Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

aaawebsearch/69sexsearch


  • Please log in to reply

#1
mrpecunia

mrpecunia

    New Member

  • Member
  • Pip
  • 1 posts
:tazz: My computer seems to be infected with aaawebsearch. It redirects my browsers startup page etc. Even when i am not online it pops up windows. Please Help!

This is a copy of my most recent Hijackthislog:

Logfile of HijackThis v1.99.0
Scan saved at 11:58:24, on 2-1-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\geinstalleerde software\diskkeeper\Diskkeeper\Diskkeeper\DkService.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\geinstalleerde software\i-tunes for windows\iTunes for Windows\iTunesHelper.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\xpsp2fw.exe
C:\windows\system32\dptdsadd.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuclient.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\internet downloads\webroot\spysweeper trial\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\internet downloads\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://aaawebsearch.com/?a=2&b=601
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://aaawebsearch.com/?a=2&b=601
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.home.nl/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.home.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.nl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://aaawebsearch.com/?a=2&b=601
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://aaawebsearch.com/?a=2&b=601
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://[email protected]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: Richfind - {E4900F2D-7FB1-48A2-9D1B-5A9E103AC2E7} - C:\WINDOWS\System32\Q987269.dll (file missing)
R3 - URLSearchHook: Richfind - {2B1ADDD0-8C52-4459-8DCF-13396C1E61C1} - C:\WINDOWS\System32\Q990854.dll (file missing)
R3 - URLSearchHook: Richfind - {8331F545-51E7-4946-81D2-7B3703C17F15} - C:\WINDOWS\System32\Q990854.dll (file missing)
R3 - URLSearchHook: Richfind - {035CD140-D147-4C0A-A3A9-CF4548253EE2} - C:\WINDOWS\System32\Q990854.dll (file missing)
R3 - URLSearchHook: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
R3 - URLSearchHook: Richfind - {0E63CDB2-B2C8-4CF2-8012-F1A0CC43CD6B} - C:\WINDOWS\System32\Q1511403.dll (file missing)
R3 - URLSearchHook: (no name) - {900E5495-08C7-EA19-F0E9-CF4714E05A26} - C:\windows\system32\dptdsadd.exe
O2 - BHO: BHO - {00000015-A527-34E7-25C2-03A4E313B2E9} - c:\WINDOWS\system32\winsrvs_1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\internet downloads\adobe reader\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0C507AC8-9CC4-1970-BE39-A99F9532D512} - C:\WINDOWS\crcb.dll (file missing)
O2 - BHO: Richfind - {3F6AD2D1-E85B-47B8-8F8D-CCC7169D5DAC} - C:\WINDOWS\System32\Q990854.dll (file missing)
O2 - BHO: Popup Killer - {4A3A071E-F913-4eee-AE15-AEFFA16FB6BC} - C:\WINDOWS\PopUpWasher21.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\internet downloads\spybot\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Richfind - {5B0ACFA5-2765-4030-A69D-11EC93F899B7} - C:\WINDOWS\System32\Q1002591.dll (file missing)
O2 - BHO: Richfind - {671A6729-9E16-4D4D-8748-6AD66138C3E3} - C:\WINDOWS\System32\Q990854.dll (file missing)
O2 - BHO: Richfind - {70F28BC1-3E09-4BBD-B060-A9A9634A8912} - C:\WINDOWS\System32\Q990854.dll (file missing)
O2 - BHO: Richfind - {F32E2F7B-71FF-41ED-880E-7129C5BF8C85} - C:\WINDOWS\System32\Q1511403.dll (file missing)
O2 - BHO: Richfind - {FD981860-3385-4A81-AF0A-159479DA6AEC} - C:\WINDOWS\System32\Q987269.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Richfind - {A718102F-370D-46EB-B47F-DA8688CB2844} - C:\WINDOWS\System32\Q987269.dll (file missing)
O3 - Toolbar: Richfind - {FEC26A79-A0AB-4AF7-885B-E4BCCB392C73} - C:\WINDOWS\System32\Q990854.dll (file missing)
O3 - Toolbar: Richfind - {0C32583F-69AB-4D4C-8C88-058C5DDCB484} - C:\WINDOWS\System32\Q990854.dll (file missing)
