Computing.Net > Forums > Security and Virus > adware, popups, and whatnot

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

adware, popups, and whatnot

Reply to Message Icon

Original Message
Name: AWS
Date: January 30, 2004 at 13:37:20 Pacific
Subject: adware, popups, and whatnot
OS: Windows XP 2002
CPU/Ram: Intel Celeron 1.7 / 248 R
Comment:

I have spent a long time trying to get spyware and stuff off of my computer. the most recent one that has been getting to me is the commonname thing, which i think i finally got off in safe mode. unfortunately i am still getting tons of popups in IE even though i removed IE and use mozilla now. this doesnt make sense to me so i think there is more adware on my computer. here is my hijackthis log. if you can help me out it will be much appreciated!!!

Logfile of HijackThis v1.97.7
Scan saved at 4:20:56 PM, on 1/30/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\sylcfqqu.exe
C:\Program Files\aim\aim.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
C:\Documents and Settings\Adam W. Smith\Application Data\DownloadPlus.exe
C:\Program Files\Cisco Systems\VPN Client\ipseclog.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\MOZILLA.ORG\MOZILLA\MOZILLA.EXE
C:\Documents and Settings\Adam W. Smith\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.blazefind.com/search.php?search=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.blazefind.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.blazefind.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.blazefind.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.lib.muohio.edu:3128
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = "C:\Program Files\Outlook Express\msimn.exe"
N2 - Netscape 6: user_pref("browser.startup.homepage", "http://www.yahoo.com"); (C:\Documents and Settings\Adam W. Smith\Application Data\Mozilla\Profiles\default\fiq1l3dk.slt\prefs.js)
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Adam W. Smith\Application Data\Mozilla\Profiles\default\fiq1l3dk.slt\prefs.js)
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - (no file)
O2 - BHO: (no name) - {01DE36CC-1A4C-E03D-6F58-A8F42FC1DD7A} - C:\WINDOWS\system32\wygussky.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\System32\bridge.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [WinFavorites] c:\program files\winfavorites\WinFavorites.exe1
O4 - HKLM\..\Run: [fglypxvv] C:\WINDOWS\sylcfqqu.exe
O4 - HKLM\..\Run: [systray] C:\WINDOWS\System32\a.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKLM\..\RunOnce: [SpyBotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Adam W. Smith\Application Data\DownloadPlus.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: AOL Instant Messenger (SM) (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} (brdg Class) - http://www2.flingstone.com/cab/2000XP/bridge.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2515AC8B-7277-4EDA-813C-B3679DC5AE86}: Domain = muohio.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{2515AC8B-7277-4EDA-813C-B3679DC5AE86}: NameServer = 134.53.253.1,134.53.253.5
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = muohio.edu
O17 - HKLM\System\CS1\Services\Tcpip\..\{2515AC8B-7277-4EDA-813C-B3679DC5AE86}: Domain = muohio.edu
O17 - HKLM\System\CS1\Services\Tcpip\..\{2515AC8B-7277-4EDA-813C-B3679DC5AE86}: NameServer = 134.53.253.1,134.53.253.5
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = muohio.edu


Report Offensive Message For Removal


Response Number 1
Name: mark2a
Date: January 30, 2004 at 14:10:02 Pacific
Reply: (edit)

Hi Adam

The first thing we need to do is extract Hijackthis to it's own folder, right click > extract all,then run it from that folder without doing this we have no means of recovery should a mistake occur.

Then close all browser/explorer windows and run Hijackthis allowing it to fix the following by putting a tick in the box next to them and hitting the 'Fix Checked' button.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.blazefind.com/search.php?search=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.blazefind.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.blazefind.com/search_page.php
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.blazefind.com
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - (no file)
O2 - BHO: (no name) - {01DE36CC-1A4C-E03D-6F58-A8F42FC1DD7A} - C:\WINDOWS\system32\wygussky.dll
O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\System32\bridge.dll
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [WinFavorites] c:\program files\winfavorites\WinFavorites.exe1
O4 - HKLM\..\Run: [fglypxvv] C:\WINDOWS\sylcfqqu.exe
O4 - HKLM\..\Run: [systray] C:\WINDOWS\System32\a.exe

Then reboot and find and delete the following files/folders


C:\WINDOWS\System32\bridge.dll <----file
c:\program files\winfavorites <-----folder
C:\WINDOWS\sylcfqqu.exe <-----file
C:\WINDOWS\System32\a.exe <-----file

To make sure none of them elude you due to being hidden, make sure to show hidden/system files. How to show hidden/system files: http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Then rescan with Hijackthis and post a fresh log


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software