Any help would be appreciated.Logfile of HijackThis v1.99.1
Scan saved at 5:53:01 PM, on 7/06/2010
Platform: Unknown Windows (WinNT 6.00.1906 SP2)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\dvd43\DVD43_Tray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Users\Jili\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\jili\programs to install\antispyware\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14672&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://au.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [googletalk] C:\Users\Jili\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International
O17 - HKLM\System\CCS\Services\Tcpip\..\{49970718-9D9E-43AB-88D2-DD4CD2BD45EB}: NameServer = 93.188.162.164,93.188.166.195
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.162.164,93.188.166.195
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.162.164,93.188.166.195
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.164,93.188.166.195
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
some help using HiJack this
Moderator: Thanas
- mr friendly guy
- The Doctor
- Posts: 11235
- Joined: 2004-12-12 10:55pm
- Location: In a 1960s police telephone box somewhere in Australia
some help using HiJack this
Some random adds keep on appearing.
Never apologise for being a geek, because they won't apologise to you for being an arsehole. John Barrowman - 22 June 2014 Perth Supernova.
Countries I have been to - 14.
Australia, Canada, China, Colombia, Denmark, Ecuador, Finland, Germany, Malaysia, Netherlands, Norway, Singapore, Sweden, USA.
Always on the lookout for more nice places to visit.
Countries I have been to - 14.
Australia, Canada, China, Colombia, Denmark, Ecuador, Finland, Germany, Malaysia, Netherlands, Norway, Singapore, Sweden, USA.
Always on the lookout for more nice places to visit.
Re: some help using HiJack this
I won't pretend to be an expert on this, but running your log through this handy tool reveals the following possible issues:
Recommended procedure is to run a Spybot Search and Destroy (or equivalent) scan. Spybot S&D is available here, documentation is available on the website, and if you need any further help feel free to ask.
O17 is indicative of a domain hack, and a quick check of Wikipedia reveals this.O17 - HKLM\System\CCS\Services\Tcpip\..\{49970718-9D9E-43AB-88D2-DD4CD2BD45EB}: NameServer = 93.188.162.164,93.188.166.195 Do you know the IP or Domain '93.188.162.164,93.188.166.195'? If not, fix this entry.
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.162.164,93.188.166.195 Nasty (1.89 / 5.00)
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.162.164,93.188.166.195 Nasty (1.89 / 5.00)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.164,93.188.166.195 Nasty (1.82 / 5.00)
Recommended procedure is to run a Spybot Search and Destroy (or equivalent) scan. Spybot S&D is available here, documentation is available on the website, and if you need any further help feel free to ask.
- mr friendly guy
- The Doctor
- Posts: 11235
- Joined: 2004-12-12 10:55pm
- Location: In a 1960s police telephone box somewhere in Australia
Re: some help using HiJack this
I already ran a spybot search and destroy. They identified several problems, however one of them it refused to remove saying I am not an administrator or something or rather. Which is all very strange since this is my own personal desktop. WTF?
Never apologise for being a geek, because they won't apologise to you for being an arsehole. John Barrowman - 22 June 2014 Perth Supernova.
Countries I have been to - 14.
Australia, Canada, China, Colombia, Denmark, Ecuador, Finland, Germany, Malaysia, Netherlands, Norway, Singapore, Sweden, USA.
Always on the lookout for more nice places to visit.
Countries I have been to - 14.
Australia, Canada, China, Colombia, Denmark, Ecuador, Finland, Germany, Malaysia, Netherlands, Norway, Singapore, Sweden, USA.
Always on the lookout for more nice places to visit.
- SCRawl
- Has a bad feeling about this.
- Posts: 4191
- Joined: 2002-12-24 03:11pm
- Location: Burlington, Canada
Re: some help using HiJack this
It's possible that you're not logged in as the administrator. You might have been set up (by whoever set up your computer) as a power user without administrator privileges. (I only ever do this when the computer I'm setting up will be used by idiots; this clearly doesn't apply in your case, so I can't think of a good reason for it.)
When you turn on your computer, do you have a login screen of any kind?
When you turn on your computer, do you have a login screen of any kind?
73% of all statistics are made up, including this one.
I'm waiting as fast as I can.
I'm waiting as fast as I can.
- mr friendly guy
- The Doctor
- Posts: 11235
- Joined: 2004-12-12 10:55pm
- Location: In a 1960s police telephone box somewhere in Australia
Re: some help using HiJack this
The thing is, I looked on control panel and it blatantly says I am the administrator.
Never apologise for being a geek, because they won't apologise to you for being an arsehole. John Barrowman - 22 June 2014 Perth Supernova.
Countries I have been to - 14.
Australia, Canada, China, Colombia, Denmark, Ecuador, Finland, Germany, Malaysia, Netherlands, Norway, Singapore, Sweden, USA.
Always on the lookout for more nice places to visit.
Countries I have been to - 14.
Australia, Canada, China, Colombia, Denmark, Ecuador, Finland, Germany, Malaysia, Netherlands, Norway, Singapore, Sweden, USA.
Always on the lookout for more nice places to visit.
- GrandMasterTerwynn
- Emperor's Hand
- Posts: 6787
- Joined: 2002-07-29 06:14pm
- Location: Somewhere on Earth.
Re: some help using HiJack this
Could be you've got some sort of malware that's preventing Spybot from removing it. Try another malware remover. MalwareBytes is good.mr friendly guy wrote:I already ran a spybot search and destroy. They identified several problems, however one of them it refused to remove saying I am not an administrator or something or rather. Which is all very strange since this is my own personal desktop. WTF?
Tales of the Known Worlds:
2070s - The Seventy-Niners ... 3500s - Fair as Death ... 4900s - Against Improbable Odds V 1.0
2070s - The Seventy-Niners ... 3500s - Fair as Death ... 4900s - Against Improbable Odds V 1.0