Computing.Net > Forums > Security and Virus > spyware problem

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

spyware problem

Reply to Message Icon

Name: edga_dave
Date: December 18, 2004 at 07:42:28 Pacific
OS: xp
CPU/Ram: 256
Comment:

hey, im having problems with spyware!!

what keeps happening is that when im surfing the net, my home page and search bar keeps changing (i know this because spyware guard askes me if i want to change them)

I have spybot, adaware, spyware guard, AVG and all are clean

hijck this log is:

Logfile of HijackThis v1.98.2
Scan saved at 15:35:51, on 18/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\avgserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\twink64.exe
C:\PROGRA~1\AVG\avgcc32.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\msshed32.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\3com\Connection Assistant\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\3com\CONNEC~1\Common\MOTIVE~1.exe
C:\Program Files\adaware\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = 0
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fishforums.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.dashtabs.com/dashtabs/index.php?sid=420193d2b8316ff4bc89eeabc2e40cc7
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: IE Search Toolbar - {EB381422-F797-4A98-A266-9DC490821907} - C:\Program Files\IESearchToolbar\IESearchToolbar.dll
O4 - HKLM\..\Run: [load32] C:\WINDOWS\System32\swchost.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [inhelpw] C:\WINDOWS\System32\inhelpw.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\twink64.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [cdgLV] C:\documents and settings\dave\local settings\temp\cdgLV.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\AVG\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [atiupdate] C:\DOCUME~1\Dave\LOCALS~1\Temp\msshed32.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: 3Com Connection Assistant.lnk = C:\Program Files\3com\Connection Assistant\bin\matcli.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.exe
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/167bd1ed019ddf0f0723/netzip/RdxIE601.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.co.uk/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab

any help with his problem?? its getting really anoying and ive tryed everythink!!



Sponsored Link
Ads by Google

Response Number 1
Name: Sabertooth
Date: December 18, 2004 at 09:13:13 Pacific
Reply:

Here is your log as analyzed...BTW update your version to the newer 1.99.0

C:\WINDOWS\System32\twink64.exe
C:\PROGRA~1\3com\CONNEC~1\Common\MOTIVE~1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.dashtabs.com/dashtabs/index.php?sid=420193d2b8316ff4bc89eeabc2e40cc7
R3 - Default URLSearchHook is missing.
O3 - Toolbar: IE Search Toolbar - {EB381422-F797-4A98-A266-9DC490821907} - C:\Program Files\IESearchToolbar\IESearchToolbar.dll
O4 - HKLM\..\Run: [load32] C:\WINDOWS\System32\swchost.exe
O4 - HKLM\..\Run: [inhelpw] C:\WINDOWS\System32\inhelpw.exe
04 - HKLM\..\Run: [cdgLV] C:\documents and settings\dave\local settings\temp\cdgLV.exe
04 - HKCU\..\Run: [atiupdate] C:\DOCUME~1\Dave\LOCALS~1\Temp\msshed32.exe

Boot into safe mode and let hijackthis fix all the above.

-- Always do what you are afraid to do --


0

Response Number 2
Name: yankanuk
Date: December 18, 2004 at 09:14:00 Pacific
Reply:

You have a bunch of nasties...try Hi-Jack This analyzer
I pasted your log into it and there was lots of bad stuff. If you don't know what an item is, don't delete it. Make sure you make up a folder on C drive before you run it, that way it will keep the back-ups for you and you can always undo what you've done. Also, here's the latest Hi-Jack This

If you need a simple solution, try mine. I try to give advise on things that have happened to my PC. Glad to have a chance to help you.


0

Response Number 3
Name: fordman
Date: December 19, 2004 at 11:59:19 Pacific
Reply:

Yeah, thank goodness for that now, the analyzer.

Techs


0

Response Number 4
Name: yankanuk
Date: December 19, 2004 at 13:20:35 Pacific
Reply:

It is a pleasure to use, yes fordman

If you need a simple solution, try mine. I try to give advise on things that have happened to my PC. Glad to have a chance to help you.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: spyware problem

Spyware Problems www.computing.net/answers/security/spyware-problems/19452.html

Spyware problems www.computing.net/answers/security/spyware-problems/24330.html

popups/spyware problems www.computing.net/answers/security/popupsspyware-problems/13221.html