Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

IE6 Random popups including flash ads and random popup instances in fi


  • Please log in to reply

#1
INFERNO2K

INFERNO2K

    New Member

  • Member
  • Pip
  • 5 posts
Hello.

I am a computer science major, I should know better.

I made a stupid mistake of visiting a sly sight this morning and downloading software to help a friend look for sound engineer program.

Now I am recieving random popups with no programs open, sitting on my desktop. As well firefox opens randomly and outputs random popups too. Some even flash ads.

My log

Logfile of HijackThis v1.99.1
Scan saved at 10:06:51 AM, on 21/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\system32\dmremote.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Documents and Settings\Aaron\Desktop\HijackThis.exe

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nutafun4.dll' missing
O20 - Winlogon Notify: policies - C:\WINDOWS\system32\m646lghs1646.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

Appreciate any help. Thanks in advance.
  • 0

Advertisements


#2
INFERNO2K

INFERNO2K

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Might I add, one just popped up for searc-h.com
  • 0

#3
INFERNO2K

INFERNO2K

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Something seems to be injecting my hosts file too with crap

127.0.0.1  www.igetnet.com
127.0.0.1  code.ignphrases.com
127.0.0.1  clear-search.com
127.0.0.1  r1.clrsch.com
127.0.0.1  sds.clrsch.com
127.0.0.1  status.clrsch.com
127.0.0.1  www.clrsch.com
127.0.0.1  clr-sch.com
127.0.0.1  sds-qckads.com
127.0.0.1  status.qckads.com
127.0.0.1  www.qoolaid.com
127.0.0.1  www.qoologic.com
127.0.0.1  www.CLKPrecision.com
127.0.0.1  www.urllogic.com
127.0.0.1  www.clkoptimizer.com
127.0.0.1  www.isearch.com
127.0.0.1  isearch.com
127.0.0.1  www.idownload.com
127.0.0.1  idownload.com
127.0.0.1  www.mytotalsearch.com
127.0.0.1  mytotalsearch.com
127.0.0.1  www.lop.com
127.0.0.1  lop.com
127.0.0.1  www.websearch.com
127.0.0.1  websearch.com
127.0.0.1  www.page-not-found.net
127.0.0.1  page-not-found.net
127.0.0.1  www.isearchhere.com
127.0.0.1  isearchhere.com
127.0.0.1  xads.offeroptimizer.comm
127.0.0.1  search.offeroptimizer.com
127.0.0.1  ximages.offeroptimizer.com
127.0.0.1  xlime.offeroptimizer.com
127.0.0.1  xadsj-o.offeroptimizer.com
127.0.0.1  xadsj.offeroptimizer.com
127.0.0.1  www.offeroptimizer.com
127.0.0.1  as.adwave.com
127.0.0.1  sr.adwave.com
127.0.0.1  www.adwave.com
127.0.0.1  adwave.com

  • 0

#4
INFERNO2K

INFERNO2K

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
CWSHredder has found VX2.Look2Me
  • 0

#5
INFERNO2K

INFERNO2K

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
bump
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP