Computing.Net > Forums > Security and Virus > pops are bad! please help! (moved)

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

pops are bad! please help! (moved)

Reply to Message Icon

Name: markdark
Date: November 24, 2003 at 15:22:30 Pacific
OS: xp
CPU/Ram: p4 3gig 512 ram
Comment:

after trying everything i can think of ill try posting here, i searched the forums but still have the problem i have tried ad-aware, trojan remover and spybot, all newest versions, here is my hijack this log, please help!!! !

Logfile of HijackThis v1.97.7
Scan saved at 6:03:30 PM, on 11/24/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\SK9910DM.exe
C:\WINNT\System32\PROMon.exe
C:\WINNT\System32\CTHELPER.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINNT\GWMDMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINNT\System32\rundll32.exe
C:\WINNT\System32\Zih6JY6.exe
C:\WINNT\System32\Xuj4rB2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\taskmgr.exe
C:\Documents and Settings\Owner\My Documents\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.net
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.exe
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.exe
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\Updater\wupdater.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\Ths89524.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/1251/ftp.coupons.com/v6/brix6ie.cab
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://dc2.carefirst.com/iNotes.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/1006f96ddb33bbca4d01/netzip/RdxIE601.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37487.7667708333
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/ym/yiebio5_1_6_0.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECA3907E-BB2F-458D-88C1-67B4F15E359F}: NameServer = 151.199.0.39 199.45.32.43



Sponsored Link
Ads by Google

Response Number 1
Name: Kevin The Tech Dude
Date: November 24, 2003 at 16:00:10 Pacific
Reply:

You are infected, with what? I am not sure. You might give HouseCalls a try and see if they pick up anything. These files are far from normal...

C:\WINNT\System32\Zih6JY6.exe
C:\WINNT\System32\Xuj4rB2.exe

O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\Ths89524.exe

That is to just name a few of them. There are plenty more. If I can dig up what it might be I'll let ya know.

KTTD


0

Response Number 2
Name: mark
Date: November 24, 2003 at 16:35:46 Pacific
Reply:

i tried that going to house calls and it didnt find anything... any other suggestions?


0

Response Number 3
Name: Kevin The Tech Dude
Date: November 24, 2003 at 16:46:26 Pacific
Reply:

Go here and download TDS-3 make sure you get the latest Radius file and update per there web site. It is simple to do.

KTTD



0

Response Number 4
Name: www
Date: November 24, 2003 at 16:48:02 Pacific
Reply:

do you mean popups?
try http://grc.com/files/ShootTheMessenger.exe
you can use this utility to turn on and off
windows messenger, aka netsend.

Windows Messenger Service may sound like an IM client, but it's actually a program that runs in the background, slowing your computer and posing a security risk. Shoot the Messenger shuts down this largely unnecessary program. In the past, network administrators used Windows Messenger Service to send network-wide announcements. Although most have since turned to e-mail and/or IM, Windows Messenger Service still runs invisibly, possibly accepting data packets that you never see and compromising your system's security. In the unlikely event that you find yourself needing Windows Messenger Service, Shoot the Messenger will let you switch it back on.


0

Response Number 5
Name: markdark
Date: November 24, 2003 at 16:59:31 Pacific
Reply:

got td3 and the new radius' downloads, scanned and found no trojan mutexes... any other suggestions?


0

Related Posts

See More



Response Number 6
Name: Kevin The Tech Dude
Date: November 24, 2003 at 17:00:14 Pacific
Reply:

You did a full system scan???

KTTD


0

Response Number 7
Name: DRD1
Date: November 24, 2003 at 17:40:46 Pacific
Reply:

Remove the file & directory
C:\Program Files\Common Files\slmss\slmss.exe.

This is a Trojan downloader that Trend Micro identifies as ADW_SCANPORTAL.A

Use this procedure to terminate the running malware process from memory:

1. Open Windows Task Manager (press CTRL+SHIFT+ESC) and click the Processes tab.
2. In the list of running programs, locate the process SLMSS.EXE.
3. Select the process, then press the End Process button.
4. To check if the malware process has been terminated, close Task Manager, and then open it again.

