Computing.Net > Forums > Security and Virus > UnspyPC help!

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

UnspyPC help!

Reply to Message Icon

Name: furiousxazn
Date: May 13, 2006 at 14:19:23 Pacific
OS: Windows XP
CPU/Ram: 1gig
Product: amd
Comment:

i just got unspypc yesterday please help!



Sponsored Link
Ads by Google

Response Number 1
Name: furiousxazn
Date: May 13, 2006 at 14:22:23 Pacific
Reply:

I've gone to add/remove programs and removed unspypc there but i still have the toolbars in my ie browser that says :
x remove toolbar | gambing | internet | pharmacy | finance | insurance | adult


0

Response Number 2
Name: jabuck
Date: May 13, 2006 at 14:26:00 Pacific
Reply:

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified. You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed.

Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor at this forum.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.

After you post the HT log run this free online scan from Kaspersky http://kaspersky.com/kos/english/kavwebscan.html
Click Accept
When the updates are finished downloading, click Next, Scan Settings
Under Scan using the following antivirus database:, select extended
Make sure the Scan Archives and Scan Mail Bases options are selected as well. Click OK
Click My Computer and wait for the scan to finish
Click Save Report As. Under Save as type:, select Text file. Save this log to your Desktop and post a copy of it here.



0

Response Number 3
Name: furiousxazn
Date: May 13, 2006 at 14:30:57 Pacific
Reply:

Here's my HJthis log

Logfile of HijackThis v1.99.1
Scan saved at 2:27:44 PM, on 5/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Documents and Settings\will\Desktop\New Folder\HijackThis.exe

O1 - Hosts: localhost 127.0.0.1
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171
O17 - HKLM\System\CCS\Services\Tcpip\..\{8092BFA6-18AA-460B-8899-399CEAC0A54F}: NameServer = 85.255.115.235 85.255.112.171
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2D6E3FA-323A-40F3-9F18-574105D52642}: NameServer = 85.255.115.235,85.255.112.171
O17 - HKLM\System\CS1\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171
O17 - HKLM\System\CS2\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


I've found a file called qtzdw that didn't exist in the web...(i did a google search and found no such files exist) so i deleted it.
Toolbar is gone but the file qtzdw.dll still exists in system32 folder. shall i delete it?


0

Response Number 4
Name: furiousxazn
Date: May 13, 2006 at 14:33:38 Pacific
Reply:

tried going to your link but it keeps redirecting me to http://www.windowsreinstall.com/


0

Response Number 5
Name: furiousxazn
Date: May 13, 2006 at 15:11:19 Pacific
Reply:

jabuck?



0

Related Posts

See More



Response Number 6
Name: jabuck
Date: May 13, 2006 at 15:38:58 Pacific
Reply:

Be with you in a minute.


0

Response Number 7
Name: jabuck
Date: May 13, 2006 at 15:50:36 Pacific
Reply:

Please download Fixwareout from this link

http://swandog46.geekstogo.com/Fixwareout.exe

or

http://downloads.subratam.org/Fixwareout.exe

Save it to your desktop and run it. Click next, then Install, then make sure "Run fixit" is checked and click finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.Post a copy at the log located at C:\fixwareout\report.txt

After you get the fixwareout log posted go to msconfig>startup tab and check all the items there untill we get you clean. Then post a new HT log.



0

Response Number 8
Name: furiousxazn
Date: May 14, 2006 at 02:23:03 Pacific
Reply:

i have unspypc UNchecked on the startup tabs... you want me to check it? it'll run again won't it


0

Response Number 9
Name: furiousxazn
Date: May 14, 2006 at 02:24:20 Pacific
Reply:

here's the report from fixwareout

Fixwareout ver 1.003
Last edited 04/26/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\32refaselif
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B381A928EFD7-C849-0CE4-7809-B33EA4E9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\rdemd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\32refaselif
...

Microsoft (R) Windows Script Host Version 5.6
Random Runs removed from HKLM
"dmedr.exe"=-
...

PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Example ipsec6.exe is lagitamate

»»»»» Search by size and names...
* csr.exe C:\WINDOWS\System32\CSJLD.exe

»»»»» Misc files

»»»»» Checking for older varients covered by the Rem3 tool

»»»»»
Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\CSJLD.exe 51,237 2006-05-13
C:\WINDOWS\SYSTEM32\DMEDR.exe 61,998 2004-08-03


And here is new hijack this log (without checking unspypc)


Logfile of HijackThis v1.99.1
Scan saved at 2:21:40 AM, on 5/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\NOTEPAD.exe
C:\WINDOWS\SOUNDMAN.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\Documents and Settings\will\Desktop\New Folder\HijackThis.exe

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171
O17 - HKLM\System\CCS\Services\Tcpip\..\{8092BFA6-18AA-460B-8899-399CEAC0A54F}: NameServer = 85.255.115.235 85.255.112.171
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2D6E3FA-323A-40F3-9F18-574105D52642}: NameServer = 85.255.115.235,85.255.112.171
O17 - HKLM\System\CS1\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171
O17 - HKLM\System\CS2\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



0

Response Number 10
Name: jabuck
Date: May 14, 2006 at 08:23:14 Pacific
Reply:

Yes, uncheck it also but do the following first

Please download killbox to your desktop from this link Killbox We have a file or two to delete.

Once killbox is downloaded boot into safe mode.

To do so restart your computer

After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;

Instead of Windows loading as normal, a menu with options should appear;

Select the first option, to run Windows in Safe Mode, then press "Enter".

Choose your usual account.

Start Killbox place a tick next to [x]Delete on reboot "Press the All Files button"
Copy this whole list into the windows clipboard, all the bolded file paths below. Copy the following list of files to clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\SYSTEM32\DMEDR.exe

C:\WINDOWS\SYSTEM32\CSJLD.exe

Next in Killbox go to File > Paste from clipboard
"Click on the All Files button."
Next click on the button that has the red circle with the white X in the middle.
It will ask for confimation to delete the files on next reboot and ask you if you want to reboot now.
Click Yes and let the computer reboot.

Now post new HT log with all item in msconfig/startup tab checked.


0

Response Number 11
Name: furiousxazn
Date: May 14, 2006 at 23:19:34 Pacific
Reply:

Here it is
did everything you asked. here is the hijack this log


Logfile of HijackThis v1.99.1
Scan saved at 11:17:34 PM, on 5/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\will\Desktop\New Folder\HijackThis.exe

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171
O17 - HKLM\System\CCS\Services\Tcpip\..\{8092BFA6-18AA-460B-8899-399CEAC0A54F}: NameServer = 85.255.115.235 85.255.112.171
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2D6E3FA-323A-40F3-9F18-574105D52642}: NameServer = 85.255.115.235,85.255.112.171
O17 - HKLM\System\CS1\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171
O17 - HKLM\System\CS2\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



0

Response Number 12
Name: jabuck
Date: May 15, 2006 at 03:24:43 Pacific
Reply:

You need to update your java to the newest 1.5 version.

Run HT again, close all windows and browsers except HT, place a check to the left of the following iyems and press "fix checked":

O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"

O17 - HKLM\System\CCS\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171

O17 - HKLM\System\CCS\Services\Tcpip\..\{8092BFA6-18AA-460B-8899-399CEAC0A54F}: NameServer = 85.255.115.235 85.255.112.171

O17 - HKLM\System\CCS\Services\Tcpip\..\{C2D6E3FA-323A-40F3-9F18-574105D52642}: NameServer = 85.255.115.235,85.255.112.171

O17 - HKLM\System\CS1\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171

O17 - HKLM\System\CS2\Services\Tcpip\..\{40692D7D-3447-4A99-922D-2BF0B1F0EE9F}: NameServer = 85.255.115.235,85.255.112.171

THen post a new HT log



0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: UnspyPC help!

UnSpyPC infection www.computing.net/answers/security/unspypc-infection/17821.html

UnSpyPC problem - Help! www.computing.net/answers/security/unspypc-problem-help/17460.html

UnSpyPc infection www.computing.net/answers/security/unspypc-infection/17228.html