How to block website?

Status
Not open for further replies.
Originally Posted By: OVERK1LL
It really sounds like you have some sort of redirect hijack in place. Can you download and run Hijackthis and then post the log here?


+1
 
Thanks again for the help here. I checked on HIjackthis, and to be honest I do not want to download it. If I make the wrong move with that program I will do a lot more harm than good. I downloaded MSE and also the MSE Malicious Software Removal Tool. I just finished a quick scan with MSE, it came back with nothing found. I just started a complete scan with the MSE Malicious Software Removal Tool. It takes a while so I will hit the hay and check my computer tomorrow morning.

Before this happened I used Avast anitivirus and Malwarebytes. My computer was slow sometimes, and when it would slow down was when the Avast orange ball in my tool bar was spinning around. Seems like Avast was checking the web page every time I navigated from one page or web site to another. Microsoft says to uninstall any other AV or spyware tools before downloading or running MSE. So I removed Avast and also removed the SAS anti spyware tool. I don't know if I should reinstall them, I have read that having too many AV programs on one computer will cause conflicts. I don't know which is better, MSE or Avast but my computer seems to be running faster without Avast and SAS, even with a complete scan running at the same time.

I am going to let this MS malicious software remover run overnight, it says it can take a few hours for a complete scan. I will check my computer and the Dodge Forum tomorrow and see what is going on then. It is too bad some idjit somewhere thinks it's funny to write programs that make people's computers have problems like this. I just hope that's all it is and there are no crooks out there with my personal info or bank card numbers. So far my bank account and credit cards are OK. I usually check my bank account status twice every day, but I still try my best to watch out for the thieves and scammers on the Internet. Seems like the bad guys are smarter than I will ever be.

There are way too many crooks, smart-aleck punks, idiots and sleazy thieves out there. I will post back again tomorrow. If I have to I will do the Hijackthis scan if I absolutely have to. If there is anything else I need to know about hijackthis please let me know. Thanks for all your help.
 
I wonder about Avast anitivirus and Malwarebytes. To me they seemed to work OK, but I would not know the difference between a good and bad AV or malware tool. Now that I look at it, I remember I have the same little green MSE icon in my work computer's task bar. If MSE is good enough for the State of Florida then it must be good enough for me to use it at home. I will have to se if I can find out what AV program is on my work computer. I beleive there is a separate AV program on it so I guess I should run one on my own computer too. If you guys know of a better free AV than Avast, or whether MSE will work well enough by itself, I am all ears. And should I uninstall Malwarebytes too if I keep the MSE and MS malicious software removal tool?

Thanks for all your help.
 
Hijackthis doesn't damage anything unless you tell it to
grin.gif


I don't want you to add/remove any entries at this point with it. Just run it to create a log, then paste that log here.
 
Originally Posted By: OVERK1LL
Hijackthis doesn't damage anything unless you tell it to
grin.gif


I don't want you to add/remove any entries at this point with it. Just run it to create a log, then paste that log here.


Thanks for the help. Here it is:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:20:37 AM, on 9/9/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1288411228531
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsof...b?1288411273078
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7851 bytes
 
Thanks for taking time to help me on this. I did a Sophos scan, it found 5 hidden/unknown files. Here are the details from the scan:

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\KX7WBLDU\ljc0xpbmtCb3hBbGwEcG9zAzExMgRzZWMDTWVkaWFMaW5rYm94;_ylg=X3oDMTFwNjNlNDc4BGludGwDdXMEbGFuZwNlbi11cwRwc3RhaWQDBHBzdGNhdAMEcHQDY29taWMtZ2FsbGVyeQR0ZXN0Aw--;_ylv=3[1].htm
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\3TMITCN1\n65VRB0uOUX1MynVO6R9DGQ1DAOJAe35pldQ8gHLSLH9GnQXh7ZUrCX-H1QPQp5_m4ym_s0_0wZI1tTYPpc7kWK2inTlW7ODLffC4GvmmlcdsSfiZIYLppi6CQTC-E-r_QxM9HV0RkWrx5KMn5j_adXVgBfdklw[1].gif
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\V6V2J7ZX\8adbe4e0b5;ord=17KH2F3HYN6KDQ3VQ9ST;s=i0;s=i1;s=i2;s=i3;s=i4;s=i6;s=i7;s=i8;s=i9;s=1009;s=1132;s=32;s=1089;s=u5;s=m4;s=u15;s=m1;s=u9;s=u7;z=627;z=633;s=1290;tile=1[1]
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\System Volume Information\_restore{08152AC4-F3E9-4014-AA61-A9F6EDE2950D}\RP187\A0036228.rbf
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

Area: Local hard drives
Description: Unknown hidden file
Location: C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\3TMITCN1\TMAPdI5DrPI1RX-CXDPjHW9JJdV5zAYogbPueCoNeJapjbcf2l0zWJwnYhZOXlSBOIX2o30n2R6028TXUGc712Ykpn0iNcrk5X3Tobk9k4T0y4BtUb_bMTmTRgomGb5iOOespFymifQGO1ThXszmW1NJEaTxCYV[1].gif
Removable: Yes (but clean up not recommended for this file)
Notes: (no more detail available)

I appreciate any help you can offer on this. Thanks.
 
Thanks. Maybe I am just stuck with having the web cam site in my history list. It has to come from somewhere on the Dodge Forum site because it never shows up in my history until I visit the Dodge Forum, it happens on the first visit there each day. I correct the position of the forum page on my monitor and have no more problems with it until the next day. Then the next morning, same thing happens all over again. If there is no virus or malware coming from it I guess I will learn to live with it. In the history folder it has the name of the site and it says "live sexy girls - web cam pics". I would like to get rid of it completely and never see it again if possible.

Do you have any suggestions for my AV and Spyware programs now? Right now I only have MSE and the MS Malicious Software Removal tool. Would it be good to put Avast and the SuperAntiSpyware programs back on my computer or would that cause problems? Which is the better AV, Avast or MSE? My computer does seem to run faster with only the MSE, but is MSE a good enough AV just by itself?

Thanks for your help on this. I am not very tech-savvy with computers, I only know just enough to be dangerous. I can use a computer fairly well but I know nothing about the innards of one. I do appreciate your help.
 
I would highly recommend using ESET's NOD32 product. You don't need a "security suite", just their regular antivirus. It blocks access to malicious sites and cookies as well, so it may very well help you out here.
 
Thanks. I removed MSE and downloaded ESET. It seems to be a lot more thorough than Avast. I ran a scan with it and it came back with these 6 problems. Any idea if they are related to the web cam site problem? Thanks again for your help.

C:\Documents and Settings\User\Local Settings\Temp\40774359.Uninstall\Uninstall.exe a variant of Win32/InstallCore.A potentially unwanted application Clean

C:\Documents and Settings\User\Local Settings\Temp\ICReinstall\AudioConverterSetup[1].exe a variant of Win32/InstallCore.A potentially unwanted application Clean

C:\Documents and Settings\User\Local Settings\Temp\ish1401806143\defaultOffer\offer_code.txt Win32/Toolbar.Facemoods potentially unwanted application Clean

C:\Documents and Settings\User\Local Settings\Temp\ish1401806143\defaultOffer\offer_html.txt Win32/Toolbar.Facemoods potentially unwanted application Clean

C:\Documents and Settings\User\Local Settings\Temp\ish2028614834\defaultOffer\offer_code.txt Win32/Toolbar.Facemoods potentially unwanted application Clean

C:\Documents and Settings\User\Local Settings\Temp\ish2028614834\defaultOffer\offer_html.txt Win32/Toolbar.Facemoods potentially unwanted application Clean
 
So far I like the way the ESET antivirus program works. It doesn't slow down my computer like Avast did. Avast was good as far as I know, but it did make my system run slow at times. At least that is what I think it did. I reinstalled Super AntiSpyware and did a complete scan tonight. So far so good, but I will have to continue monitoring my system and see if I get the web cam site back in my history again. I like being able to do a scan with SAS every day, it seems to work well. Thanks for helping me with this. I do not know much about computers and I appreciate the help. I have learned a little more about my computer from this web cam site problem.
 
We have a site license for NOD32 at work, I'm quite fond of it. And my experience with it echoes yours: It is very lightweight and doesn't slow down the system.
 
This new AV progam works great, but the web cam site is back in my history again today. When I started my computer and went online today I purposely went on sites other than the Dodge Forum, BITOG, Yahoo, my bank's website, one or two others. After I went on each one I checked my browser history, and there was no sign of the web cam site. Then I went to the Dodge Forum, the home page was skewed to the right side of the screen again. I read a post there and when I clicked my back button I again got the warning window about being redirected to another site, do I wish to continue? I clicked No and it went back to the DF home page. Then I checked my browsing history, sure enough there was the web cam site in my browsing history again. I have absolutely no interest in porno, I do not want to see porno and I do not want this junk on my computer. I know the web cam site thing comes from somewhere on the DF site and I am going to email an admin or some other mods there and get it straightened out. Norton Safe Web says the DF site is OK, so there has to be some way to fix this problem.
 
A couple more things:

1. As others have suggested, try using Chrome or Firefox
2. Change your DNS servers manually to the OpenDNS ones: 208.67.222.222 and 208.67.220.220
 
I suggest using Chrome or Firefox as well. I also suggest that you change your DNS to OpenDNS. Once you do that, you can sign up for a free account and block any site/domain you want to with it. It works great. You can find more information here - http://www.opendns.com/home
 
Status
Not open for further replies.
Back
Top Bottom