Please can anyone help?

Discussion in 'General Topics' started by jake2, May 21, 2004.

Thread Status:
Not open for further replies.
  1. jake2

    jake2 Guest

    Please can anyone help me with this hot kiss dialer?
    I have used the latest ad-aware, and cw shredder, but every time i log on, it cimes back...
    Im not too advanced with computers, so easy instructions would be apreciated.
    Also, I keep getting a google pop up, ........nay ideas ?

    Many thanx...:)
     
  2. TheQuest

    TheQuest Registered Member

    Joined:
    Jun 9, 2003
    Posts:
    2,301
    Location:
    Kent. UK by the sea
    Hi, jake2


    Try over here:- Browser Hijacks and Spyware Problems

    TheQuest :cool:
     
  3. lonewolf3367

    lonewolf3367 Guest

    Have you tried Spybot? Another free scanner( but it won't automatically remove anything) Is Bazooka adware & spyware scanner. Also you could try the trial of Spysweeper- it will remove alot of junk and it's free. If none of these work you could post a Hijackthis log in the hijack removal forum. Good luck.
     
  4. jake2

    jake2 Guest

    where do i get hijackthis??
    Thanx:)
     
  5. lonewolf3367

    lonewolf3367 Guest

  6. Nick

    Nick Registered Member

    Joined:
    May 14, 2002
    Posts:
    187
    Location:
    California
  7. lonewolf3367

    lonewolf3367 Guest

    Sorry about that first link not working. I can't make corrections to it if i'm not logged in.
     
  8. jake2

    jake2 Guest

    Logfile of HijackThis v1.97.7
    Scan saved at 03:57:02, on 22/05/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.00 (5.00.2614.3500)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\SA3DSRV.EXE
    C:\WINDOWS\CPQDIAG\CPQDFWAG.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\MOUSE\SYSTEM\EM_EXEC.EXE
    C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
    C:\COMPAQ\INTERNET\CISRVR.EXE
    C:\CPQS\BWTOOLS\SCCENTER.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\SYSTEM\PRINTRAY.EXE
    C:\WINDOWS\SYSTEM\CIJ3P2PS.EXE
    C:\PROGRAM FILES\PRIMAX\POWERTWAIN\PMXDETECT.EXE
    C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\LAUNCHER.EXE
    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\WINDOWS\DAEMON.EXE
    C:\WINDOWS\SYSTEM\SYSTEM.EXE
    C:\WINDOWS\SYSTEM\WINLOGON.EXE
    C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\BTOPENWORLD\DIALBTISURFTIME.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\CPQS\BACKWEB\PROGRAM\BACKWEB.EXE
    C:\UNZIPPED\HIJACKTHIS[1]\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=2c99&lc=0809&s=search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=2c99&lc=0809&s=search
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=2c99&lc=0809&s=search
    O1 - Hosts: 66.250.170.70 verisign.com
    O1 - Hosts: 66.250.170.70 www.altavista.com
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
    O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
    O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
    O4 - HKLM\..\Run: [Aureal A3D Interactive Audio Init] A3dInit.exe
    O4 - HKLM\..\Run: [Compaq Internet Setup] C:\Compaq\Internet\InetWizard.exe /RUN
    O4 - HKLM\..\Run: [CISrvr Program] C:\COMPAQ\INTERNET\CISRVR.EXE
    O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [CompaqPrinTray] PrinTray.exe
    O4 - HKLM\..\Run: [CIJ3P2PSERVER] CIJ3P2PS.EXE
    O4 - HKLM\..\Run: [Scan Detector] C:\PROGRA~1\PRIMAX\POWERT~1\Pmxdetect.exe
    O4 - HKLM\..\Run: [PrimaLauncher] C:\WINDOWS\SYSTEM\Launcher.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [Update] C:\WINDOWS\svchost.exe /i
    O4 - HKLM\..\Run: [browser] C:\WINDOWS\daemon.exe /i MSNJU1
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] c:\windows\SYSTEM\mstask.exe
    O4 - HKLM\..\RunServices: [HC Reminder] hc.exe
    O4 - HKLM\..\RunServices: [Aureal A3D Interactive Audio] sa3dsrv.exe
    O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\cpqdiag\CpqDfwAg.exe
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKCU\..\Run: [System Update] C:\WINDOWS\System\system.exe
    O4 - HKCU\..\Run: [System Update4] c:\windows\system\winlogon.exe
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O14 - IERESET.INF: START_PAGE_URL=http://bt.yahoo.com
    O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - https://register.btinternet.com/templates/btwebcontrol014.cab
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab



    dont really know what im doing, so, here is a log, any more help is much appreciated:)
     
  9. TheQuest

    TheQuest Registered Member

    Joined:
    Jun 9, 2003
    Posts:
    2,301
    Location:
    Kent. UK by the sea
    Hi, jake2
    Sorry not to clear, Hit the Link and then the bottom link in Image.
    TheQuest :cool:
     

    Attached Files:

  10. jake2

    jake2 Guest

    please can u explain things in brain dead terms, im new to pc and dont know much, but this site has helped me b 4 !

    Thanx
     
  11. lonewolf3367

    lonewolf3367 Guest

    I'd just like to add that all Hijackthis logs are supposed to be posted in the Adware, Spyware, and Hijack cleaning forum only. But i'm sure one of the experts here will move it for you shortly.
     
  12. snapdragin

    snapdragin Administrator

    Joined:
    Feb 16, 2002
    Posts:
    8,415
    Location:
    Southern Ont., Canada
    Hi Jake2

    Posting your hijackthis log in this forum (the one you are in now is called General Topics) will not be responded to. The General Topics forum is for board-related issues only.

    You need to post your hijackthis log over in our Adware/Spyware/Hijack cleaning forum. But before you can do that you must be a Registered Member as only Registered Members can post in that forum.

    Please see the Posting Policy here: https://www.wilderssecurity.com/showthread.php?t=31835

    Once you have Registered, then go to the link that Nick posted to you and follow all the Steps there.

    Then post your hijackthis log in the appropriate forum.

    Regards,

    snap
     
  13. jake2

    jake2 Guest

    Sorry, but im just after help to get rid of this, i dont know what im doing half the time, but have had good help in the past from this site.

    :)
     
  14. dog

    dog Guest

    Hi Jake2, :D

    You now have to register as a member at Wilders' to receive HJT help ... it's free to register ... once your logged in ... repost your HJT log in this FORUM make sure that you start a new thread ... "new thread" button is located in the upper right

    dog - *puppy*
     
  15. TheQuest

    TheQuest Registered Member

    Joined:
    Jun 9, 2003
    Posts:
    2,301
    Location:
    Kent. UK by the sea
    Hi, jake2

    Sorry see you were not there yet.

    You should, not worry ARE your in Good Hand when you get there.

    TheQuest :cool:
     
    Last edited: May 21, 2004
  16. twiztedmatt1007

    twiztedmatt1007 Registered Member

    Joined:
    May 21, 2004
    Posts:
    4
    Location:
    Las Vegas, Nevada
  17. snapdragin

    snapdragin Administrator

    Joined:
    Feb 16, 2002
    Posts:
    8,415
    Location:
    Southern Ont., Canada
    Since this is a board issue related forum, and the original poster of this thread has been given great help and advise from the members here on how to post his hijackthis log and where, I will lock this thread now. ;)

    Thank you everyone for your help.

    Regards,

    snap
     
Thread Status:
Not open for further replies.