razer\DeathAdder\razertra.exe
D:\Program Files\Razer\DeathAdder\razerofa.exe
D:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Program Files\BitComet\BitComet.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Program Files\iTunes\iTunes.exe
D:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: 82.98.231.89 url.adtrgt.com
O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
O1 - Hosts: scanner.info
O1 - Hosts: 82.98.231.89 antivirus-xp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.infosecuritycenter.com
O1 - Hosts: 82.98.231.89 microsoft.softwaresecurityhelp.com
O1 - Hosts: 82.98.231.89 onlinenotifyq.net
O1 - Hosts: 82.98.231.89 antivirusxp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.browser-security-center.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {449a697f-076e-44e6-acac-0dc8fbe0fd70} - D:\WINDOWS\system32\mufokuvo.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [DeathAdder] D:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [Zboard] D:\Program Files\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] D:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] D:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [vosihogazi] Rundll32.exe "D:\WINDOWS\system32\jozoyona.dll",s
O4 - HKLM\..\Run: [bc4fcf9f] rundll32.exe "D:\WINDOWS\system32\pamepusu.dll",b
O4 - HKLM\..\Run: [CPM8f0f47bf] Rundll32.exe "d:\windows\system32\rifediga.dll",a
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O8 - Extra context menu item: &D&ownload &with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://D:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://D:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: d:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZI ... b56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: d:\windows\system32\wuhahate.dll D:\WINDOWS\system32\suhalewo.dll d:\windows\system32\diburazo.dll d:\windows\system32\rifediga.dll
O20 - Winlogon Notify: avgrsstarter - D:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - d:\windows\system32\rifediga.dll
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Belkin High-Speed Mode Wireless G USB Driver (Belkin High-Speed Mode Wireless G USB Network Adapter Service) - Unknown owner - D:\Program Files\Belkin\F5D7051\WLService.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BT Common Client - British Telecommunications Plc. - D:\BT Common Client\btomosrv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - D:\Program Files\Kontiki\KService.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - D:\Program Files\Spyware Terminator\sp_rsser.exe
Image
User avatar
Spadess
1st Lieutenant
1st Lieutenant
 
Posts: 1040
Joined: Wed Oct 18, 2006 1:25 pm

Re: In need of help old comrade's.

Postby [Aliens]kronenbourg » Sun Apr 19, 2009 10:44 pm

Hi mate, you have an out of date HijackThis. Uninstall it, then use this one:


Click here to download HJTInstall.exe
  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

Kro
Image

Image
User avatar
[Aliens]kronenbourg
Lieutenant General
Lieutenant General
 
Posts: 4665
Joined: Thu Oct 19, 2006 7:20 am
Location: Bradford, England

Re: In need of help old comrade's.

Postby [Aliens]kronenbourg » Wed Apr 22, 2009 10:41 pm

Okay, anyone reading this may wonder whats going on...

Spadess can't log into Aliens, so helping him via email. I'll keep you all informed :)

Kro
Image

Image
User avatar
[Aliens]kronenbourg
Lieutenant General
Lieutenant General
 
Posts: 4665
Joined: Thu Oct 19, 2006 7:20 am
Location: Bradford, England

Re: In need of help old comrade's.

Postby [Aliens]solifer » Fri Apr 24, 2009 5:44 pm

[Aliens]kronenbourg wrote:Okay, anyone reading this may wonder whats going on...

Spadess can't log into Aliens, so helping him via email. I'll keep you all informed :)

Kro



Meaning cant log into our servers? or cant log in on our forum?
Image
Image
Camaro - If you don´t own one, you´ll never understand!
<<-Bönder är liksom en egen ras, precis som rörmokare och föräldrar->>
User avatar
[Aliens]solifer
General
General
 
Posts: 7136
Joined: Wed Oct 18, 2006 12:31 pm
Location: Sweden Borlänge

Re: In need of help old comrade's.

Postby [Aliens]kronenbourg » Fri Apr 24, 2009 5:53 pm

The forum.

Belive me, he has a nasty infection, but I've sent him some things, and I'm working on it :P
Image

Image
User avatar
[Aliens]kronenbourg
Lieutenant General
Lieutenant General
 
Posts: 4665
Joined: Thu Oct 19, 2006 7:20 am
Location: Bradford, England

Re: In need of help old comrade's.

Postby [Aliens]solifer » Fri Apr 24, 2009 5:59 pm

[Aliens]kronenbourg wrote:The forum.

Belive me, he has a nasty infection, but I've sent him some things, and I'm working on it :P


So it would not help with a new password then??
Image
Image
Camaro - If you don´t own one, you´ll never understand!
<<-Bönder är liksom en egen ras, precis som rörmokare och föräldrar->>
User avatar
[Aliens]solifer
General
General
 
Posts: 7136
Joined: Wed Oct 18, 2006 12:31 pm
Location: Sweden Borlänge

Re: In need of help old comrade's.

Postby [Aliens]kronenbourg » Fri Apr 24, 2009 6:10 pm

Nope, its malware/virus stuff :evil:
Image

Image
User avatar
[Aliens]kronenbourg
Lieutenant General
Lieutenant General
 
Posts: 4665
Joined: Thu Oct 19, 2006 7:20 am
Location: Bradford, England

Re: In need of help old comrade's.

Postby [Aliens]solifer » Sat Apr 25, 2009 6:17 am

Q-# Q-# Q-# Q-# :cry:
Image
Image
Camaro - If you don´t own one, you´ll never understand!
<<-Bönder är liksom en egen ras, precis som rörmokare och föräldrar->>
User avatar
[Aliens]solifer
General
General
 
Posts: 7136
Joined: Wed Oct 18, 2006 12:31 pm
Location: Sweden Borlänge

Re: In need of help old comrade's.

Postby [Aliens]Chrille » Sat Apr 25, 2009 7:47 am

[Aliens]spadess wrote:Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\Program Files\Belkin\F5D7051\WLService.exe
D:\Program Files\Bonjour\mDNSResponder.exe



after that you lost me :?: :?:
---Work It Harder Make It Better---
--Do It Faster, Makes Us stronger--
----More Than Ever Hour After----
-----Our Work Is Never Over-----
User avatar
[Aliens]Chrille
Lieutenant Colonel
Lieutenant Colonel
 
Posts: 2238
Joined: Sat Mar 01, 2008 7:36 pm
Location: Sweden - Skåne - Kristianstad

Re: In need of help old comrade's.

Postby [Aliens]RigRock » Sat Apr 25, 2009 6:00 pm

Bluemovis :dont: :wink:
Image
User avatar
[Aliens]RigRock
First Sergeant
First Sergeant
 
Posts: 456
Joined: Wed Oct 18, 2006 8:09 pm
Location: sweden\estonia


Return to Tech-support

Who is online

Users browsing this forum: No registered users and 1 guest

cron