my computer is going to have a heart attack

Thread Solved

Join Date: May 2004
Posts: 38
Reputation: deadbydesign is an unknown quantity at this point 
Solved Threads: 0
deadbydesign deadbydesign is offline Offline
Light Poster

my computer is going to have a heart attack

 
0
  #1
May 7th, 2004
hi, i dont know THAT much about computers. i do however know that mine is being severly raped by spyware and adware and trojans. i currently have ad-aware 6.0, spybot search and destroy, up to date norton anti virus 2004, spy sweeper, and pest patrol (trial/scan only). ive known that ive had spy/ad ware problems for a while now..but they were too minor for me to really care about past running ad-aware. recently ive been bombarded with popups and other websites i have visited all show links to the offer the popups are showing. i think it is v shield or something to that affect. im really not interested in that program nor will i ever click on the links/windows. i have noticed a substantial decrease in my computers performance (im running broadband). websites i visit have a tendency to disable me from typing in anything..such as this website a few moments ago, i tried to register and had to close it out and start all over. what i care about is what i notice on the surface, COMPLETE ANNOYANCE. i would insert a picture to further illustrate what is wrong but im new and it would more than likely not work. im rambling..but im in dyre need of help of anyone who knows how to fix what is wrong with my pc (that you can gather either through here or via private messaging). two of my main problems are euniverse.com/sirsearch.com, and recently "clientman" along with something that inserts green bars and hyperlinks into key words on websites such as "movie" or "car". i just downloaded spy sweeper which claims to handle clientman but i havent noticed any changes as of yet..but then again i havent rebooted. anyways, sorry i went on about nothing basically, im just ready to beat this piece with a hammer and never use computers again (figuratively speaking). HELP!!!
Reply With Quote Quick reply to this message  
Join Date: Mar 2004
Posts: 381
Reputation: Yzk is an unknown quantity at this point 
Solved Threads: 14
Yzk's Avatar
Yzk Yzk is offline Offline
Posting Whiz

Re: my computer is going to have a heart attack

 
0
  #2
May 7th, 2004
Try running Hyjack this:
http://www.sherrylynn.us/HijackThis.exe
and post a log from this program and we'll see what we can do about this.
- Yzk
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 9
Reputation: iris_eye is an unknown quantity at this point 
Solved Threads: 2
iris_eye iris_eye is offline Offline
Newbie Poster

Re: my computer is going to have a heart attack

 
0
  #3
May 7th, 2004
Make backups of your important personal files from your PC, then destroy your DOS partitions. Reformat your hard drive. Then reinstall your OS and software.

BUT before you even connect online, buy the lastest anti-Virus software from somewhere like McAfee, and also install a firewall - Zonealarm is free (but make sure you are very strict as to what you allow to access the net).

That should go a long way to eliminating the threat.

I've found that downloaded software simply cannot remove very embedded scumware, which is why I recommend start from scratch with a full reformat. Otherwise you may never be rid. And, hey, be more careful in future.
Reply With Quote Quick reply to this message  
Join Date: Aug 2003
Posts: 9,579
Reputation: caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold 
Solved Threads: 494
Team Colleague
caperjack's Avatar
caperjack caperjack is offline Offline
Posting Prodigy

Re: my computer is going to have a heart attack

 
0
  #4
May 7th, 2004
Originally Posted by iris_eye
Make backups of your important personal files from your PC, then destroy your DOS partitions. Reformat your hard drive. Then reinstall your OS and software.

BUT before you even connect online, buy the lastest anti-Virus software from somewhere like McAfee, and also install a firewall - Zonealarm is free (but make sure you are very strict as to what you allow to access the net).

That should go a long way to eliminating the threat.

I've found that downloaded software simply cannot remove very embedded scumware, which is why I recommend start from scratch with a full reformat. Otherwise you may never be rid. And, hey, be more careful in future.
6 months ago I had a computer full of spyware /trojans ,i did a search and found and used all the programs to remove the unwanted spyware ,I now use these tools to help otheres remove spyware ,I didn't format my computer ,I have't formated my computer is almost a year .I run windows updates regulary and install a couple of programs to block spyware sites ,so formating is not necessasry,but is sometimes the fastes way!!
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 363
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: my computer is going to have a heart attack

 
0
  #5
May 7th, 2004
As YzK said, download and run HijackThis and post the log file it generates. That will allow us to see exactly what "guests" you've still got in your system.

