hello im new to the site and it appears others have had help from you attached is my hijackthis log please help me. my explorer directs me to different places other than my intended search and dumps me out of explorer if i try to back out . here is my log.
Looks like you definitely have a few baddies!FIRST:
Look in Add /Remove Programs and UNINSTALL the following:
ArcadeRockstar
Viewpoint
NOW:
Please EXTRACT HijackThis from the ZIP to a safe location. Most Forum volunteers expect to find it at C:\Program Files\HijackThis or C:\HijackThis.
Then – RENAME HijackThis.exe to hjtscanner.exe
If you are unable to move or Rename HJT on your own, please do the following:
-- Delete your current copy of HJT.
-- Please download HijackThis Self-X to your Desktop.
-- DoubleClick on it to run it and follow the prompts.
-- A Shortcut for HJT will be created on your Desktop. Just leave it for now.
NOW, on to the fix:
-- Please make sure the Viewing of Hidden Files is Enabled .
You may want to print these instructions or save them locally, since you will have to restart your computer during the fix. Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe
Save it to your desktop and run it.
Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
When your system reboots, follow the prompts.
Afterwards, HijackThis will launch (If Hijackthis does not launch then please start it yourself).
Please Scan with HJT, and check the boxes for the following items, if they remain:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
O2 - BHO: ArsPlugin Class - {DABE0C57-5B57-4E2D-837A-08F290F7458E} - C:\Program Files\ArcadeRockstar\arsplg.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - (no file)
O4 - HKLM\..\Run: [EzQwN] C:\WINDOWS\xjpx.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [mpcsr] C:\WINDOWS\system32\mpcsr.exe
O4 - HKLM\..\Run: [arcaderockstar] C:\Program Files\ArcadeRockstar\arcaderockstar32.exe
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.5.107.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{53457BCE-6CAA-4E7C-B72D-69754368FB1C}: NameServer = 85.255.113.198,85.255.112.138
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD09042B-F47E-4B02-B058-C736DC09479B}: NameServer = 85.255.113.198,85.255.112.138
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.198 85.255.112.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.198 85.255.112.138
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Be sure All Browser Windows are Closed and then Click Fix Checked.
NEXT:
Please Boot to Safe Mode .
Use Windows Explorer to navigate to and DELETE these, if they remain.
Remember to ENABLE the Viewing of Hidden Files as I mentioned before....
C:\WINDOWS\xjpx.exe
C:\WINDOWS\system32\mpcsr.exe
C:\Program Files\ArcadeRockstar
C:\Program Files\Viewpoint
THEN:
Click Start > Run > type CMD > Enter
Type or Copy&Paste: ipconfig /flushdns > Press Enter
(Be sure to leave the space between the g and the / )
NEXT:
Download ATF-Cleaner.exe by Atribune to your Desktop.
-- Click on ATF-Cleaner to run it
-- Where it says Select Files To Delete, Check the Select All Option (if you don’t want it to clean cookies, set it accordingly)
-- Click Empty Selected > OK > EXIT
This will flush TEMP files, etc... as well as clean the Java Cache.
NOW:
Please download and Install AVG Anti-Spyware v7.5
NEXT:
RightClick the AVG Anti-Spy Icon in your system tray and do the following:
-- Uncheck Resident Shield
-- Uncheck Automatic Updates
-- Uncheck Start with Windows
* You can reset the above to their defaults AFTER your machine has been deemed “clean,” if you so desire. For now, we need them disabled.
Click Run online update and allow it to run until you see the Update Successful message. If you are unable to do this, please let me know.
Then, run a full scan:
-- Click on the Scanner button and choose the Settings Tab.
---> Under How to act?, click on Recommended action and choose Quarantine to set default action for detected malware.
--->Under Reports make sure Automatically generate report after every scan is selected and UNCHECK the Only if threats were found box.
-- Leave everything else at their default settings and Select the Scan tab and CLICK Complete System Scan to scan your machine.
-- Upon completion of the scan, Click Apply all actions to place any detected baddies in Quarantine.
-- AFTER clicking Apply all actions, Click on Save Report and select Save the report to your Desktop where you can find it easily. Again, be sure to Apply All Actions Before saving the Log!
LASTLY: Please locate c:\fixwareout\report.txt and post it here along with Fresh HijackThis Scanlog and the AVG Anti-Spyware Log and we'll go from there.
Let me know if you had any problems with the above and how things are running now.
Best Luck :)
PP