Content Top
DAL Computer Help » Internet Security Help » Spyware, Adware, Viruses and HijackThis Logs » Damm Spyware

Recommended Fix

Click here to fix Windows Errors and Optimize Windows Performance

Need Computer Help?
Register Now for FREE

Damm Spyware

Reply
Thread Tools
Spyware, Adware, Viruses and HijackThis Logs
  #1 (permalink)  
Old 11-01-2005, 05:49 PM
Newbie
D-A-L Newbie
 
Join Date: Jan 2005
Posts: 8
Redler Is a beginner here at D-A-L
Angry Damm Spyware

Hello,
I, like a lot of other people, seem to be dammed with recent variants of Spyware. I seem to have tried everything and now I turning to the so-called experts to help me out. Here's a summary of my issues plus my Hijackthis log which by the way throws up a virus alarm from my nortan antivirus evertime I try to save Hijacthis log. I have to disable the real time protection to save the log! That's just minor compared to what I seem to be picking up.
I continuously get infected by B-S SPY. I've disabled System restore, booted up on safe mode ran the virus protection etc. etc. to no avail. I keep getting re-infected. My Desktop Wallpaper has changed to a black background and I can't get it back. My Task manager is disabled and everytime I enable it via regedit it keeps getting disabled when I log out and log back in again.

Any help would be much appreciated!

Logfile of HijackThis v1.99.0
Scan saved at 16:38:14, on 11/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\RVS\WCOM\SYSTEM\RVSINST.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\NavNT\vptray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet\ICC\icc2000.exe
C:\Program Files\Intelligent ISDN Utilities\ccmon.exe
C:\Program Files\RVS\WCOM\SYSTEM\RVSCC.EXE
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\system32\kernels32.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\notepad.exe
C:\data\downloads\Nav Updates\virusfixes\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie.
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.usefulware.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\kernels32.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Iusage] C:\PROGRA~1\INTERN~1.7\netdet.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICC2000] C:\Program Files\Internet\ICC\icc2000.exe
O4 - Global Startup: CAPI Tray.lnk = C:\Program Files\Intelligent ISDN Utilities\ccmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.05p.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.scoobidoo.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: 206.161.124.130 (HKLM)
O16 - DPF: Ulster Bank AnyTime - https://anytime2.ulsterbank.com/asp/AnyTime.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTS...my_car_pop.jsp
O16 - DPF: {11111111-1111-1111-1111-222222222222} - ms-its:mhtml:file://Cne.MHT!http://www.t058.com//inst//x.chm::/open.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1104704582356
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9AA2F31F-640B-4D69-B478-9FDEA4EEC9E5}: NameServer = 195.218.116.2 194.46.8.57
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: RVS CommCenter - Living Byte Software GmbH, Munich - C:\Program Files\RVS\WCOM\SYSTEM\RVSCC.EXE
O23 - Service: RvscomSv - Living Byte Software GmbH, Munich - C:\Program Files\RVS\WCOM\SYSTEM\RVSCOMSV.EXE
O23 - Service: RVS Installer - Living Byte Software GmbH, Munich - C:\Program Files\RVS\WCOM\SYSTEM\RVSINST.EXE
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 11-01-2005, 07:11 PM
spud's Avatar
D-A-L Team Member (UK)
Loyal Contributor
 
Join Date: Aug 2004
Posts: 1,658
spud is just really nicespud is just really nicespud is just really nicespud is just really nicespud is just really nice
Re: Damm Spyware

please be patient with us "so-called experts" we will get you out of trouble asap

thanks
__________________
DOWNLOADS

NCFC rule

OWENS HELP

Yeti sports

Microsoft Help

latest DirectX 9c here

hijacthis

have a laugh


If it dont fit...force it. If ya cant force it...get a bigger hammer. If it breaks...it probably needed replacing anyway.

APPROVED MICROSOFT BETA TESTER
There are 10 kinds of people in the world:
Those who understand binary & those who don't.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 11-01-2005, 08:28 PM
Newbie
D-A-L Newbie
 
Join Date: Jan 2005
Posts: 8
Redler Is a beginner here at D-A-L
Re: Damm Spyware

Dear Spud,

Any idea how long I'll h ave to wait? :-)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 11-01-2005, 10:19 PM
spud's Avatar
D-A-L Team Member (UK)
Loyal Contributor
 
Join Date: Aug 2004
Posts: 1,658
spud is just really nicespud is just really nicespud is just really nicespud is just really nicespud is just really nice
Re: Damm Spyware

hi there owen is the expert on hijack this logs and he will do it as soon as poss but it seems at the mo that he is not on line he is usually doing the answers with in 2-3 hours please be patient he will do it i promise
__________________
DOWNLOADS

NCFC rule

OWENS HELP

Yeti sports

Microsoft Help

latest DirectX 9c here

hijacthis

have a laugh


If it dont fit...force it. If ya cant force it...get a bigger hammer. If it breaks...it probably needed replacing anyway.

APPROVED MICROSOFT BETA TESTER
There are 10 kinds of people in the world:
Those who understand binary & those who don't.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 12-01-2005, 11:18 PM
Newbie
D-A-L Newbie
 
Join Date: Jan 2005
Posts: 8
Redler Is a beginner here at D-A-L
Smile Re: Damm Spyware

..... any idea how long more I'll have to wait??
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 12-01-2005, 11:41 PM
spud's Avatar
D-A-L Team Member (UK)
Loyal Contributor
 
Join Date: Aug 2004
Posts: 1,658
spud is just really nicespud is just really nicespud is just really nicespud is just really nicespud is just really nice
Re: Damm Spyware

i have just asked owen to have a look at it

please bear with him as you can see he has a lot to catch up with tonight

thanks
__________________
DOWNLOADS

NCFC rule

OWENS HELP

Yeti sports

Microsoft Help

latest DirectX 9c here

hijacthis

have a laugh


If it dont fit...force it. If ya cant force it...get a bigger hammer. If it breaks...it probably needed replacing anyway.

APPROVED MICROSOFT BETA TESTER
There are 10 kinds of people in the world:
Those who understand binary & those who don't.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 12-01-2005, 11:58 PM
Newbie
D-A-L Newbie
 
Join Date: Jan 2005
Posts: 8
Redler Is a beginner here at D-A-L
Re: Damm Spyware

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 13-01-2005, 09:48 PM
owen's Avatar
D-A-L Team Member (UK)
Loyal Contributor
 
Join Date: Jun 2004
Posts: 5,272
owen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furnitureowen is beginning to become part of the furniture
Re: Damm Spyware

Hello, in future be patient. What we do is voluntary and we have a lot to do and sometimes it piles up and takes hours to get through. PMing spud won't really help you get a faster response.

Please download the attached DelDomains.zip. Unzip it and right click the file DelDomains.inf and from the drop down menu, click Install. It will perform a silent process.

Warning: This will delete all sites in the IE Trusted and Restricted Zones! If you have made immunizations with software such as SpywareBlaster and Spybot, you will need to perform them again after this procedure.

Close all browser windows, restart Hijack This and put a checkmark next to the following entries:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.usefulware.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\kernels32.exe
O16 - DPF: {11111111-1111-1111-1111-222222222222} - ms-its:mhtml:file://Cne.MHT!http://www.t058.com//inst//x.chm::/open.exe

Click Fix Checked

Then boot into Safe Mode and ensure that you are showing Hidden Files and Folders.

Delete the following files and folders:
C:\WINDOWS\system32\kernels32.exe

Reboot and post a fresh log
__________________
Owen,
My Website - I Security.org.uk

MALWARE: READ FIRST Procedures:
|_ SpyBot V1.4 _|_ Ad-Aware SE 1.06_|_ HijackThis Log __V1.99.1 _|


[*]Be patient and wait for a response, we'll do our best to help resolve your issue.
[*]When posting for help, start your own thread and stick to it. Don't start multiple threads or post in other peoples threads!

If we have helped you, please consider making a donation to help support the forum. All donations are greatly appreciated. You can also support the forum by placing a link to us on your personal website.

Useful Links:
Posting a Hijack This Log
Preposting and Prevention Info
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 14-01-2005, 10:03 AM
D-A-L's Avatar
D-A-L Administrator
 
Join Date: Apr 2004
Posts: 3,534
D-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legendD-A-L is on their way to becoming a legend
Re: Damm Spyware

Quote:
so-called experts
I'm suprised you actually got help after that comment Redler, your pushing your luck!
__________________
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 14-01-2005, 07:48 PM
spud's Avatar
D-A-L Team Member (UK)
Loyal Contributor
 
Join Date: Aug 2004
Posts: 1,658
spud is just really nicespud is just really nicespud is just really nicespud is just really nicespud is just really nice
Re: Damm Spyware

has the advice fixed your problems redler if so could you please let us know so we can close the thraed if not we will help you further

thanks
__________________
DOWNLOADS

NCFC rule

OWENS HELP

Yeti sports

Microsoft Help

latest DirectX 9c here

hijacthis

have a laugh


If it dont fit...force it. If ya cant force it...get a bigger hammer. If it breaks...it probably needed replacing anyway.

APPROVED MICROSOFT BETA TESTER
There are 10 kinds of people in the world:
Those who understand binary & those who don't.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Spyware Shortthiing_Jenn Desktop / Server Applications 4 22-08-2007 09:35 AM
Microsoft Anti-Spyware=IE Spyware! Tyler Desktop / Server Applications 8 25-01-2005 04:47 PM
Spyware that will not go away CONFUSED Spyware, Adware, Viruses and HijackThis Logs 4 28-10-2004 07:44 PM
Spyware!!! Help!!!!! ikaika Spyware, Adware, Viruses and HijackThis Logs 13 02-10-2004 03:34 PM
HSA Spyware karthik Spyware, Adware, Viruses and HijackThis Logs 1 07-09-2004 06:02 PM


All times are GMT +1. The time now is 11:22 AM.

Bottom Corner