PDA

View Full Version : securityiguard


Kempus
24th Feb 2005, 17:49
hi guys!

having some major problems with some ad/spyware to the point that my comp may reach terminal velocity out the window and putting files onto cd to wipe hard drive but still got 20GB to go!!!!

The main culprits are;

securityiguard
www56.com
system update - system soap??
"you have spam in your email"
"computer running slow? you have adware!"

I run CWshredder, highjack this, search and destroy and adware se every time i run my comp and these are all updated but it dosent shift any of them!

Here is a copy of the hijack this log!

*******! it just happened again!

can anyone help?

ok, it wont allow me to post it!!

when i try to post the log it syas i have too many images in my signature!!!???

amanoffewwords
24th Feb 2005, 20:00
You need to tick "disable smilies in this post" when posting HJT logs.

Charles

Kempus
24th Feb 2005, 22:27
cheers!

here we go!


Logfile of HijackThis v1.98.2
Scan saved at 18:28:40, on 24/02/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\ATI-CPanel\atiptaxx.exe
C:\NORMAN\Nvc\BIN\ZLH.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\NORMAN\Nvc\BIN\NYMSE.EXE
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\NORMAN\Nvc\BIN\nvcoas.exe
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\NORMAN\Nvc\BIN\NJEEVES.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\NORMAN\Nvc\BIN\cclaw.exe
C:\DOCUME~1\STUKEM~1\LOCALS~1\Temp\~e5d141.tmp
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\stu kemp\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\STUKEM~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.hta
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RealAudio.exe

amanoffewwords
24th Feb 2005, 23:30
http://www.ptalink.net/eliam.gif

Avtrician
25th Feb 2005, 11:29
Kempus,

There doesnt appear to be much wrong with the log, apart from geing a bit short. They are usualy a lot longer than that.

Try going to GRC.com , download and run a prog called :- Shoot the messenger.

This will stop msmessager from running and prevent most of these popups. Do not confuse this with MSn Messenger, its a totaly different thing and wont be affected. There is information on GRC.com on this subject.

Goodluck:ok:

Kempus
25th Feb 2005, 13:41
hey,

tried that! still no joy! how do you know if your HD is partitioned to re install windows as i'm gonna cry!!!

kempus

SoftTop
26th Feb 2005, 08:21
I notice that you ran an older version of HJT!. Download the latest one and give it another go please.

How many drive letters do you have? if just the one for the hard disk, then you don't have it partitioned - unless it's from Dell or similar company, in which case it's likely to have a hidden partition.

ST

Kempus
3rd Mar 2005, 09:34
Hi!

Thanks for your reply guys but i'm still having no luck. Here is the log before anything is done and any of ther other spy/adwere programs are run.

I only have 1 hard drive on my comp and not sure where windows is to re install it!!

the log:

Logfile of HijackThis v1.99.1
Scan saved at 10:06:09, on 03/03/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\ATI-CPanel\atiptaxx.exe
C:\NORMAN\Nvc\BIN\ZLH.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\NORMAN\Nvc\BIN\nvcoas.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\System32\mshta.exe
C:\NORMAN\Nvc\BIN\NYMSE.EXE
C:\NORMAN\Nvc\BIN\NJEEVES.EXE
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\NORMAN\Nvc\BIN\cclaw.exe
C:\WINDOWS\System32\mshta.exe
C:\Documents and Settings\stu kemp\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://0ml.net/cat
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://0ml.net/searchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://0ml.net/cat
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://0ml.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://0ml.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://0ml.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://0ml.net/searchasst.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://0ml.net/cat
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://0ml.net/cat
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://0ml.net/searchasst.html


any ideas?


kempus

Avtrician
3rd Mar 2005, 11:10
Kempus,
Your log is still a bit short I think.
At a guess , you need to check and fix all those R0, R1 entries. Thats what I would do on my beast .

SoftTop
3rd Mar 2005, 19:51
I have to agree. Compared to virtually all the other HJT! logs this seems VERY short.

Kempus, does the log that you've posted here match the one in the HJT! window when you run it?

You could also try downloading another browser (Firefox or Opera) and see if the problem persists with them. I'm assuming that you're having the problem in IE6.

One other thought - are you using the "innoculate" option with Spybot S&D?

ST

Kempus
5th Mar 2005, 12:31
hi!

Thanks for all your help but found the system disk and wiped the lot to start again although it has wiped my anti virus thing i got with it. can anyone recomend the best free antvirus program?

kempus

rotorcraig
5th Mar 2005, 20:53
Opinions vary, but I have been very happy with AVG Free Edition (http://www.grisoft.com/us/us_dwnl_free.php) in conjunction with a software firewall.

RC

SoftTop
6th Mar 2005, 11:39
Kempus,

glad you've resolved the problem - albeit with the "sledgehammer to crack a nut" route - respect!

I've been hanging back for about 8 or 9 months now from doing just that here because of niggly problems on this PC. I've got five user accounts on it and I'm bottling out from the re-install route in case I lose all the user data. That's even after I've done all the sensible stuff like backing it all up. What a wimp eh?

Hope that the future's problem free now.

Regards

ST