The new forums will be named Coin Return (based on the most recent vote)! You can check on the status and timeline of the transition to the new forums here.
The Guiding Principles and New Rules document is now in effect.

I Need Some Computer Help

ScrumtrulescentScrumtrulescent Registered User regular
edited July 2007 in Games and Technology
Okay, here's my problem:

My computer, whilst I am browsing the internet, always gives me Internet Explorer pop-ups, even while I'm in Firefox. This started out of the blue a month or so ago. I frequently run Windows Defender scans, and I almost always have numerous viruses with the "Severe" threat level. I remove them. But the problem persists. I'm afraid I may have to completely wipe my computer. What can I do?

Edit: It is also worth mentioning that at times, it gives me so many popups at once, I cannot even turn off my computer. it will just keep cranking them out, and I must use a "button" shutdown.

Scrumtrulescent on
«1

Posts

  • RohanRohan Registered User regular
    edited July 2007
    Are you using any anti-virus program? Download AVG Free or Avast! Home (I use the latter) and do a memory scan. Avast! will also check all of your startup items, and upon installation will ask you to restart and if you want it to scan your hard drive when Windows boots. Let it do so, and see what it finds, and if the problem perseveres.

    Edit - Windows Defender is not a substitute for a real anti-virus program.

    Rohan on
    ...and I thought of how all those people died, and what a good death that is. That nobody can blame you for it, because everyone else died along with you, and it is the fault of none, save those who did the killing.

    Nothing's forgotten, nothing is ever forgotten
  • KoekjesKoekjes Registered User regular
    edited July 2007
    It sounds like you have some sort of advertising trojan. I doubt an anti-virus program is going to get rid of it. Try Spybot Search and Destroy at http://www.safer-networking.org/.

    Did you install any shareware anything else new recently? If so, that program may be the source of your problem.

    Do you download anything from peer-to-peer networks? If you do what ever the last thing was may be your problem. You really need to scan everything downloaded from those systems.

    Koekjes on
  • RaereRaere Registered User regular
    edited July 2007
    Use Ad-Aware in addition to Spybot mentioned above. They should catch most of it. When you're done, run HijackThis and post the log it spits out. Don't do anything with it; it will basically tell us if there's any spyware left on the system.

    Raere on
    Raere.png
  • SorensonSorenson Registered User regular
    edited July 2007
    Raere wrote: »
    Use Ad-Aware in addition to Spybot mentioned above. They should catch most of it. When you're done, run HijackThis and post the log it spits out. Don't do anything with it; it will basically tell us if there's any spyware left on the system.
    Wasn't there some big hubbub about a year or two back where someone allegedly found that Ad-Aware was actually linked to a whole bunch of advertisers or something like that?

    Anyway, I use a combo of Spybot and Symantec Security for my PC, and the only ads I ever get are usually page-embedded, so that setup might be worth checking out.

    Sorenson on
  • MajorDodoMajorDodo Registered User regular
    edited July 2007
    I use Adaware and E-Trust antivirus. myself, although i dont exactly need a high level of security since i only go to a select few sites all the time.

    MajorDodo on
    Baranoth's Diary: Woke up this morning. Killed 7 gnomes. Proceeded to brush teeth.
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    is the Avast Home free? It says so, but I want to make sure that I don't need to buy it to get the full protection.

    Scrumtrulescent on
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    Sorenson wrote: »
    Raere wrote: »
    Use Ad-Aware in addition to Spybot mentioned above. They should catch most of it. When you're done, run HijackThis and post the log it spits out. Don't do anything with it; it will basically tell us if there's any spyware left on the system.
    Wasn't there some big hubbub about a year or two back where someone allegedly found that Ad-Aware was actually linked to a whole bunch of advertisers or something like that?

    Yes, but no one really cares it seems. :(

    Run HiJack This, and post the log it prints out for us to look at.

    urahonky on
  • TzenTzen Registered User regular
    edited July 2007
    In addition to Ad-Aware and Spybot, I would suggest downloading the trial for Prevx. It seems to knock out the nasties that the other two miss. Even though it's just a trial, I've never had any problem just installing it multiple times when I need to use it.

    Tzen on
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    How, exactly, do I post the log? I haven't gotten it yet, but I'm unzipping the folder now.

    Scrumtrulescent on
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    How, exactly, do I post the log? I haven't gotten it yet, but I'm unzipping the folder now.

    It allows you to create a log, and it opens a notepad then pastes everything there. Then you copy and paste it into the chat box.

    urahonky on
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    Alright, got it, I just want to make sure this isn't going to like, give away any info.

    Scrumtrulescent on
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    Alright here it is:
    Logfile of HijackThis v1.99.1
    Scan saved at 3:43:48 PM, on 7/9/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Microsoft Hardware\Mouse\point32.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\AIM6\aim6.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Web Buying\v1.7.4\webbuying.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\Program Files\WiFiConnector\NintendoWFCReg.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
    C:\WINNT\system32\slserv.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINNT\wanmpsvc.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINNT\system32\wscntfy.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINNT\System32\svchost.exe
    c:\program files\aim6\anotify.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - Default URLSearchHook is missing
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [POINTER] point32.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [wcmdmgr] C:\WINNT\wt\updater\wcmdmgrl.exe -launch
    O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINNT\system32\rhrgfgug.dll",forkonce
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.7.4\webbuying.exe
    O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra button: Print Using ClickBook - {180E1E16-F536-4B51-9723-6025D98AA375} - C:\Program Files\Blue Squirrel\ClickBook\macros\ieprint.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {040F4385-8DAD-4306-94BF-B8291D841FAE} (USBAPTester Class) - http://www.nintendowifi.com/troubleshooting/usbaptest.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
    O16 - DPF: {77538FC7-CE52-4704-9865-494FE92BC320} (LaunchUBO.Ulit) - http://www.ultimatebaseballonline.com/myubo/launchubo.OCX
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: DomainService - Unknown owner - C:\WINNT\system32\gkvmiymk.exe (file missing)
    O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINNT\SYSTEM32\slserv.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe

    Scrumtrulescent on
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    I see webbuying.exe, sounds bad.

    Also, try to stick with only one anti-virus at a time. More than one hinders performance on your computer, and may end up locking it.

    urahonky on
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    So I Check the box next to whatever you guys tell me, and fix them?

    I also want to get rid of the Ultimate Baseball Online thing, even though it isn't a virus. So do I just check that?

    Scrumtrulescent on
  • gneGnegneGne Registered User regular
    edited July 2007
    You should not keep more than 1 anti-virus program running at a time.

    gneGne on
    pasigcopyox6.jpg
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    Avast isn't running right now. I stopped it.

    Scrumtrulescent on
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    Uh...I can't find webbuying.exe on the checklist

    stupid computers and their moon language

    learn english, you damned machines!

    Scrumtrulescent on
  • VoroVoro Registered User regular
    edited July 2007
    C:\Program Files\Web Buying\v1.7.4\webbuying.exe

    O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINNT\system32\rhrgfgug.dll",forkonce
    O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.7.4\webbuying.exe

    I don't have the time to run all of them through a search engine right now, but those seem like the obviously bad ones.

    Edit: Actually...well, rhrgfgug.dll doesn't show up on any search engines, but then I also don't have icq...I'd regard it with extreme caution.

    Voro on
    XBL GamerTag: Comrade Nexus
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    Alright, I deleted those last two. I'll post if the problem is fixed or not.

    Scrumtrulescent on
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    Yeah, just got a popup. Less frequent now, but still happening I guess.

    Scrumtrulescent on
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    Scrum I'll look at it when I get home. Sorry, I was typing more but I am at work... and actually need to do something :P

    As soon as I get home in about an hour, I'll take a look at it for you, okay?

    urahonky on
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    Thanks a lot. I don't think this is doing anything super bad, but it annoys me to no end to have to close a pop up every five minutes.

    Scrumtrulescent on
  • cfgausscfgauss Registered User regular
    edited July 2007
    stupid computers and their moon language

    learn english, you damned machines!

    Damned foreigners! Get out of my country!

    But really, it is advantageous to know what's going on if you want to prevent this from happening again.

    cfgauss on
    The hero and protagonist, whose story the book follows, is the aptly-named Hiro Protagonist: "Last of the freelance hackers and Greatest sword fighter in the world." When Hiro loses his job as a pizza delivery driver for the Mafia, he meets a streetwise young girl nicknamed Y.T. (short for Yours Truly), who works as a skateboard "Kourier", and they decide to become partners in the intelligence business.
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    Yeah no problem. I know how it feels... *glances again while I have a break*

    O4 - HKLM\..\Run: [wcmdmgr] C:\WINNT\wt\updater\wcmdmgrl.exe -launch
    O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.7.4\webbuying.exe
    O23 - Service: DomainService - Unknown owner - C:\WINNT\system32\gkvmiymk.exe (file missing)
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    Try checking those, and clicking FIX at the bottom. Then restart. Those seem pretty redundant.

    urahonky on
  • darunia106darunia106 J-bob in games Death MountainRegistered User regular
    edited July 2007
    That's funny... I have the exact same problem that he does.

    Is it alright if I run HijackThis and post the results here?

    darunia106 on
    pHWHd2G.jpg
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    darunia106 wrote: »
    That's funny... I have the exact same problem that he does.

    Is it alright if I run HijackThis and post the results here?

    Go for it, maybe we can see some similarities

    urahonky on
  • darunia106darunia106 J-bob in games Death MountainRegistered User regular
    edited July 2007
    urahonky wrote: »
    darunia106 wrote: »
    That's funny... I have the exact same problem that he does.

    Is it alright if I run HijackThis and post the results here?

    Go for it, maybe we can see some similarities

    Sweet. Already ran Ad-aware and I'm downloading Spybot now.

    darunia106 on
    pHWHd2G.jpg
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    urahonky wrote: »
    Yeah no problem. I know how it feels... *glances again while I have a break*

    O4 - HKLM\..\Run: [wcmdmgr] C:\WINNT\wt\updater\wcmdmgrl.exe -launch
    O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.7.4\webbuying.exe
    O23 - Service: DomainService - Unknown owner - C:\WINNT\system32\gkvmiymk.exe (file missing)
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    Try checking those, and clicking FIX at the bottom. Then restart. Those seem pretty redundant.

    Let me know if that helps scrum... If not, we'll start disabling a lot more of that unnecessary CANON software and Epson software.

    urahonky on
  • darunia106darunia106 J-bob in games Death MountainRegistered User regular
    edited July 2007
    Huh, when I open that HijackThis download link in Firefox, the whole program closes all on its own. And when I try to download it in IE, it's as if the computer presses the cancel button for me when I'm trying to save it.

    EDIT: Managed to download it but now my computer won't let me run the program. It shows the first screen for a few seconds then closes it. Help?

    EDITEDIT: Never mind, got it to run a scan and save a .log but couldn't keep it open for more than a second without it automatically closing. Is there a MS program I'm unaware of that prevents programs and files with certain keywords from working?

    darunia106 on
    pHWHd2G.jpg
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    darunia106 wrote: »
    Huh, when I open that HijackThis download link in Firefox, the whole program closes all on its own. And when I try to download it in IE, it's as if the computer presses the cancel button for me when I'm trying to save it.

    EDIT: Managed to download it but now my computer won't let me run the program. It shows the first screen for a few seconds then closes it. Help?

    Hmmm... How knowledgeable are you on the computer?

    This is what I'd try:

    Boot into safe mode.
    Start -> Run -> msconfig
    Click on the startup tab
    Click disable all
    restart your computer

    urahonky on
  • darunia106darunia106 J-bob in games Death MountainRegistered User regular
    edited July 2007
    Here's what HijackThis came up with:
    Logfile of HijackThis v1.99.1
    Scan saved at 4:39:44 PM, on 7/9/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    c:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\D-Link\RangeBooster G WUA-2340\AirPlusCFG.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\tkzmzmlm.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\program files\steam\steam.exe
    C:\Program Files\WiFiConnector\NintendoWFCReg.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Xfire\xfire.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Documents and Settings\Compaq_Administrator\Desktop\New Folder (2)\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [D-Link RangeBooster G WUA-2340] C:\Program Files\D-Link\RangeBooster G WUA-2340\AirPlusCFG.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [ps2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - HKLM\..\Run: [tkzmzmlm.exe] C:\WINDOWS\system32\tkzmzmlm.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\gppdlked.dll",forkonce
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - c:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.3.102.cab
    O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150413555078
    O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
    O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin10USA.cab
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - c:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Unknown owner - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

    darunia106 on
    pHWHd2G.jpg
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    C:\WINDOWS\system32\tkzmzmlm.exe (looks really fishy)
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKLM\..\Run: [tkzmzmlm.exe] C:\WINDOWS\system32\tkzmzmlm.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    That's all I can really see. Unless you use the google toolbar, get rid of those 4. Reboot and see if that helps.

    urahonky on
  • darunia106darunia106 J-bob in games Death MountainRegistered User regular
    edited July 2007
    urahonky wrote: »
    C:\WINDOWS\system32\tkzmzmlm.exe (looks really fishy)
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKLM\..\Run: [tkzmzmlm.exe] C:\WINDOWS\system32\tkzmzmlm.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    That's all I can really see. Unless you use the google toolbar, get rid of those 4. Reboot and see if that helps.

    Tried it, nothing much has changed. Also, most of the ad-ware and pop-ups that I'm getting seem to be anti-spyware centric. I've even got this one annoying thing in the system tray that displays a speech baloon about how I should click on it and download an anti-spyware program. I'm thinking most of those things are really trojan horses so any ideas about what i should do?

    darunia106 on
    pHWHd2G.jpg
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    darunia106 wrote: »
    urahonky wrote: »
    C:\WINDOWS\system32\tkzmzmlm.exe (looks really fishy)
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKLM\..\Run: [tkzmzmlm.exe] C:\WINDOWS\system32\tkzmzmlm.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    That's all I can really see. Unless you use the google toolbar, get rid of those 4. Reboot and see if that helps.

    Tried it, nothing much has changed. Also, most of the ad-ware and pop-ups that I'm getting seem to be anti-spyware centric. I've even got this one annoying thing in the system tray that displays a speech baloon about how I should click on it and download an anti-spyware program. I'm thinking most of those things are really trojan horses so any ideas about what i should do?

    Oh shit, yeah I remember that beast. I had a few computers in my bay with that exact same virus. Do you have a way to backup your data? The safest (and easiest route) would be to reformat your computer. It will run like new again. (I know, everyone hates doing it... but believe me, to get this virus off your computer it may take a miracle... I'd used about 5 different AV on it, and I don't think I got it off)

    You may also (before formatting) try:

    Start -> Run -> msconfig (hit enter)
    Go to the Startup Tab, and disable all.
    Restart computer

    See if it still pops up. I think it still will, but this way we can see what we're really dealing with.

    urahonky on
  • darunia106darunia106 J-bob in games Death MountainRegistered User regular
    edited July 2007
    urahonky wrote: »
    darunia106 wrote: »
    urahonky wrote: »
    C:\WINDOWS\system32\tkzmzmlm.exe (looks really fishy)
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKLM\..\Run: [tkzmzmlm.exe] C:\WINDOWS\system32\tkzmzmlm.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    That's all I can really see. Unless you use the google toolbar, get rid of those 4. Reboot and see if that helps.

    Tried it, nothing much has changed. Also, most of the ad-ware and pop-ups that I'm getting seem to be anti-spyware centric. I've even got this one annoying thing in the system tray that displays a speech baloon about how I should click on it and download an anti-spyware program. I'm thinking most of those things are really trojan horses so any ideas about what i should do?

    Oh shit, yeah I remember that beast. I had a few computers in my bay with that exact same virus. Do you have a way to backup your data? The safest (and easiest route) would be to reformat your computer. It will run like new again. (I know, everyone hates doing it... but believe me, to get this virus off your computer it may take a miracle... I'd used about 5 different AV on it, and I don't think I got it off)

    You may also (before formatting) try:

    Start -> Run -> msconfig (hit enter)
    Go to the Startup Tab, and disable all.
    Restart computer

    See if it still pops up. I think it still will, but this way we can see what we're really dealing with.

