943,460 Members | Top Members by Rank

Ad:
You are currently viewing page 1 of this multi-page discussion thread
May 7th, 2004
0

my computer is going to have a heart attack

Expand Post »
hi, i dont know THAT much about computers. i do however know that mine is being severly raped by spyware and adware and trojans. i currently have ad-aware 6.0, spybot search and destroy, up to date norton anti virus 2004, spy sweeper, and pest patrol (trial/scan only). ive known that ive had spy/ad ware problems for a while now..but they were too minor for me to really care about past running ad-aware. recently ive been bombarded with popups and other websites i have visited all show links to the offer the popups are showing. i think it is v shield or something to that affect. im really not interested in that program nor will i ever click on the links/windows. i have noticed a substantial decrease in my computers performance (im running broadband). websites i visit have a tendency to disable me from typing in anything..such as this website a few moments ago, i tried to register and had to close it out and start all over. what i care about is what i notice on the surface, COMPLETE ANNOYANCE. i would insert a picture to further illustrate what is wrong but im new and it would more than likely not work. im rambling..but im in dyre need of help of anyone who knows how to fix what is wrong with my pc (that you can gather either through here or via private messaging). two of my main problems are euniverse.com/sirsearch.com, and recently "clientman" along with something that inserts green bars and hyperlinks into key words on websites such as "movie" or "car". i just downloaded spy sweeper which claims to handle clientman but i havent noticed any changes as of yet..but then again i havent rebooted. anyways, sorry i went on about nothing basically, im just ready to beat this piece with a hammer and never use computers again (figuratively speaking). HELP!!!
Reputation Points: 10
Solved Threads: 0
Light Poster
deadbydesign is offline Offline
45 posts
since May 2004
May 7th, 2004
0

Re: my computer is going to have a heart attack

Try running Hyjack this:
http://www.sherrylynn.us/HijackThis.exe
and post a log from this program and we'll see what we can do about this.
Yzk
Reputation Points: 82
Solved Threads: 14
Posting Whiz
Yzk is offline Offline
380 posts
since Mar 2004
May 7th, 2004
0

Re: my computer is going to have a heart attack

Make backups of your important personal files from your PC, then destroy your DOS partitions. Reformat your hard drive. Then reinstall your OS and software.

BUT before you even connect online, buy the lastest anti-Virus software from somewhere like McAfee, and also install a firewall - Zonealarm is free (but make sure you are very strict as to what you allow to access the net).

That should go a long way to eliminating the threat.

I've found that downloaded software simply cannot remove very embedded scumware, which is why I recommend start from scratch with a full reformat. Otherwise you may never be rid. And, hey, be more careful in future.
Reputation Points: 10
Solved Threads: 2
Newbie Poster
iris_eye is offline Offline
9 posts
since May 2004
May 7th, 2004
0

Re: my computer is going to have a heart attack

Quote originally posted by iris_eye ...
Make backups of your important personal files from your PC, then destroy your DOS partitions. Reformat your hard drive. Then reinstall your OS and software.

BUT before you even connect online, buy the lastest anti-Virus software from somewhere like McAfee, and also install a firewall - Zonealarm is free (but make sure you are very strict as to what you allow to access the net).

That should go a long way to eliminating the threat.

I've found that downloaded software simply cannot remove very embedded scumware, which is why I recommend start from scratch with a full reformat. Otherwise you may never be rid. And, hey, be more careful in future.
6 months ago I had a computer full of spyware /trojans ,i did a search and found and used all the programs to remove the unwanted spyware ,I now use these tools to help otheres remove spyware ,I didn't format my computer ,I have't formated my computer is almost a year .I run windows updates regulary and install a couple of programs to block spyware sites ,so formating is not necessasry,but is sometimes the fastes way!!
Team Colleague
Reputation Points: 1056
Solved Threads: 790
I hate 20 Questions
caperjack is offline Offline
12,711 posts
since Aug 2003
May 7th, 2004
0

Re: my computer is going to have a heart attack

As YzK said, download and run HijackThis and post the log file it generates. That will allow us to see exactly what "guests" you've still got in your system.

Also, Ad Aware, SpyBot, and the like will usually nail 99% of the "malware" programs, but only if you keep them very up to date!!! Use the "check for new updates" functions of utilities often; updates are sometimes released within days of each other. Just like your anti-virus program, these utilites are useless if you don't keep them current.
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003
May 7th, 2004
0

Re: my computer is going to have a heart attack

See the post re "Eliminate Spyware etc......", or go to http://bubdaddy.blogspot.com/ and read the April 21, 2004 post there.

Update Ad-aware every day and get a copy of GhostSurf Pro.
Reputation Points: 10
Solved Threads: 1
Newbie Poster
Seaward is offline Offline
3 posts
since May 2004
May 8th, 2004
0

Re: my computer is going to have a heart attack

erm..ok so here is the logfile..im not touching anything yet because im really not familiar with this program..ill check back later for posts on what to do.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Roadrunner
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;;localhost;<local>
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {269B6797-664E-48AA-B283-B012BDF6E525} - C:\PROGRA~1\INCRED~1\BHO\BHO.dll (file missing)
O2 - BHO: (no name) - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C:\WINDOWS\System32\msibkd.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: FlowGoBar - {4E7BD74F-2B8D-469E-C0FF-FD63B399BC7D} - C:\PROGRA~1\FLOWGO~1\Toolbar\flgobar.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [kbdro] C:\WINDOWS\System32\kbdro.exe
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msgked.exe
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
O16 - DPF: {11111111-2222-3333-4444-555555555555} - https://www.taxsimple.com/citrix/federal.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/downlo...?1083818275015
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/28c61a3bd8b0b4e...p/RdxIE601.cab
O16 - DPF: {59D04288-805E-4D43-BE09-83B1083E9E1E} (IUpdateAutoLaunch Control) - http://idenphones.motorola.com/idenu...AutoLaunch.ocx
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...005.8272106481
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553542500} - http://active.macromedia.com/flash2/cabs/swflash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/Te...loads/outc.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
Reputation Points: 10
Solved Threads: 0
Light Poster
deadbydesign is offline Offline
45 posts
since May 2004
May 8th, 2004
0

Re: my computer is going to have a heart attack

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com

O2 - BHO: (no name) - {269B6797-664E-48AA-B283-B012BDF6E525} - C:\PROGRA~1\INCRED~1\BHO\BHO.dll (file missing)
O2 - BHO: (no name) - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C:\WINDOWS\System32\msibkd.dll

O3 - Toolbar: FlowGoBar - {4E7BD74F-2B8D-469E-C0FF-FD63B399BC7D} - C:\PROGRA~1\FLOWGO~1\Toolbar\flgobar.dll (file missing)

O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
O4 - HKCU\..\Run: [kbdro] C:\WINDOWS\System32\kbdro.exe
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msgked.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/28c61a3bd8b0b4...ip/RdxIE601.cab

Reboot into safe mode following the instructions here & navigate to & delete

C:\PROGRA~1\INCRED~1< folder
C:\PROGRA~1\FLOWGO~1< folder
C:\Program Files\System Soap Pro< folder
C:\WINDOWS\System32\kbdro.exe< file
C:\WINDOWS\System32\msgked.exe< file

Reboot normally after doing the above then post a fresh log plz.
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,162 posts
since Feb 2004
May 8th, 2004
0

Re: my computer is going to have a heart attack

Quote originally posted by iris_eye ...
Make backups of your important personal files from your PC, then destroy your DOS partitions. Reformat your hard drive. Then reinstall your OS and software.

BUT before you even connect online, buy the lastest anti-Virus software from somewhere like McAfee, and also install a firewall - Zonealarm is free (but make sure you are very strict as to what you allow to access the net).

That should go a long way to eliminating the threat.

I've found that downloaded software simply cannot remove very embedded scumware, which is why I recommend start from scratch with a full reformat. Otherwise you may never be rid. And, hey, be more careful in future.
You're not related to Mad_Dog are you?? If I found some tracking cookies on my computer, do you think I should reformat?? I'm really not sure.
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,162 posts
since Feb 2004
May 8th, 2004
0

Re: my computer is going to have a heart attack

do i need winzip to unzip hjt?..or anything for that matter
Reputation Points: 10
Solved Threads: 0
Light Poster
deadbydesign is offline Offline
45 posts
since May 2004

This thread is solved

Either the thread starter or a moderator has marked this thread as solved. You can most likely trust the responses and answers given. There is most likely no reason for any further responses to be posted here. If you have a related question, please start a new thread in this forum instead.

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: Follow up to :- RUNDLL32.EXE is not responding
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: Bridge.dll again





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC