Results 1 to 22 of 22

Thread: Spyware..?

  1. #1

    Default Spyware..?

    Greetings everyone...

    In the last week, I've been getting an internet window opening on "www.dvdforce.com", just like a pop-up, instead it opens from windows, not an already open internet window.. I scanned using Spyware Blaster, S&D and Ad-Aware.. No luck. Any ideas?

    Regards.
    "Cry, the beloved country, for the unborn child that is the inheritor of our fear. Let him not love the earth too deeply. Let him not laugh too gladly when the water runs through his fingers, nor stand too silent when the setting sun makes red the veld with fire. Let him not be moved when the birds of his land are singing, nor give too much of his heart to a mountain or a valley. For fear will rob him of all if he gives too much."

    Cry, the Beloved Country by Alan Paton.

  2. #2

    Default Re: Spyware..?

    No idea. Tried AVG ?
    Also, did you install any software products from dvdforce lately ? This usually happens, in my experience, with not fully registered software, or similar things.
    Ya know, like reminders, popups, ads, etc.

    Alternatively, try a firewall - it should allow you to block it, and hopefully also pinpoint it.
    Do you see any extra things in your task manager ?
    I think Caravel had posted a link to some windoze site that explains what most of those do - so you can figure out the legal ones by gradually crossing them out. See what's left.
    This isn't bound to give results, though, it's possible that no extra executables appear in the task manager - but it's worth trying.
    Therapy helps, but screaming obscenities is cheaper.

  3. #3
    Cynic Senior Member sapi's Avatar
    Join Date
    Oct 2004
    Location
    Brisbane
    Posts
    4,970

    Default Re: Spyware..?

    Does it appear in msconfig's startup tab? (start>run>msconfig)

    When does it appear? On startup?

    There's a registery key that controls that iirc
    From wise men, O Lord, protect us -anon
    The death of one man is a tragedy; the death of millions, a statistic -Stalin
    We can categorically state that we have not released man-eating badgers into the area -UK military spokesman Major Mike Shearer

  4. #4
    Guest Stig's Avatar
    Join Date
    Sep 2006
    Location
    At the bar
    Posts
    4,215

    Default Re: Spyware..?

    Scan with Hijack This
    Don't delete anything yet, just post the log you get at the end here.

    I know for sure that Caravel knows what's spyware and what not. And besides that I know something of it as well (better said, I know what's not spyware)



    And install this program:
    http://www.mlin.net/StartupMonitor.shtml

    It stops all programs that start by themselves, you will have to allow them first
    Last edited by Stig; 03-03-2007 at 10:33.

  5. #5
    Cynic Senior Member sapi's Avatar
    Join Date
    Oct 2004
    Location
    Brisbane
    Posts
    4,970

    Default Re: Spyware..?

    @stig - won't startup monitor disable the av and firewall
    From wise men, O Lord, protect us -anon
    The death of one man is a tragedy; the death of millions, a statistic -Stalin
    We can categorically state that we have not released man-eating badgers into the area -UK military spokesman Major Mike Shearer

  6. #6
    Guest Stig's Avatar
    Join Date
    Sep 2006
    Location
    At the bar
    Posts
    4,215

    Default Re: Spyware..?

    Nope, it'll mostlikely give a pop-up that that programs wants to start and you simply allow it.
    I use it, and have both a firewall and AV

  7. #7

    Default Re: Spyware..?

    Nothing "extra" on the task manager nop. And it doesn't happen at start up.. Like, the PC has been on for 20 minutes, and then it comes.. It is random.

    EDIT:

    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 12:14:49 PM, on 3/3/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\MSI\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\Program Files\GizmoPlugin\GizmoPlugin.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Creative\ShareDLL\CtNotify.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\WINDOWS\wuauclt.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Fraps\FRAPS.EXE
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\MSI\Bluetooth Software\BTTray.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\Creative\ShareDLL\Mediadet.exe
    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Program Files\Hijackthis\HijackThis.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
    O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
    O4 - HKLM\..\Run: [Microsoft] C:\WINDOWS\wuauclt.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Fraps] C:\Fraps\FRAPS.EXE
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: BTTray.lnk = ?
    O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\MSI\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by21fd.bay21.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{BAB45B4A-28F4-469B-99CC-B8B4AEFAD9A4}: NameServer = 196.27.0.29,169.27.0.7
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Filter: text/html - (no CLSID) - (no file)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\MSI\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Gizmo VoIP Service (Gizmo Plugin) - SIPphone, Inc. - C:\Program Files\GizmoPlugin\GizmoPlugin.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    P.S. It's ironic to take advice from a "Drunk" :P (JK of course )
    Last edited by x-dANGEr; 03-03-2007 at 11:18.
    "Cry, the beloved country, for the unborn child that is the inheritor of our fear. Let him not love the earth too deeply. Let him not laugh too gladly when the water runs through his fingers, nor stand too silent when the setting sun makes red the veld with fire. Let him not be moved when the birds of his land are singing, nor give too much of his heart to a mountain or a valley. For fear will rob him of all if he gives too much."

    Cry, the Beloved Country by Alan Paton.

  8. #8
    Cynic Senior Member sapi's Avatar
    Join Date
    Oct 2004
    Location
    Brisbane
    Posts
    4,970

    Default Re: Spyware..?

    I don't see anything out of place, although i'm hardly an expert.
    From wise men, O Lord, protect us -anon
    The death of one man is a tragedy; the death of millions, a statistic -Stalin
    We can categorically state that we have not released man-eating badgers into the area -UK military spokesman Major Mike Shearer

  9. #9
    Honorary Argentinian Senior Member Gyroball Champion, Karts Champion Caius's Avatar
    Join Date
    Aug 2006
    Location
    I live in my home, don't you?
    Posts
    8,114

    Default Re: Spyware..?

    Quote Originally Posted by sapi
    I don't see anything out of place, although i'm hardly an expert.
    What about this

    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

    cheers




    Names, secret names
    But never in my favour
    But when all is said and done
    It's you I love

  10. #10
    Guest Stig's Avatar
    Join Date
    Sep 2006
    Location
    At the bar
    Posts
    4,215

    Default Re: Spyware..?

    No CTHELPER.exe is nothing, it's something used by Creative

    Personally I would get rid of Daemon Tools, it got me some nasty spyware some time ago, but I doubt that's it. Next to that I didn't really see anything wrong in the log, looks normal.

  11. #11
    Honorary Argentinian Senior Member Gyroball Champion, Karts Champion Caius's Avatar
    Join Date
    Aug 2006
    Location
    I live in my home, don't you?
    Posts
    8,114

    Default Re: Spyware..?

    Cambyses II know something more, change the name of hijack and go again




    Names, secret names
    But never in my favour
    But when all is said and done
    It's you I love

  12. #12

    Default Re: Spyware..?

    You need to rename hijackthis.exe to hijackthis1991.exe (or "hijackthis" to "hijackthis1991" if you've chosen to hide file extensions) and ensure that it's placed in it's own folder that is not on the desktop or in a folder on the desktop. Otherwise it will be circumvented, and certain spyware will hide from it (if they know where it is and what it's called they can exploit that - that is the main failing of HJT).

    There is nothing in the way of malware in your log at present, though there is a load of - safe - rubbish running, but HTJ is not the way to remedy this. Generally HJT should not be used to remove, only to reveal.

    The only thing I can see that looks amiss is the nameserver line, I seriously doubt that this is problem though and you should not fix/delete it:
    Code:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{BAB45B4A-28F4-469B-99CC-B8B4AEFAD9A4}: NameServer = 196.27.0.29,169.27.0.7
    The first nameserver is ok (If your ISP is Wanadoo Jordan? If it isn't it may still be using their DNS anyway.), the second is a self assigned address which is weird. It may be because the DHCP server is having trouble picking up the secondary DNS server, who knows?

    You should try renaming HJT, as above, and post a new log. You should also download the AVG Antispyware (Formerly Ewido) and run a full scan and fix any problems. If the problem still persists you may have something else, in which case there are other methods/tools available.

    Also consider using alternative anti-virus/personal firewall software to Symantec/Norton.
    “The majestic equality of the laws prohibits the rich and the poor alike from sleeping under bridges, begging in the streets and stealing bread.” - Anatole France

    "The law is like a spider’s web. The small are caught, and the great tear it up.” - Anacharsis

  13. #13
    Cynic Senior Member sapi's Avatar
    Join Date
    Oct 2004
    Location
    Brisbane
    Posts
    4,970

    Default Re: Spyware..?

    Quote Originally Posted by Stig
    No CTHELPER.exe is nothing, it's something used by Creative

    Personally I would get rid of Daemon Tools, it got me some nasty spyware some time ago, but I doubt that's it. Next to that I didn't really see anything wrong in the log, looks normal.
    Daemon tools is fine - i've been using it for ages without problems.

    limewire often = spyware if you don't know what you're doing though
    From wise men, O Lord, protect us -anon
    The death of one man is a tragedy; the death of millions, a statistic -Stalin
    We can categorically state that we have not released man-eating badgers into the area -UK military spokesman Major Mike Shearer

  14. #14

    Default Re: Spyware..?

    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 5:52:45 PM, on 3/4/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\MSI\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\Program Files\GizmoPlugin\GizmoPlugin.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Creative\ShareDLL\CtNotify.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\WINDOWS\wuauclt.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Fraps\FRAPS.EXE
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\MSI\Bluetooth Software\BTTray.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\Creative\ShareDLL\Mediadet.exe
    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Hijackthisako7\HijackThisako7.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
    O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
    O4 - HKLM\..\Run: [Microsoft] C:\WINDOWS\wuauclt.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Fraps] C:\Fraps\FRAPS.EXE
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: BTTray.lnk = ?
    O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\MSI\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by21fd.bay21.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{BAB45B4A-28F4-469B-99CC-B8B4AEFAD9A4}: NameServer = 196.27.0.29,169.27.0.7
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Filter: text/html - (no CLSID) - (no file)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\MSI\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Gizmo VoIP Service (Gizmo Plugin) - SIPphone, Inc. - C:\Program Files\GizmoPlugin\GizmoPlugin.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    About the "safe rubbish", I remove most of it gradually, but it just keeps building up with another load of "safe rubbish" :P

    The first nameserver is ok (If your ISP is Wanadoo Jordan? If it isn't it may still be using their DNS anyway.), the second is a self assigned address which is weird. It may be because the DHCP server is having trouble picking up the secondary DNS server, who knows?
    The "supposed to be" secondary server is 196.27.0.9, but it doesn't work.. And yeah am with Wanadoo Jordan. How did you know that though?
    "Cry, the beloved country, for the unborn child that is the inheritor of our fear. Let him not love the earth too deeply. Let him not laugh too gladly when the water runs through his fingers, nor stand too silent when the setting sun makes red the veld with fire. Let him not be moved when the birds of his land are singing, nor give too much of his heart to a mountain or a valley. For fear will rob him of all if he gives too much."

    Cry, the Beloved Country by Alan Paton.

  15. #15
    Honorary Argentinian Senior Member Gyroball Champion, Karts Champion Caius's Avatar
    Join Date
    Aug 2006
    Location
    I live in my home, don't you?
    Posts
    8,114

    Default Re: Spyware..?

    The "supposed to be" secondary server is 196.27.0.9, but it doesn't work.. And yeah am with Wanadoo Jordan. How did you know that though?
    He hacked you computer.Twice.
    Spoiler Alert, click show to read: 




    Names, secret names
    But never in my favour
    But when all is said and done
    It's you I love

  16. #16

    Default Re: Spyware..?

    No kiddin'!!!

    How!!!
    "Cry, the beloved country, for the unborn child that is the inheritor of our fear. Let him not love the earth too deeply. Let him not laugh too gladly when the water runs through his fingers, nor stand too silent when the setting sun makes red the veld with fire. Let him not be moved when the birds of his land are singing, nor give too much of his heart to a mountain or a valley. For fear will rob him of all if he gives too much."

    Cry, the Beloved Country by Alan Paton.

  17. #17

    Default Re: Spyware..?

