Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

securityiguard

Thread Tools
 
Search this Thread
 
Old 24th Feb 2005, 17:49
  #1 (permalink)  
Thread Starter
 
Join Date: Jan 2002
Location: UAE
Age: 44
Posts: 465
Likes: 0
Received 0 Likes on 0 Posts
Angry securityiguard

hi guys!

having some major problems with some ad/spyware to the point that my comp may reach terminal velocity out the window and putting files onto cd to wipe hard drive but still got 20GB to go!!!!

The main culprits are;

securityiguard
www56.com
system update - system soap??
"you have spam in your email"
"computer running slow? you have adware!"

I run CWshredder, highjack this, search and destroy and adware se every time i run my comp and these are all updated but it dosent shift any of them!

Here is a copy of the hijack this log!

*******! it just happened again!

can anyone help?

ok, it wont allow me to post it!!

when i try to post the log it syas i have too many images in my signature!!!???
Kempus is offline  
Old 24th Feb 2005, 20:00
  #2 (permalink)  

'nough said
 
Join Date: Sep 2002
Location: Raynes Park
Age: 58
Posts: 1,025
Likes: 0
Received 0 Likes on 0 Posts
You need to tick "disable smilies in this post" when posting HJT logs.

Charles
amanoffewwords is offline  
Old 24th Feb 2005, 22:27
  #3 (permalink)  
Thread Starter
 
Join Date: Jan 2002
Location: UAE
Age: 44
Posts: 465
Likes: 0
Received 0 Likes on 0 Posts
cheers!

here we go!


Logfile of HijackThis v1.98.2
Scan saved at 18:28:40, on 24/02/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\ATI-CPanel\atiptaxx.exe
C:\NORMAN\Nvc\BIN\ZLH.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\NORMAN\Nvc\BIN\NYMSE.EXE
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\NORMAN\Nvc\BIN\nvcoas.exe
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\NORMAN\Nvc\BIN\NJEEVES.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\NORMAN\Nvc\BIN\cclaw.exe
C:\DOCUME~1\STUKEM~1\LOCALS~1\Temp\~e5d141.tmp
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\stu kemp\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\STUKEM~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.hta
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RealAudio.exe
Kempus is offline  
Old 24th Feb 2005, 23:30
  #4 (permalink)  

'nough said
 
Join Date: Sep 2002
Location: Raynes Park
Age: 58
Posts: 1,025
Likes: 0
Received 0 Likes on 0 Posts
amanoffewwords is offline  
Old 25th Feb 2005, 11:29
  #5 (permalink)  
Chief Tardis Technician
 
Join Date: Jan 2001
Location: Western Australia S31.715 E115.737
Age: 71
Posts: 554
Likes: 0
Received 0 Likes on 0 Posts
Kempus,

There doesnt appear to be much wrong with the log, apart from geing a bit short. They are usualy a lot longer than that.

Try going to GRC.com , download and run a prog called :- Shoot the messenger.

This will stop msmessager from running and prevent most of these popups. Do not confuse this with MSn Messenger, its a totaly different thing and wont be affected. There is information on GRC.com on this subject.

Goodluck
Avtrician is offline  
Old 25th Feb 2005, 13:41
  #6 (permalink)  
Thread Starter
 
Join Date: Jan 2002
Location: UAE
Age: 44
Posts: 465
Likes: 0
Received 0 Likes on 0 Posts
hey,

tried that! still no joy! how do you know if your HD is partitioned to re install windows as i'm gonna cry!!!

kempus
Kempus is offline  
Old 26th Feb 2005, 08:21
  #7 (permalink)  
 
Join Date: Apr 2004
Location: North of Watford
Posts: 196
Likes: 0
Received 0 Likes on 0 Posts
I notice that you ran an older version of HJT!. Download the latest one and give it another go please.

How many drive letters do you have? if just the one for the hard disk, then you don't have it partitioned - unless it's from Dell or similar company, in which case it's likely to have a hidden partition.

ST
SoftTop is offline  
Old 3rd Mar 2005, 09:34
  #8 (permalink)  
Thread Starter
 
Join Date: Jan 2002
Location: UAE
Age: 44
Posts: 465
Likes: 0
Received 0 Likes on 0 Posts
Hi!

Thanks for your reply guys but i'm still having no luck. Here is the log before anything is done and any of ther other spy/adwere programs are run.

I only have 1 hard drive on my comp and not sure where windows is to re install it!!

the log:

Logfile of HijackThis v1.99.1
Scan saved at 10:06:09, on 03/03/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\ATI-CPanel\atiptaxx.exe
C:\NORMAN\Nvc\BIN\ZLH.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\NORMAN\Nvc\BIN\nvcoas.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\System32\mshta.exe
C:\NORMAN\Nvc\BIN\NYMSE.EXE
C:\NORMAN\Nvc\BIN\NJEEVES.EXE
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\NORMAN\Nvc\BIN\cclaw.exe
C:\WINDOWS\System32\mshta.exe
C:\Documents and Settings\stu kemp\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://0ml.net/cat
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://0ml.net/searchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://0ml.net/cat
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://0ml.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://0ml.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://0ml.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://0ml.net/searchasst.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://0ml.net/cat
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://0ml.net/cat
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://0ml.net/searchasst.html


any ideas?


kempus
Kempus is offline  
Old 3rd Mar 2005, 11:10
  #9 (permalink)  
Chief Tardis Technician
 
Join Date: Jan 2001
Location: Western Australia S31.715 E115.737
Age: 71
Posts: 554
Likes: 0
Received 0 Likes on 0 Posts
Kempus,
Your log is still a bit short I think.
At a guess , you need to check and fix all those R0, R1 entries. Thats what I would do on my beast .
Avtrician is offline  
Old 3rd Mar 2005, 19:51
  #10 (permalink)  
 
Join Date: Apr 2004
Location: North of Watford
Posts: 196
Likes: 0
Received 0 Likes on 0 Posts
I have to agree. Compared to virtually all the other HJT! logs this seems VERY short.

Kempus, does the log that you've posted here match the one in the HJT! window when you run it?

You could also try downloading another browser (Firefox or Opera) and see if the problem persists with them. I'm assuming that you're having the problem in IE6.

One other thought - are you using the "innoculate" option with Spybot S&D?

ST
SoftTop is offline  
Old 5th Mar 2005, 12:31
  #11 (permalink)  
Thread Starter
 
Join Date: Jan 2002
Location: UAE
Age: 44
Posts: 465
Likes: 0
Received 0 Likes on 0 Posts
hi!

Thanks for all your help but found the system disk and wiped the lot to start again although it has wiped my anti virus thing i got with it. can anyone recomend the best free antvirus program?

kempus
Kempus is offline  
Old 5th Mar 2005, 20:53
  #12 (permalink)  
 
Join Date: Jul 2002
Location: Northampton UK
Posts: 537
Likes: 0
Received 0 Likes on 0 Posts
Opinions vary, but I have been very happy with AVG Free Edition in conjunction with a software firewall.

RC
rotorcraig is offline  
Old 6th Mar 2005, 11:39
  #13 (permalink)  
 
Join Date: Apr 2004
Location: North of Watford
Posts: 196
Likes: 0
Received 0 Likes on 0 Posts
Kempus,

glad you've resolved the problem - albeit with the "sledgehammer to crack a nut" route - respect!

I've been hanging back for about 8 or 9 months now from doing just that here because of niggly problems on this PC. I've got five user accounts on it and I'm bottling out from the re-install route in case I lose all the user data. That's even after I've done all the sensible stuff like backing it all up. What a wimp eh?

Hope that the future's problem free now.

Regards

ST
SoftTop is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.