Question:
pop ups and slow internet :( please help (hijack log is posted)?
2010-01-30 14:23:12 UTC
I've deleted things from this log that I know aren't viruses or harmful (yahoo stuff and apple itunes stuff)



Logfile of Trend Micro HijackThis v2.0.3 (BETA)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe


R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://mail.yahoo.com/?.redir=ymmapi9&.clntymver=2004.6.13.1&.cldefstat=Def2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe lfrt.njo gxsgk
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\strCodec\isaddon.dll (file missing)
O2 - BHO: TBSB02751 - {25875464-7327-417C-8264-902D99CF6FD1} - C:\Program Files\Search Enhancer Toolbar\tbu07722\enhancer.dll (file missing)
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Protection Bar - {479fd0cf-5be9-4c63-8cda-b6d371c67bd5} - C:\Program Files\strCodec\iesplugin.dll (file missing)
O3 - Toolbar: Search Enhancer Toolbar - {BFB5F154-9212-46F3-B547-AC6106030A54} - C:\Program Files\Search Enhancer Toolbar\tbu07722\enhancer.dll (file missing)
O4 - HKLM\..\Run: [bomuwonaw] Rundll32.exe "c:\windows\system32\dagimewo.dll",a
O4 - HKLM\..\Run: [Htotucobu] rundll32.exe "C:\WINDOWS\uyodunuj.dll",Startup
O4 - HKLM\..\Policies\Explorer\Run: [pmsngr.exe] C:\Program Files\strCodec\pmsngr.exe
O4 - HKLM\..\Policies\Explorer\Run: [Network Sub Spooler] C:\WINDOWS\system32\oobe\SERVICES.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\mshta.dll c:\windows\system32\palodide.dll zodabuma.dll C:\WINDOWS\system32\guard32.dll c:\windows\system32\dagimewo.dll c:\windows\system32\zudalure.dll c:\windows\system32\bulisazu.dll
O20 - Winlogon Notify: bidmon - bidmon.dll (file missing)
O21 - SSODL: pofepavoz - {92b3ad14-0c43-4800-921f-ecc7275e5078} - c:\windows\system32\palodide.dll (file missing)
O21 - SSODL: rozofagus - {738d6079-6c7e-46e5-922d-e5b3215ba385} - c:\windows\system32\zudalure.dll
O21 - SSODL: tilubahiz - {05327ae7-2d41-4fe1-8862-33df2de4951f} - c:\windows\system32\bulisazu.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: jugezatag - {92b3ad14-0c43-4800-921f-ecc7275e5078} - c:\windows\system32\palodide.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {738d6079-6c7e-46e5-922d-e5b3215ba385} - c:\windows\system32\zudalure.dll
O22 - SharedTaskScheduler: gahurihor - {05327ae7-2d41-4fe1-8862-33df2de4951f} - c:\windows\system32\bulisazu.dll
O23 - Service: AntipyProex (AntipPro2009_100) - Unknown owner - C:\WINDOWS\svchast.exe (file missing)
Three answers:
?
2010-02-03 09:58:54 UTC
Hijack is a trojan horse.

In order to remove the it, you should download, install, and update the best antispyware.

this software can delete it.

http://trojan-horses-remover.com
2010-01-30 14:33:22 UTC
Don't post it here. You need people who are properly trained since there are lots of wrong information on the net. Go to any of the forums (only one forum though - you can't post it to more than one otherwise you can get conflicting advices)



Go to bleepingcomputer



http://www.bleepingcomputer.com/forums/topic34773.html
Tech Forumz
2010-01-30 14:52:06 UTC
If you join www.techforumz.net and post the log there i will have your computer analyzed 15mins after you post


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...