Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection > HijackThis Logs (finished)

 
 
LinkBack Thread Tools Display Modes
Old 12-15-2004, 10:57 AM   #1 (permalink)
Newb Techie
 
Join Date: Dec 2004
Posts: 12
Default Hijackthis HELP!!!!

Can someone pleasew take a look at my logfile. I can't seem to stop thses popups.

ThaLogfile of HijackThis v1.98.2
Scan saved at 11:50:32 AM, on 12/15/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dictionary.reference.com/wordoftheday/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SDWin32 Class - {70F76C7E-B070-4A82-B432-0949F3A4EFD0} - C:\WINDOWS\System32\fbcxx.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [C:\WINDOWS\sbhvy.exe] C:\WINDOWS\sbhvy.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DR_S] C:\Program Files\DR_S\DR_S.exe
O4 - HKCU\..\Run: [SYSfit] C:\WINDOWS\SYSfit.exe
O4 - HKCU\..\Run: [dow3RjKmj] ipsdexts.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV0 2.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1103119060978
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://dar.armstrong.com/ib/databases/actimage30717.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E86B042-64C7-4B53-9BC2-6B3B55C6BC91}: Domain = Miller
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E86B042-64C7-4B53-9BC2-6B3B55C6BC91}: NameServer = 192.226.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E86B042-64C7-4B53-9BC2-6B3B55C6BC91}: Domain = Miller
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E86B042-64C7-4B53-9BC2-6B3B55C6BC91}: NameServer = 192.226.0.1

nks,

Jerry


jzak22 is offline  
Old 12-15-2004, 11:16 AM   #2 (permalink)
Super Techie
 
Join Date: Jul 2004
Posts: 421
Send a message via AIM to silence782
Default

I'd just back up your data and reformat. Sometimes, it's just better to do that then go through all the hassle.
__________________
Still weak, I know, but getting better:
CPU: AMD AthlonXP 2500+
1.8GHz @ 333 FSB
512 DDR 2700
160 GB westerndigital hd
Dual booted with XP/Fedora Core 5
PCchips M848A mobo
nVIDIA GeForce MX 4000 video Card
Associate\'s Degree in Applied Computer Sciences.
A+ Certified for Hardware and Operating Systems. Network+ Certified
silence782 is offline  
Old 12-24-2004, 08:51 PM   #3 (permalink)
Admin
 
Dave's Avatar
 
Join Date: Mar 2002
Location: "Almost Heaven" USA
Posts: 4,855
Send a message via AIM to Dave Send a message via Yahoo to Dave
Default

Hi Jerry. It seems that your HJT log file was overlooked. If you haven't had it read and still need help, please download and run the latest version of HijackThis.

In the meantime, if you don't recognize this url, it may be the culprit and should be fixed:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html

Dave
__________________


Tech Forums
Moderating Policies | Forum Rules | ***PROFANITY***

Note that I do not accept support requests via IM, email, or PMs. Please ask it on the forums.


Trying this out: My Dollar Store :: Naturally Good


Dave is offline  
Old 01-13-2005, 10:23 PM   #4 (permalink)
Monster Techie
 
Join Date: Nov 2004
Posts: 1,346
Send a message via AIM to southernlady Send a message via Yahoo to southernlady
Default

Closing this thread due to lack of activity. Liz
southernlady is offline  
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 09:31 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0