Announcement

Collapse
No announcement yet.

Comp trouble: Spyware infestation

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Comp trouble: Spyware infestation



    I've got some silly spyware infestation, that blasts me with ads in IE windows (I don't use IE for browsing), and popups prompting me to download errorsafe. I thought maybe someone here could help me if I post my HijackThis log:

    Logfile of HijackThis v1.99.1
    Scan saved at 08:21:59, on 2006-05-11
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program\NVIDIA~1\NETWOR~1\bin\nTrayFw.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program\D-Tools\daemon.exe
    C:\Program\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program\Winamp\winampa.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program\iTunes\iTunesHelper.exe
    C:\Program\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\Program\QuickTime\qttask.exe
    C:\Program\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\SCURIT~1\csrss.exe
    C:\Program\WIDCOMM\Bluetooth-programvara\bin\btwdins.exe
    C:\Program\F?nts\s?ool32.exe
    C:\Program\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
    C:\Program\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
    C:\Program\WIDCOMM\Bluetooth-programvara\BTTray.exe
    C:\Program\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
    C:\Program\Mozilla Firefox\firefox.exe
    C:\Program\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
    C:\Program\Winamp\winamp.exe
    C:\Program\iPod\bin\iPodService.exe
    C:\Program\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    C:\Program\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.5.0_06\bin\ssv.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [nTrayFw] C:\Program\NVIDIA~1\NETWOR~1\bin\nTrayFw.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AVG7_CC] C:\Program\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\Program\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program\Winamp\winampa.exe
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
    O4 - HKLM\..\RunOnce: [Execute] C:\WINDOWS\System32\Tools\DelFolders.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Asep] "C:\WINDOWS\SCURIT~1\csrss.exe" -vt yazb
    O4 - HKCU\..\Run: [Hkztv] C:\Program\F?nts\s?ool32.exe
    O4 - Startup: Reboot.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: BTTray.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O23 - Service: app_filter - Unknown owner - C:\Program\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Program\WIDCOMM\Bluetooth-programvara\bin\btwdins.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program\iPod\bin\iPodService.exe
    O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - Unknown owner - C:\Program\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    Why can't you be a non-conformist just like everybody else?

    It's no good (from an evolutionary point of view) to have the physique of Tarzan if you have the sex drive of a philosopher. -- Michael Ruse
    The Nedaverse I can accept, but not the Berzaverse. There can only be so many alternate realities. -- Elok

  • #2
    Yeah, sounds like you have spyware.
    “As a lifelong member of the Columbia Business School community, I adhere to the principles of truth, integrity, and respect. I will not lie, cheat, steal, or tolerate those who do.”
    "Capitalism ho!"

    Comment


    • #3
      I pretty sure you already did that but....

      Did you try to scan you cpu with AVG and AdAware?

      Without any further investigation I dont see any strange processes
      bleh

      Comment


      • #4
        Wich processes?
        or services?

        Originally posted by DaShi
        Yeah, sounds like you have spyware.
        bleh

        Comment


        • #5
          RUNDLL32.EXE ?

          Maybe this exe run another undesired processes:
          bleh

          Comment


          • #6
            Originally posted by cronos_qc
            I pretty sure you already did that but....

            Did you try to scan you cpu with AVG and AdAware?
            Yes I did. Found nothing.
            Why can't you be a non-conformist just like everybody else?

            It's no good (from an evolutionary point of view) to have the physique of Tarzan if you have the sex drive of a philosopher. -- Michael Ruse
            The Nedaverse I can accept, but not the Berzaverse. There can only be so many alternate realities. -- Elok

            Comment


            • #7
              Rundll32 is running two times...
              bleh

              Comment


              • #8
                Originally posted by cronos_qc
                Wich processes?
                or services?
                I don't know, it just sounds like spyware.



                Anyway, Adaware hasn't been updated since forever. Try spyware doctor or something more recent.
                “As a lifelong member of the Columbia Business School community, I adhere to the principles of truth, integrity, and respect. I will not lie, cheat, steal, or tolerate those who do.”
                "Capitalism ho!"

                Comment


                • #9
                  If The csrss.exe file is located in the C:\Windows\System32 folder. In other cases, csrss.exe is a virus, spyware, trojan or worm!
                  bleh

                  Comment


                  • #10
                    At first glance, these look suspicious.

                    C:\Program\F?nts\s?ool32.exe
                    O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
                    O4 - HKCU\..\Run: [Asep] "C:\WINDOWS\SCURIT~1\csrss.exe" -vt yazb
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_06\bin\ssv.dll
                    Also, all those programs with unknown owner are also suspicious.
                    (\__/) 07/07/1937 - Never forget
                    (='.'=) "Claims demand evidence; extraordinary claims demand extraordinary evidence." -- Carl Sagan
                    (")_(") "Starting the fire from within."

                    Comment


                    • #11
                      Good resume UR

                      But:
                      "C:\Program\Java\jre1.5.0_06\bin\ssv.dll"

                      I'm not sure about this one!
                      bleh

                      Comment


                      • #12
                        C:\Program\Java\jre1.5.0_06\bin\ssv.dll
                        This website is for sale! hijackfree.com is your first and best source for all of the information you’re looking for. From general topics to more of what you would expect to find here, hijackfree.com has it all. We hope you find what you are searching for!


                        Edit:
                        These three are clearly malware!

                        C:\Program\F?nts\s?ool32.exe ~ - This files is supposed to be into the system folder.

                        O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe" ~- Survey??? Ads and sh*t

                        O4 - HKCU\..\Run: [Asep] "C:\WINDOWS\SCURIT~1\csrss.exe" -vt yazb
                        - Read the link I sended to you.
                        bleh

                        Comment


                        • #13
                          @cronos: The only csrss.exe file I've got is the System32 one, but I do have a file called CSRSS.EXE-1F980EC0.pf

                          @UR: I'll look at those. Thanks.
                          Why can't you be a non-conformist just like everybody else?

                          It's no good (from an evolutionary point of view) to have the physique of Tarzan if you have the sex drive of a philosopher. -- Michael Ruse
                          The Nedaverse I can accept, but not the Berzaverse. There can only be so many alternate realities. -- Elok

                          Comment


                          • #14
                            Originally posted by cronos_qc

                            C:\Program\F?nts\s?ool32.exe ~ - This files is supposed to be into the system folder.

                            O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe" ~- Survey??? Ads and sh*t

                            O4 - HKCU\..\Run: [Asep] "C:\WINDOWS\SCURIT~1\csrss.exe" -vt yazb
                            Okay, I removed those. Should I deled the spool32.exe in Fonts?
                            Why can't you be a non-conformist just like everybody else?

                            It's no good (from an evolutionary point of view) to have the physique of Tarzan if you have the sex drive of a philosopher. -- Michael Ruse
                            The Nedaverse I can accept, but not the Berzaverse. There can only be so many alternate realities. -- Elok

                            Comment


                            • #15
                              Last Conformist:
                              ... wait, i'll try to look into google
                              bleh

                              Comment

                              Working...
                              X