    Nothing's changed. Guess I'll have to reformat (dang).

    I'll have reformat later though. Also, I have a compaq computer, would performing a full system recovery from the hard drive be a viable option?

    darunia106 on
    pHWHd2G.jpg
  • urahonkyurahonky Cynical Old Man Registered User regular
    edited July 2007
    darunia106 wrote: »
    urahonky wrote: »
    darunia106 wrote: »
    urahonky wrote: »
    C:\WINDOWS\system32\tkzmzmlm.exe (looks really fishy)
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKLM\..\Run: [tkzmzmlm.exe] C:\WINDOWS\system32\tkzmzmlm.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    That's all I can really see. Unless you use the google toolbar, get rid of those 4. Reboot and see if that helps.

    Tried it, nothing much has changed. Also, most of the ad-ware and pop-ups that I'm getting seem to be anti-spyware centric. I've even got this one annoying thing in the system tray that displays a speech baloon about how I should click on it and download an anti-spyware program. I'm thinking most of those things are really trojan horses so any ideas about what i should do?

    Oh shit, yeah I remember that beast. I had a few computers in my bay with that exact same virus. Do you have a way to backup your data? The safest (and easiest route) would be to reformat your computer. It will run like new again. (I know, everyone hates doing it... but believe me, to get this virus off your computer it may take a miracle... I'd used about 5 different AV on it, and I don't think I got it off)

    You may also (before formatting) try:

    Start -> Run -> msconfig (hit enter)
    Go to the Startup Tab, and disable all.
    Restart computer

    See if it still pops up. I think it still will, but this way we can see what we're really dealing with.

    Nothing's changed. Guess I'll have to reformat (dang).

    I'll have reformat later though. Also, I have a compaq computer, would performing a full system recovery from the hard drive be a viable option?

    Sorry bro. It's the safest and cheapest way to get rid of that damned thing.

    Well, I'd try it first. It will make it easier on you by giving you all your drivers and stuff. But if that's infected too you'll have to format twice.

    I'd risk it, just to save yourself some time (possibly). :)

    urahonky on
  • Lars_DomusLars_Domus Registered User regular
    edited July 2007
    darunia106 wrote: »
    Nothing's changed. Guess I'll have to reformat (dang).

    I'll have reformat later though. Also, I have a compaq computer, would performing a full system recovery from the hard drive be a viable option?

    I'd recommend you visit the Spybot site's malware removal forum and ask for advice there. Those guys know how to get rid of just about anything.

    If you decide to do that, remember to be a good chap and follow the instructions in the stickies.

    Lars_Domus on
  • TzenTzen Registered User regular
    edited July 2007
    PREVX...?

    Tzen on
  • ScrumtrulescentScrumtrulescent Registered User regular
    edited July 2007
    ...Still getting pop ups. I too sometimes get those ads involving Anti-Virus programs that try to download no matter what you do.

    How do I uh...How do I reformat? I use my computer for internets only, and I have no clue what any of this means.

    Scrumtrulescent on
  • TzenTzen Registered User regular
    edited July 2007
    Look for svchost.exe in folders that it shouldn't be in. Remember to set hidden files to be shown. Check the registry under both HKLM and HKCU in software/microsoft/windows/currentversion/run and runonce for anything suspicious. Export them if you want a backup, but then delete anything suspicious.

    Ad-Aware + Spybot + Prevx + manual process/registry analysis should be able to stop anything.

    If you or any of the programs find files that can't be deleted because they're in use (some of the shit disguises itself as drivers), then either set one/all of the programs to run on startup to get it before it can start itself, or just boot into safemode and manually delete the files yourself.

    Edit: Oh. And MAKE SURE that each of the programs is updated! A lot of the nastier malware will prevent the programs from updating or even scanning, and sometimes will reboot/bluescreen your computer. Ad-Aware has a .def file you can download and place in the dir manually. If AA/SB/PX are being duped and are not able to update/scan, you're gonna have to start manually defeating the malware until you nail the ones that are pwning the apps.

    Tzen on
Sign In or Register to comment.