Also, Ad Aware, SpyBot, and the like will usually nail 99% of the "malware" programs, but only if you keep them very up to date!!! Use the "check for new updates" functions of utilities often; updates are sometimes released within days of each other. Just like your anti-virus program, these utilites are useless if you don't keep them current.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 3
Reputation: Seaward is an unknown quantity at this point 
Solved Threads: 1
Seaward Seaward is offline Offline
Newbie Poster

Re: my computer is going to have a heart attack

 
0
  #6
May 7th, 2004
See the post re "Eliminate Spyware etc......", or go to http://bubdaddy.blogspot.com/ and read the April 21, 2004 post there.

Update Ad-aware every day and get a copy of GhostSurf Pro.
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 38
Reputation: deadbydesign is an unknown quantity at this point 
Solved Threads: 0
deadbydesign deadbydesign is offline Offline
Light Poster

Re: my computer is going to have a heart attack

 
0
  #7
May 8th, 2004
erm..ok so here is the logfile..im not touching anything yet because im really not familiar with this program..ill check back later for posts on what to do.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Roadrunner
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;;localhost;<local>
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {269B6797-664E-48AA-B283-B012BDF6E525} - C:\PROGRA~1\INCRED~1\BHO\BHO.dll (file missing)
O2 - BHO: (no name) - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C:\WINDOWS\System32\msibkd.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: FlowGoBar - {4E7BD74F-2B8D-469E-C0FF-FD63B399BC7D} - C:\PROGRA~1\FLOWGO~1\Toolbar\flgobar.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [kbdro] C:\WINDOWS\System32\kbdro.exe
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msgked.exe
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
O16 - DPF: {11111111-2222-3333-4444-555555555555} - https://www.taxsimple.com/citrix/federal.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/downlo...?1083818275015
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/28c61a3bd8b0b4e...p/RdxIE601.cab
O16 - DPF: {59D04288-805E-4D43-BE09-83B1083E9E1E} (IUpdateAutoLaunch Control) - http://idenphones.motorola.com/idenu...AutoLaunch.ocx
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...005.8272106481
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553542500} - http://active.macromedia.com/flash2/cabs/swflash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/Te...loads/outc.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,002
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 757
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: my computer is going to have a heart attack

 
0
  #8
May 8th, 2004
Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com

O2 - BHO: (no name) - {269B6797-664E-48AA-B283-B012BDF6E525} - C:\PROGRA~1\INCRED~1\BHO\BHO.dll (file missing)
O2 - BHO: (no name) - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C:\WINDOWS\System32\msibkd.dll

O3 - Toolbar: FlowGoBar - {4E7BD74F-2B8D-469E-C0FF-FD63B399BC7D} - C:\PROGRA~1\FLOWGO~1\Toolbar\flgobar.dll (file missing)

O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
O4 - HKCU\..\Run: [kbdro] C:\WINDOWS\System32\kbdro.exe
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msgked.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/28c61a3bd8b0b4...ip/RdxIE601.cab

Reboot into safe mode following the instructions here & navigate to & delete

C:\PROGRA~1\INCRED~1< folder
C:\PROGRA~1\FLOWGO~1< folder
C:\Program Files\System Soap Pro< folder
C:\WINDOWS\System32\kbdro.exe< file
C:\WINDOWS\System32\msgked.exe< file

Reboot normally after doing the above then post a fresh log plz.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,002
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 757
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: my computer is going to have a heart attack

 
0
  #9
May 8th, 2004
Originally Posted by iris_eye
Make backups of your important personal files from your PC, then destroy your DOS partitions. Reformat your hard drive. Then reinstall your OS and software.

BUT before you even connect online, buy the lastest anti-Virus software from somewhere like McAfee, and also install a firewall - Zonealarm is free (but make sure you are very strict as to what you allow to access the net).

That should go a long way to eliminating the threat.

I've found that downloaded software simply cannot remove very embedded scumware, which is why I recommend start from scratch with a full reformat. Otherwise you may never be rid. And, hey, be more careful in future.
You're not related to Mad_Dog are you?? If I found some tracking cookies on my computer, do you think I should reformat?? I'm really not sure.
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 38
Reputation: deadbydesign is an unknown quantity at this point 
Solved Threads: 0
deadbydesign deadbydesign is offline Offline
Light Poster

Re: my computer is going to have a heart attack

 
0
  #10
May 8th, 2004
do i need winzip to unzip hjt?..or anything for that matter
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC