It is currently Tue Sep 01, 2026 1:34 pm


spyware and virus problem

Support for any program including installing and running

Moderator: liljim

spyware and virus problem

Postby leeegglestone » Sun Aug 13, 2006 11:25 pm

spyware
I have some spyway that started to download. it was for some casino or something.

anyway it took over my Wallpaper, with this message about buying something for spyware.

Each time I run ad-aware and spybot, they both just freeze and dont get me to the stage of removing any critters that are in my system

What can I do?

Also my virus scanner picks some up, trojan. However when it finds them, this also stops and doesnt do anything else.
Windows has been downloading updates, so these mightactually be being tracked as viruses, not sure.
User avatar
leeegglestone
Geek
Geek
 
Posts: 65
Joined: Thu Nov 20, 2003 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Dave_Lethal » Sun Aug 13, 2006 11:33 pm

To get rid of the desktop, go to your display properties. Click on the Desktop tab, then click Customize Destop. Click the Web tab, and uncheck every box in there, and click Apply and Ok.

I highly suggest downloading HijackThis, you can find a link at the top left of the home page here, and run a scan and post the log back here for someone to look at.
User avatar
Dave_Lethal
Executive Geek
Executive Geek
 
Posts: 648
Joined: Sat Jun 05, 2004 1:00 am
Location: Chicago, IL
Operating System:

Thanks given:0
Thanks received:0
Top

Postby leeegglestone » Sun Aug 13, 2006 11:35 pm

Logfile of HijackThis v1.99.1
Scan saved at 11:35:06 PM, on 8/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\gsicon.exe
C:\WINDOWS\system32\dslagent.exe
C:\Program Files\VoyagerTest\fts.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\aoltpspd.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CCleaner\ccleaner.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Lee\LOCALS~1\Temp\Rar$EX00.750\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{21FB6AF6-9051-40BB-BB21-E5A3F50BB763}: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CCS\Services\Tcpip\..\{532DAD06-9FC1-4F68-BEA7-29CCE4ECFDDD}: NameServer = 205.188.146.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2BAC2D3-3590-44AD-BE72-6549F3721F76}: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.150
O17 - HKLM\System\CS1\Services\Tcpip\..\{21FB6AF6-9051-40BB-BB21-E5A3F50BB763}: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.150
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
User avatar
leeegglestone
Geek
Geek
 
Posts: 65
Joined: Thu Nov 20, 2003 1:00 am

Thanks given:0
Thanks received:0
Top

Postby leeegglestone » Sun Aug 13, 2006 11:37 pm

Also where is Display properties??

Icant Right Click on the Desktop due to this thing thats taken over it
User avatar
leeegglestone
Geek
Geek
 
Posts: 65
Joined: Thu Nov 20, 2003 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Mon Aug 14, 2006 12:51 am

You are running hijackthis.exe from a temp folder please put it in it's own folder so you can use the backup feature just in case.
The path should be something like this:
C:\hjt\hijackthis.exe

Please copy this to Notepad and print it. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
You should not have any open windows when you are following the procedures below.

Close all other open Windows and have HiJackThis Fix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{21FB6AF6-9051-40BB-BB21-E5A3F50BB763}: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2BAC2D3-3590-44AD-BE72-6549F3721F76}: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.150
O17 - HKLM\System\CS1\Services\Tcpip\..\{21FB6AF6-9051-40BB-BB21-E5A3F50BB763}: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.30 85.255.112.150

This one:
O17 - HKLM\System\CCS\Services\Tcpip\..\{532DAD06-9FC1-4F68-BEA7-29CCE4ECFDDD}: NameServer = 205.188.146.145
Is your AOL name server so make sure you do not remove it:
(205.188.146.145 = nstot.proxy.aol.com)

I suspect that the trojan is trying to access those IPs (85.255.115.30,85.255.112.150)
To try and download something or notify them that you are an infected system.

Reboot in to Safe mode:
(Restart Windows after you see the BIOS screen and before Windows starts to load.
Start tapping the F8 key. The Windows Advanced Options Menu appears.
Use the Arrow key to ensure that the Safe Mode option is selected.
Press Enter. The computer then begins to start in Safe mode.)

Then run your AVG antivirus, make sure you do a full scan for all files on your system.

When the virus scan is finished empty all your TEMP Folders, Temporary Internet Files Folder and then empty your Recycle Bin, reboot and post a new HiJackThis log.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Dave_Lethal » Mon Aug 14, 2006 4:41 pm

To get to the display properties:

Start>Control Panel>Display
User avatar
Dave_Lethal
Executive Geek
Executive Geek
 
Posts: 648
Joined: Sat Jun 05, 2004 1:00 am
Location: Chicago, IL
Operating System:

Thanks given:0
Thanks received:0
Top

Postby leeegglestone » Mon Aug 14, 2006 10:10 pm

I have tried in safe mode and the spybot,adaware and my avg virus checker all freeze, just like in normal view.

I removed some things with hijacker, this is the log now.

Im really struggling, nothing is working that I try, I need to get this spyware/viruses out

Logfile of HijackThis v1.99.1
Scan saved at 10:08:41 PM, on 8/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\gsicon.exe
C:\WINDOWS\system32\dslagent.exe
C:\Program Files\VoyagerTest\fts.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\aoltpspd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lee\Desktop\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{532DAD06-9FC1-4F68-BEA7-29CCE4ECFDDD}: NameServer = 205.188.146.145
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
User avatar
leeegglestone
Geek
Geek
 
Posts: 65
Joined: Thu Nov 20, 2003 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Tue Aug 15, 2006 11:54 am

your log looks clean

At this point I would suggest you download this is a free 30 trial of there anti-spyware program.
Install it, update it and run a complete system scan when it finishes go with the default removal recommendation.
Make sure you select the option to save the report, post this report and a new hijackthis log.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top


Return to Misc. Software

Who is online

Users browsing this forum: No registered users and 1 guest

cron