    You posted the IP address of you primary DNS server, using that info I was able to locate you using a simple whois lookup. Even now an entire legion of my best camel warriors are on their way, there is no escape!!! Mwuhahahaha!

    There's nothing wrong with your second log either, looks clean.

    Download and run this rootkit scanner, anything that is still managing to hide and anything even nastier should be detectable via that: https://europe.f-secure.com/blacklight/try.shtml

    Accept the agreement and download the GUI version, then run a scan (as ever place it it's own folder, not on the desktop and rename it to e.g. "blbeta000999.exe" ). If you get a 0 then you should be clean, if not post the log.

    Next download this (look near the bottom of the page): http://www.microsoft.com/technet/sys...tRevealer.mspx

    Unzip it to "C:\_rootkitrevealer_" or something similar. Run a scan, save a log and post it as well. Do nothing else.

    Completely nuke all of browser cache, history and cookies before you do anything. Which browser are you using anyway?
    Last edited by caravel; 03-04-2007 at 21:51.
    “The majestic equality of the laws prohibits the rich and the poor alike from sleeping under bridges, begging in the streets and stealing bread.” - Anatole France

    "The law is like a spider’s web. The small are caught, and the great tear it up.” - Anacharsis

  18. #18

    Default Re: Spyware..?

    Internet Explorer 6.

    Will do all that tommorow.
    "Cry, the beloved country, for the unborn child that is the inheritor of our fear. Let him not love the earth too deeply. Let him not laugh too gladly when the water runs through his fingers, nor stand too silent when the setting sun makes red the veld with fire. Let him not be moved when the birds of his land are singing, nor give too much of his heart to a mountain or a valley. For fear will rob him of all if he gives too much."

    Cry, the Beloved Country by Alan Paton.

  19. #19

    Default Re: Spyware..?

    Quote Originally Posted by x-dANGEr
    Internet Explorer 6
    I would advise you to use a different browser. IE6 is the mainstream browser that all browser hijacks, adware toolbars and other nasties are designed to exploit. It is also integrated into the shell, so if something gets into the browser it's in the shell also. Try using Mozilla Firefox or Opera, both very good browsers, with better features, privacy and security than IE6.
    “The majestic equality of the laws prohibits the rich and the poor alike from sleeping under bridges, begging in the streets and stealing bread.” - Anatole France

    "The law is like a spider’s web. The small are caught, and the great tear it up.” - Anacharsis

  20. #20
    Cynic Senior Member sapi's Avatar
    Join Date
    Oct 2004
    Location
    Brisbane
    Posts
    4,970

    Default Re: Spyware..?



    Firefox is a far superior and far safer browser.

    Use it
    From wise men, O Lord, protect us -anon
    The death of one man is a tragedy; the death of millions, a statistic -Stalin
    We can categorically state that we have not released man-eating badgers into the area -UK military spokesman Major Mike Shearer

  21. #21

    Default Re: Spyware..?

    Like.. I've been using IE6 since it came out, and this is the first thing I ever faced. (That coudln't me removed by a single program)

    So I think there is no "pushing" need to change the browser

    EDIT:

    And nothing.. There is nothing! 0-i
    Last edited by x-dANGEr; 03-05-2007 at 17:33.
    "Cry, the beloved country, for the unborn child that is the inheritor of our fear. Let him not love the earth too deeply. Let him not laugh too gladly when the water runs through his fingers, nor stand too silent when the setting sun makes red the veld with fire. Let him not be moved when the birds of his land are singing, nor give too much of his heart to a mountain or a valley. For fear will rob him of all if he gives too much."

    Cry, the Beloved Country by Alan Paton.

  22. #22
    Honorary Argentinian Senior Member Gyroball Champion, Karts Champion Caius's Avatar
    Join Date
    Aug 2006
    Location
    I live in my home, don't you?
    Posts
    8,114

    Default Re: Spyware..?

    Quote Originally Posted by sapi


    Firefox is a far superior and far safer browser.

    Use it
    Quote Originally Posted by Reenk
    Remmember kiddies, if you download Firefox, you download comunism
    I didnt said that.Reenk did




    Names, secret names
    But never in my favour
    But when all is said and done
    It's you I love

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Single Sign On provided by vBSSO