Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: Spyware/ Torjan Attack... Again

  1. #1
    Smith's Avatar Since 1989.. BT Rep: +1
    Join Date
    Jun 2003
    Location
    in a plane, high as fuck
    Posts
    5,538
    holy shit, ive done it again. ive got another spyware attack, but this time i think i got a virus, and i cant get rid of it.

    ive run spybot s&d over and over again, but it keeps comming back. my borwser keeps getting hijacked, and just when i think ive gotten rid of it it comes back. plus ive got all this stuff that keeps appearing on my desktop. AND, the same 3 virusus keep comming back when i run AVG vrisu skan 6 free edition.

    heres some screenies, help me oput ppl, i dunn wana have 2 format again


    i know the DAP ones r fine , their just banners. its the "bookedspace" one that keeps comming back.

    Image Resized
    http://server6.uploadit.org/files/thecanuk-spyware1.jpg' width='200' height='120' border='0' alt='click for full size view'></a>


    the files that keep comming back, theres usually more, but theres just 2 this time.

    Image Resized
    [img]http://server6.uploadit.org/files/thecanuk-spyware2.jpg' width='200' height='120' border='0' alt='click for full size view'>

  2. Software & Hardware   -   #2
    Poster
    Join Date
    Aug 2003
    Location
    Burmoda triangle, right behind you!
    Posts
    564
    If you have win xp. Disable system restore, because that&#39;s how it&#39;s coming back. Now update your antivirus immedeately and restart your computer with and disable any programs running in the system tray. scan and delete everything. Also, get adaware, because SB S&D does not get everything.
    Click the longhorn icon to visit my website.
    <span style='color:blue'><span style='font-size:8pt;line-height:100%'> You try Everything in my/our post(s) at YOUR own risk. I/we do not take responsibily for damages, caused by the post(s). Clicking on/or modifying anything in here is not permitted. Whoever edits my sig is a pussy.</span></span>

    ::::::::::::::::::::::::::::::::::::::::

  3. Software & Hardware   -   #3

  4. Software & Hardware   -   #4
    Smith's Avatar Since 1989.. BT Rep: +1
    Join Date
    Jun 2003
    Location
    in a plane, high as fuck
    Posts
    5,538
    grr, manually removing it looks like a bitch, and i dunn have norton or anything like that.

    well, i guess the only easy awnser is reformatting, b4 i do, is their anything else i should try?

  5. Software & Hardware   -   #5
    Smith's Avatar Since 1989.. BT Rep: +1
    Join Date
    Jun 2003
    Location
    in a plane, high as fuck
    Posts
    5,538
    well someone told me 2 run this hijack thiss program so i did and heres the log. u guys see anything i should worrie about?




    Logfile of HijackThis v1.97.7
    Scan saved at 4:33:18 PM, on 3/18/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:&#092;WINDOWS&#092;SYSTEM&#092;KERNEL32.DLL
    C:&#092;WINDOWS&#092;SYSTEM&#092;MSGSRV32.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;MPREXE.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;MSTASK.EXE
    C:&#092;PROGRAM FILES&#092;GRISOFT&#092;AVG6&#092;AVGSERV9.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;mmtask.tsk
    C:&#092;WINDOWS&#092;EXPLORER.EXE
    C:&#092;WINDOWS&#092;TASKMON.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;SYSTRAY.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;LXSUPMON.EXE
    C:&#092;IMAGEMATE COMPACTFLASH USB&#092;SANDICON.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;LVCOMS.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;LEXBCES.EXE
    C:&#092;PROGRAM FILES&#092;CREATIVE&#092;SHAREDLL&#092;CTNOTIFY.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;SPOOL32.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;RPCSS.EXE
    C:&#092;WINDOWS&#092;LOADQM.EXE
    C:&#092;PROGRAM FILES&#092;GRISOFT&#092;AVG6&#092;AVGCC32.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;WMIEXE.EXE
    C:&#092;PROGRAM FILES&#092;CREATIVE&#092;SHAREDLL&#092;MEDIADET.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;DDHELP.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;LEXPPS.EXE
    C:&#092;PROGRAM FILES&#092;MSN MESSENGER&#092;MSNMSGR.EXE
    C:&#092;PROGRAM FILES&#092;INTERNET EXPLORER&#092;IEXPLORE.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;PSTORES.EXE
    C:&#092;PROGRAM FILES&#092;WINRAR&#092;WINRAR.EXE
    C:&#092;WINDOWS&#092;TEMP&#092;RAR&#036;EX00.547&#092;HIJACKTHIS.EXE

    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http://server224.smartbotpro.net/7search/?hkcu
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = http://searchcentral.cc/index.php?v=4&aff=4474
    R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http://www.google.ca/
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = about:blank
    R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http://default-homepage-network.com/start.cgi?hklm
    R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http://server224.smartbotpro.net/7search/?hklm
    R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = about:blank
    R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = about:blank
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;SearchURL,(Default) = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: NavErrRedir Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:&#092;PROGRA~1&#092;INCRED~1&#092;BHO&#092;INCFIN~1.DLL (file missing)
    O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:&#092;PROGRAM FILES&#092;PANICWARE&#092;POP-UP STOPPER COMPANION&#092;CCHELPER.DLL
    O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
    O2 - BHO: (no name) - {00000EF1-0786-4633-87C6-1AA7A44296DA} - (no file)
    O2 - BHO: Clear Search - {00000000-0000-0000-0000-000000000240} - C:&#092;PROGRAM FILES&#092;CLEARSEARCH&#092;IE_CLRSCH.DLL (file missing)
    O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - (no file)
    O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:&#092;WINDOWS&#092;SYSTEM&#092;MSDXM.OCX
    O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-D1F0-E56FA787AD2D} - C:&#092;PROGRA~1&#092;POWERS~1&#092;TOOLBAR&#092;PWRSCZNC.DLL (file missing)
    O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:&#092;PROGRAM FILES&#092;PANICWARE&#092;POP-UP STOPPER COMPANION&#092;POPUPUS.DLL
    O4 - HKLM&#092;..&#092;Run: [ScanRegistry] C:&#092;WINDOWS&#092;scanregw.exe /autorun
    O4 - HKLM&#092;..&#092;Run: [TaskMonitor] C:&#092;WINDOWS&#092;taskmon.exe
    O4 - HKLM&#092;..&#092;Run: [SystemTray] SysTray.Exe
    O4 - HKLM&#092;..&#092;Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM&#092;..&#092;Run: [LexStart] Lexstart.exe
    O4 - HKLM&#092;..&#092;Run: [LXSUPMON] C:&#092;WINDOWS&#092;SYSTEM&#092;LXSUPMON.EXE RUN
    O4 - HKLM&#092;..&#092;Run: [SandIcon] C:&#092;ImageMate CompactFlash USB&#092;SandIcon.Exe
    O4 - HKLM&#092;..&#092;Run: [DXM6Patch_981116] C:&#092;WINDOWS&#092;p_981116.exe /Q:A
    O4 - HKLM&#092;..&#092;Run: [LVComs] C:&#092;WINDOWS&#092;SYSTEM&#092;LVComS.exe
    O4 - HKLM&#092;..&#092;Run: [Disc Detector] C:&#092;Program Files&#092;Creative&#092;ShareDLL&#092;CtNotify.exe
    O4 - HKLM&#092;..&#092;Run: [NvCplDaemon] RUNDLL32.EXE C:&#092;WINDOWS&#092;SYSTEM&#092;NvCpl.dll,NvStartup
    O4 - HKLM&#092;..&#092;Run: [nwiz] nwiz.exe /install
    O4 - HKLM&#092;..&#092;Run: [system32] C:&#092;WINDOWS&#092;SYSTEM&#092;system32.exe
    O4 - HKLM&#092;..&#092;Run: [LoadQM] loadqm.exe
    O4 - HKLM&#092;..&#092;Run: [PCDRealtime] C:&#092;WINDOWS&#092;realtime.exe
    O4 - HKLM&#092;..&#092;Run: [QuickTime Task] "C:&#092;WINDOWS&#092;SYSTEM&#092;QTTASK.EXE" -atboottime
    O4 - HKLM&#092;..&#092;Run: [MyWebSearch Email Plugin] C:&#092;PROGRA~1&#092;MYWAY&#092;BAR&#092;1.BIN&#092;MWSOEMON.EXE
    O4 - HKLM&#092;..&#092;Run: [RUBEH] C:&#092;WINDOWS&#092;RUBEH.exe
    O4 - HKLM&#092;..&#092;Run: [NSTSCHI] C:&#092;WINDOWS&#092;SYSTEM&#092;NSTSCHI.exe
    O4 - HKLM&#092;..&#092;Run: [AVG_CC] C:&#092;PROGRAM FILES&#092;GRISOFT&#092;AVG6&#092;avgcc32.exe /startup
    O4 - HKLM&#092;..&#092;RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM&#092;..&#092;RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM&#092;..&#092;RunServices: [Avgserv9.exe] C:&#092;PROGRA~1&#092;GRISOFT&#092;AVG6&#092;Avgserv9.exe
    O4 - HKCU&#092;..&#092;Run: [MsnMsgr] "C:&#092;Program Files&#092;MSN Messenger&#092;MsnMsgr.Exe" /background
    O4 - HKCU&#092;..&#092;Run: [Brrc] C:&#092;WINDOWS&#092;Application Data&#092;uutp.exe
    O4 - HKCU&#092;..&#092;Run: [WCPT] C:&#092;WINDOWS&#092;SYSTEM&#092;wintsvtr.exe
    O4 - Startup: Adobe Gamma Loader.lnk = C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Calibration&#092;Adobe Gamma Loader.exe
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Startup: Microsoft Office.lnk = C:&#092;Program Files&#092;Microsoft Office&#092;Office10&#092;OSA.EXE
    O8 - Extra context menu item: &Download with &DAP - C:&#092;PROGRA~1&#092;DAP&#092;dapextie.htm
    O8 - Extra context menu item: Download &all with DAP - C:&#092;PROGRA~1&#092;DAP&#092;dapextie2.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~1&#092;MICROS~2&#092;OFFICE10&#092;EXCEL.EXE/3000
    O9 - Extra button: Related (HKLM)
    O9 - Extra &#39;Tools&#39; menuitem: Show &Related Links (HKLM)
    O9 - Extra &#39;Tools&#39; menuitem: Sun Java Console (HKLM)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.6.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cab
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...8030.8092476852
    O16 - DPF: DigiChat Applet - http://host3.digichat.com/DigiChat/D.../Client_IE.cab
    O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...reShowdown.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {91413D86-9F27-402C-B5E3-DEBDD122C339} - http://content2.netvenda.com/sites/g.../ca/games1.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_41.cab