O3 - Toolbar: Richfind - {69C29651-537F-4105-912D-7AE9D17B7724} - C:\WINDOWS\System32\Q990854.dll (file missing)
O3 - Toolbar: Richfind - {CFCE01FC-0894-49D3-9BA5-88942EA84328} - C:\WINDOWS\System32\Q997774.dll (file missing)
O3 - Toolbar: Richfind - {B44E204E-3743-4A7D-AB48-1578E4128DAA} - C:\WINDOWS\System32\Q1002591.dll (file missing)
O3 - Toolbar: Richfind - {36A8776C-A87E-4C79-9113-DEF9CF0B9238} - C:\WINDOWS\System32\Q1047005.dll (file missing)
O3 - Toolbar: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O3 - Toolbar: Richfind - {520829CC-EBB4-44C1-8E3E-1397090D2908} - C:\WINDOWS\System32\Q1511403.dll (file missing)
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\geinstalleerde software\i-tunes for windows\iTunes for Windows\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [ImInstaller] C:\DOCUME~1\Mario\LOCALS~1\Temp\ImInstaller\IncrediMail\imloader.exe -product IncrediMail
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KAZAA] "C:\internet downloads\kazaalite nieuw\Kazaa Lite\kpp.exe" "C:\internet downloads\kazaalite nieuw\Kazaa Lite\kazaalite.kpp" /SYSTRAY
O4 - HKLM\..\Run: [XPSP2 Firewall] C:\WINDOWS\system32\xpsp2fw.exe
O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
O4 - HKLM\..\Run: [8C2EF3E3] C:\windows\system32\dptdsadd.exe
O4 - HKLM\..\Run: [44E87E66] C:\WINDOWS\system32\ldpadbo.exe
O4 - HKLM\..\Run: [CCA9BF76] C:\WINDOWS\system32\dslrasfs.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\geinstalleerde software\Nero burn\Nero.6.Ultra.Edition.6.3.1.20.Incl.Powerpack.FULL-RETAIL(0-Day-13.Aug)\Nero.6.Ultra.Edition.6.3.1.20.Incl.Powerpack.(MAJOR.UPDATE-13.Aug)\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Windows Update Client ] C:\WINDOWS\system32\wuclient.exe
O4 - HKCU\..\Run: [44E87E66] C:\WINDOWS\system32\ldpadbo.exe
O4 - HKCU\..\Run: [8C2EF3E3] C:\windows\system32\dptdsadd.exe
O4 - HKCU\..\Run: [CCA9BF76] C:\WINDOWS\system32\dslrasfs.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Richfind - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Richfind - {0C32583F-69AB-4D4C-8C88-058C5DDCB484} - C:\WINDOWS\System32\Q990854.dll (file missing)
O9 - Extra button: Richfind - {36A8776C-A87E-4C79-9113-DEF9CF0B9238} - C:\WINDOWS\System32\Q1047005.dll (file missing)
O9 - Extra button: Richfind - {520829CC-EBB4-44C1-8E3E-1397090D2908} - C:\WINDOWS\System32\Q1511403.dll (file missing)
O9 - Extra button: Richfind - {69C29651-537F-4105-912D-7AE9D17B7724} - C:\WINDOWS\System32\Q990854.dll (file missing)
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Richfind - {A718102F-370D-46EB-B47F-DA8688CB2844} - C:\WINDOWS\System32\Q987269.dll (file missing)
O9 - Extra button: Richfind - {B44E204E-3743-4A7D-AB48-1578E4128DAA} - C:\WINDOWS\System32\Q1002591.dll (file missing)
O9 - Extra button: Richfind - {CFCE01FC-0894-49D3-9BA5-88942EA84328} - C:\WINDOWS\System32\Q997774.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Richfind - {FEC26A79-A0AB-4AF7-885B-E4BCCB392C73} - C:\WINDOWS\System32\Q990854.dll (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://start.home.nl/
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.gocyberli...udio/ChkDVD.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1096742218627
O23 - Service: AutoComplete Service - Unknown - C:\internet downloads\internetsweeper\Internet Sweeper Pro\autocomp.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\geinstalleerde software\diskkeeper\Diskkeeper\Diskkeeper\DkService.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe





Thanks for your help......
  • 0

Advertisements


#2
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi

We can definitely help you, but first you need to help us. The first step in this process is to apply Service Pack 1a for Windows XP. Without this update, you're wide open to re-infection, and we're both just wasting our time.
Click here: http://www.microsoft...p1/default.mspx
Apply the update, reboot, and post a fresh Hijack This log.

kc :tazz:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP