Need help badly, computer dying!!!!

Discussion in 'adware, spyware & hijack cleaning' started by Ryan32, Jun 15, 2004.

Thread Status:
Not open for further replies.
  1. Ryan32

    Ryan32 Registered Member

    Joined:
    Jun 15, 2004
    Posts:
    4
    My roomates downloaded a bunch of stuff, and now my computer is worthless! :mad:

    First off, my computer now shuts off and restarts at random. Also, i can't load Internet Explorer without it going to: c:\winnt\secure.html then it shoots up more pop up porn sites.

    Also, an Active Desktop keeps coming active on my desktop with a giant ad for my background. Here is my HijackThis! record, i tried removing stuff but it all comes back. Also, I've run AdAware and it didn't help either, everything comes back.... Please help as i no longer have my Win2k disc, and i have no way of getting my OS back if i reformat, and plus i have a ton of pictures and stuff i don't wanna lose. :'( Any help would be greatly appreciated.

    Oh and now my computer randomly locks up completely too. System idle starts using up 100% resources. I'll see if i can even get my HijackThis report.
     
  2. Ryan32

    Ryan32 Registered Member

    Joined:
    Jun 15, 2004
    Posts:
    4
    Logfile of HijackThis v1.97.7
    Scan saved at 2:32:59 PM, on 6/15/2004
    Platform: Windows 2000 SP3 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP3 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\runservice.exe
    C:\WINNT\System32\nvsvc32.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Steam\Steam.exe
    C:\WINNT\explorer.exe
    C:\Documents and Settings\Ryan\My Documents\torrent\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINNT\secure.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINNT\secure.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINNT\secure.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINNT\secure.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\secure.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\secure.html
    O1 - Hosts file is located at: C:\WINNT\nsdb\hosts
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup"
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe " -silent
    O4 - HKCU\..\Run: [WNSC] C:\WINNT\System32\wnsintsv.exe
    O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://cashsearch.biz/legal/x.chm::/load.exe
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
     
  3. Ryan32

    Ryan32 Registered Member

    Joined:
    Jun 15, 2004
    Posts:
    4
    Anybody know how to remove this stuff?
     
  4. Ryan32

    Ryan32 Registered Member

    Joined:
    Jun 15, 2004
    Posts:
    4
    wow thanks for all the help guys..... :rolleyes:
     
Thread Status:
Not open for further replies.