Removing autostart entries from the registry prevents the malware from executing during startup:

1. Open Registry Editor. To do this, click Start>Run, type regedit, then press Enter.
2. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>Run
3. In the right panel, locate and delete the entry:
"slmss" = "C:\Program Files\Common Files\slmss.exe"
4.Close Registry Editor.

Information obtained from:
www.trendmicro.com/vinfo/virusencyclo/...

Good Luck!
DRD


0

Response Number 8
Name: Abnormal
Date: November 24, 2003 at 18:25:18 Pacific
Reply:

The 14 random letters and numbers are
the clue to the peper trojan.
[2SWZKN82R5K47C] C:\WINNT\System32\Ths89524.exe

http://www.mjc1.com/files/peperpage/

Try today's SpyBot update.


0

Response Number 9
Name: Kevin The Tech Dude
Date: November 24, 2003 at 18:47:03 Pacific
Reply:

DRD1 and Abnormal:

Thanks for the follow up threads. I knew it was something, just did not no what. If he did do a full scan with TDS-3 I am surprised it did not pick it up. Again, thanks for the information.

KTTD


0

Response Number 10
Name: elric
Date: November 24, 2003 at 19:40:03 Pacific
Reply:

G'day,

That reference to svchost.exe is a virus. You will find it in your system directory and your startup menu as SVC service with a file called svpack.exe- uncheck it.
Also, check that it isn't run in your load and run lines in your win.ini file (also viewable in the msconfig startup list).
Good luck,
Elric


0

Response Number 11
Name: markdark
Date: November 24, 2003 at 20:33:52 Pacific
Reply:

i have done a full system scan with tds-3, i have removed the slmss.exe from the rune file via regedit. i have tried downloading todays update from spybot but it wouldnt let me download, it gave me the program not responding... thank you all for the help, ill let you know if i ever beat this thing!


0

Response Number 12
Name: markdark
Date: November 24, 2003 at 20:34:42 Pacific
Reply:

here is my most recent hijack this log

Logfile of HijackThis v1.97.7
Scan saved at 11:27:18 PM, on 11/24/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\SK9910DM.exe
C:\WINNT\System32\PROMon.exe
C:\WINNT\System32\CTHELPER.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINNT\GWMDMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINNT\System32\rundll32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\NsdQ.exe
C:\WINNT\System32\NsdQ.exe
C:\Program Files\TDS3\tds-3.exe
C:\WINNT\msagent\AgentSvr.exe
C:\Documents and Settings\Owner\My Documents\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.net
R3 - Default URLSearchHook is missing
O1 - Hosts: 203.161.127.141 www.dcsresearch.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.exe
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.exe
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [slmss] C:\Program Files\Common Files\slmss\slmss.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\Updater\wupdater.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\KvgubTz.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/1251/ftp.coupons.com/v6/brix6ie.cab
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://dc2.carefirst.com/iNotes.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/1006f96ddb33bbca4d01/netzip/RdxIE601.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/0fb5e03023def1/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37487.7667708333
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/ym/yiebio5_1_6_0.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx

ps tds-3 did find two .dll files the other programs had missed.


0

Response Number 13
Name: markdark
Date: November 24, 2003 at 21:27:53 Pacific
Reply:

ive apparently got the ladex virus to... darn i had a lot of these on here! now i cant get rid of the csrss.exe and the smss.exe... any ideas?


0

Response Number 14
Name: markdark
Date: November 26, 2003 at 05:45:52 Pacific
Reply:

no one can help with this?


0

Response Number 15
Name: Abnormal
Date: November 26, 2003 at 11:22:31 Pacific
Reply:

markdark, your best bet is the link below,
in the hijack section at the top,
post your log with subject: peper trojan

http://forums.spywareinfo.com/

Good luck


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: pops are bad! please help! (moved)

My files are gone, please help me. www.computing.net/answers/security/my-files-are-gone-please-help-me/27374.html

please help!!! www.computing.net/answers/security/please-help/6438.html

please help! Backdoor.Graybird www.computing.net/answers/security/please-help-backdoorgraybird/20273.html