PDA

View Full Version : It Just Will Not Die!



{%shellshock%}
07-09-2004, 05:29 PM
Image Resized
Image Resized
[img]http://img49.exs.cx/img49/8787/spy.jpg' width='200' height='120' border='0' alt='click for full size view'> (http://img49.exs.cx/img49/8787/spy.jpg)
Iv try'd every spyware removel i can think of.The only thing that seem's to get rid of it is Hijackthis but a few day's later i just come's back.Eny help please.

[B][O][T]
07-09-2004, 05:35 PM
Use the search....there's lots of topics about this.
And don't use IE :rolleyes: :rolleyes:

BOT

{%shellshock%}
07-09-2004, 05:40 PM
Thanks for your help. :)

sparsely
07-09-2004, 05:59 PM
Originally posted by [B
[O][T],9 July 2004 - 12:43]Use the search....there's lots of topics about this.
And don't use IE  :rolleyes:  :rolleyes:

BOT
FIREFOOOOOOXXXXXXXXXX!!!!!!!

:D

Ariel_001
07-09-2004, 06:22 PM
Originally posted by {%shellshock%}@9 July 2004 - 13:37
Image Resized
Image Resized
<a href=&#39;http://img49.exs.cx/img49/8787/spy.jpg&#39; (http://img49.exs.cx/img49/8787/spy.jpg) target=&#39;image&#39;>Image Resized
Image Resized
[img]http://img49.exs.cx/img49/8787/spy.jpg' width='200' height='120' border='0' alt='click for full size view'> (http://img49.exs.cx/img49/8787/spy.jpg)</a>
Iv try&#39;d every spyware removel i can think of.The only thing that seem&#39;s to get rid of it is Hijackthis but a few day&#39;s later i just come&#39;s back.Eny help please.
ok..

I beleve Hijackthis has the option to show a log of your computer`s state of something like that. Can you post it?

{%shellshock%}
07-09-2004, 07:55 PM
Logfile of HijackThis v1.97.7
Scan saved at 12:06:12 PM, on 7/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:&#092;WINDOWS&#092;System32&#092;smss.exe
C:&#092;WINDOWS&#092;system32&#092;winlogon.exe
C:&#092;WINDOWS&#092;system32&#092;services.exe
C:&#092;WINDOWS&#092;system32&#092;lsass.exe
C:&#092;WINDOWS&#092;system32&#092;svchost.exe
C:&#092;WINDOWS&#092;System32&#092;svchost.exe
C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccSetMgr.exe
C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccEvtMgr.exe
C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe
C:&#092;Program Files&#092;Executive Software&#092;Diskeeper&#092;DkService.exe
C:&#092;Program Files&#092;Norton AntiVirus&#092;navapsvc.exe
C:&#092;WINDOWS&#092;System32&#092;nvsvc32.exe
C:&#092;Program Files&#092;Norton AntiVirus&#092;SAVScan.exe
C:&#092;WINDOWS&#092;system32&#092;slserv.exe
C:&#092;WINDOWS&#092;wanmpsvc.exe
C:&#092;WINDOWS&#092;System32&#092;MsPMSPSv.exe
C:&#092;WINDOWS&#092;Explorer.EXE
C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe
C:&#092;Documents and Settings&#092;robert&#092;Desktop&#092;Files&#092;Hold&#092;Hijack&#092;HijackThis.exe

R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = file://C:&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = file://C:&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file://C:&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = file://C:&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = file://C:&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file://C:&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {9964B2EF-BEA6-4B88-940D-A27310F9BF3B} - C:&#092;WINDOWS&#092;System32&#092;pcl.dll
O9 - Extra button: Related (HKLM)
O9 - Extra &#39;Tools&#39; menuitem: Show &Related Links (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/shock...ash/swflash.cab (http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab)

Ariel_001
07-10-2004, 10:45 AM
Ok there are some thing that would worry me for sure.....



R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = file&#58;//C&#58;&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = file&#58;//C&#58;&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file&#58;//C&#58;&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = file&#58;//C&#58;&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = file&#58;//C&#58;&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file&#58;//C&#58;&#092;DOCUME~1&#092;robert&#092;LOCALS~1&#092;Temp&#092;sp.html

All that points to your %temp% folder and is all the same file. Delete it

Also this would worry me...


BHO&#58; &#40;no name&#41; - {9964B2EF-BEA6-4B88-940D-A27310F9BF3B} - C&#58;&#092;WINDOWS&#092;System32&#092;pcl.dll

Rastapopoulos
07-10-2004, 12:18 PM
Yes what Ariel said, delete them all.

muchspl2
07-10-2004, 12:57 PM
http://members.cox.net/ot_space/spyware.jpg

[B][O][T]
07-10-2004, 01:29 PM
:rolleyes: lol yeah, it&#39;s getting more and more common now....

Use Firefox and You&#39;ll be safe :)

BOT

{%shellshock%}
07-10-2004, 03:47 PM
Alright im going to use firefox from now no.this browser just get&#39;s hijacked too much.Thanks for your help :)

[B][O][T]
07-10-2004, 04:04 PM
:beerchug: congrats :)

BOT

Ariel_001
07-10-2004, 04:23 PM
Originally posted by muchspl2@10 July 2004 - 09:05
http://members.cox.net/ot_space/spyware.jpg
OMG. This is what happends when you click yes to every Activex install question.

If you did that I am afraid no browser can help you. (spyware attacks firefox too).

{%shellshock%}
07-10-2004, 04:40 PM
Originally posted by muchspl2@10 July 2004 - 13:05
http://members.cox.net/ot_space/spyware.jpg
:lol: :lol: :lol:

muchspl2
07-10-2004, 09:02 PM
try to do a search, all the tool bars have a fight for the re-direct