hey
ok i registered now and i also have downloaded the program you told me to (microsoft anti spyware beta) here is a new high jack this log
Logfile of HijackThis v1.98.2
Scan saved at 5:33:58 PM, on 4/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\wpwin9.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\My Room\My Documents\computer security\highjack this\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.ca/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.ca/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ww.searchforit.com
O1 - Hosts: 0.1 slotchbar.com
O1 - Hosts: 127.0..0.1 stx12.sextracker.com
O1 - Hosts: 127.0.stx14.sextracker.com
O1 - Hosts: ww.searchforit.com
O1 - Hosts: 0.1 slotchbar.com
O1 - Hosts: w.zsearchtoolbar.com
O1 - Hosts: 127.0.0.eroptimizer.com
O1 - Hosts: 127.0.0.mizer.com
O1 - Hosts: w.zsearchtoolbar.com
O1 - Hosts: 127.
O1 - Hosts: om
O1 - Hosts: om
O1 - Hosts: .com
O1 - Hosts: .com
O1 - Hosts: ay.com
O1 - Hosts: 127.0.w.xadso.offeroptimizer.com
O1 - Hosts: ay.com
O1 - Hosts: 127.0.0
O1 - Hosts: oday.com
O1 - Hosts: oday.com
O1 - Hosts: today.com
O1 - Hosts: today.com
O1 - Hosts: 127.0.0.
O1 - Hosts: com
O1 - Hosts: k-today.com
O1 - Hosts: com
O1 - Hosts: k-today.com
O1 - Hosts: 127
O1 - Hosts: ar.com
O1 - Hosts: .look-today.com
O1 - Hosts: ar.com
O1 - Hosts: .look-today.com
O1 - Hosts: 127
O1 - Hosts: olbar.com
O1 - Hosts: 127.find.com
O1 - Hosts: 127.om
O1 - Hosts: olbar.com
O1 - Hosts: 127.0
O1 - Hosts: htoolbar.com
O1 - Hosts: htoolbar.com
O1 - Hosts: earchtoolbar.com
O1 - Hosts: earchtoolbar.com
O1 - Hosts: 127.0.
O1 - Hosts: 127.0.0.
O1 - Hosts: m
O1 - Hosts: m
O1 - Hosts: com
O1 - Hosts: com
O1 - Hosts: 127.
O1 - Hosts: m
O1 - Hosts: u.com
O1 - Hosts: m
O1 - Hosts: u.com
O1 - Hosts: .com
O1 - Hosts: toyou.com
O1 - Hosts: .com
O1 - Hosts: toyou.com
O1 - Hosts: enu.com
O1 - Hosts: inkstoyou.com
O1 - Hosts: enu.com
O1 - Hosts: inkstoyou.com
O1 - Hosts: nc.whenu.com
O1 - Hosts: 127.0hinkingmedia.net
O1 - Hosts: 127.08.org
O1 - Hosts: nc.whenu.com
O1 - Hosts: 127.0.0.
O1 - Hosts: w.zinc.whenu.com
O1 - Hosts: w.zinc.whenu.com
O1 - Hosts: 127.
O1 - Hosts: er.com
O1 - Hosts: 127.0.ait.com
O1 - Hosts: 127.0.com
O1 - Hosts: om
O1 - Hosts: om
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - C:\WINDOWS\Fonts\kbvb.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [CheckMsgPlus] C:\WINDOWS\System32\Rundll32.exe C:\PROGRA~1\MESSEN~1\MsgPlusH.dll,VerifyInstallation
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Corel Registration.lnk = C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exeO16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cabO16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) -
http://www.live365.com/players/play365.cabO16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{30F00D34-C871-4704-AC44-F9ABCBB50576}: NameServer = 216.168.96.13 216.168.96.10
O17 - HKLM\System\CS1\Services\Tcpip\..\{30F00D34-C871-4704-AC44-F9ABCBB50576}: NameServer = 216.168.96.13 216.168.96.10
i have also been having a problem with my computer turning it self off. my dads girlfreind has this freind whos computer got high jacked and the guy sent rose something to this computer and many others. her freind had the same problem with her computer as i am having with mine. she told me the name of the virus that she had was backdoor.b.asl.dll would you please help me figure out how to fix my computer befor it just shuts off and doesnt turn back on (which happened to my brothers computer a while ago)