  6. Software & Hardware   -   #6
    Poster
    Join Date
    Aug 2003
    Location
    Burmoda triangle, right behind you!
    Posts
    564
    YES&#33; try to calm down and use acceptable langugage.
    Click the longhorn icon to visit my website.
    <span style='color:blue'><span style='font-size:8pt;line-height:100%'> You try Everything in my/our post(s) at YOUR own risk. I/we do not take responsibily for damages, caused by the post(s). Clicking on/or modifying anything in here is not permitted. Whoever edits my sig is a pussy.</span></span>

    ::::::::::::::::::::::::::::::::::::::::

  7. Software & Hardware   -   #7
    Smith's Avatar Since 1989.. BT Rep: +1
    Join Date
    Jun 2003
    Location
    in a plane, high as fuck
    Posts
    5,538
    ...ok? now wut...?

  8. Software & Hardware   -   #8
    Hi...

    You will have more help in here...
    Ad-aware 6.0 Build 181
    http://www.lavasoftsupport.com/
    P4 2.4C / 1024M / R9600XT 128M / 80GB / 400W
    Peer-to-peer Programs...

  9. Software & Hardware   -   #9
    Poster
    Join Date
    Jun 2003
    Posts
    126
    Hi,
    you have a cwsearch infection.

    download cwshredder here.

    close all browser windows and hit fix.

    reboot and post another log.

  10. Software & Hardware   -   #10
    The secret to removing it completely is keep scanning and rebooting till the infection is gone.
    P4 2.4C / 1024M / R9600XT 128M / 80GB / 400W
    Peer-to-peer Programs...

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •