PDA

View Full Version : Strange behaviors Please help!



masi10
2009-01-18, 22:17
Here is my HJT Log please help. Thanks:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:11:37 PM, on 1/18/2009
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe
C:\DOCUME~1\Sean\LOCALS~1\Temp\winhhemdf.exe
C:\DOCUME~1\Sean\LOCALS~1\Temp\winltlhv.exe
C:\DOCUME~1\Sean\LOCALS~1\Temp\winfbcp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: UrlHelper Class - {6D023EBF-70B8-45A6-9ED5-556515FA0FE4} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: BearSharePersonalization - {DD1849EA-8403-4441-8DFF-7575AAE1DC16} - C:\Program Files\BearShare Applications\Personalization\BearSharePersonalizationIE_v1047.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BSMediaBar.dll
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

--
End of file - 2314 bytes

pskelley
2009-01-23, 13:35
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance) http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.


Please take the time to read the directions:
http://forums.spybot.info/showpost.php?p=25290&postcount=4

Thanks

masi10
2009-01-23, 16:02
ok. I have read it. Then I posted. Are you implying that I have not followed the directions properly? If I posted or did something wrong it would be helpful to let me know because I promise it wasn't on purpose.

pskelley
2009-01-23, 16:29
Listen up, I am not implying a thing, I am telling you these are the directions and you need to click the link and read them:
http://forums.spybot.info/showpost.php?p=25290&postcount=4

Because of this, we changed our malware forum's policy on the use of P2P file sharing programs.
C:\Program Files\BearShare

If your Operating System is XP without a Service Pack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:11:37 PM, on 1/18/2009
Platform: Windows XP(NO SERVICE PACK)(WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

masi10
2009-01-23, 16:43
I GOT IT!! Clearly people like myself are visiting these sites for help,otherwise they would fix their own problems. Clearly, it was a simple mistake on my part. I will make the corrections and repost a HJT log report. I hope your future posts won't be as rude as your last.

pskelley
2009-01-23, 16:47
I have done nothing but try to give you the information you need. Considering that you think that is being rude, I would prefer you get help from someone else.

Thanks