home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > General Tech Discussion
Ask a Tech Support Question (free)!

Please help, hijacked by spyware!!

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1553
Discussions: 200,903, Posts: 2,378,878, Members: 246,272
Old October 30th, 2005, 12:54 PM   Digg it!   #1 (permalink)
Member
 
Join Date: Nov 2004
Location: SLC, UT
Posts: 182
Please help, hijacked by spyware!!

Ok I need some help, I'm at a loss as what to do. I recently had to reinstall windows and I got a peice of spyware in the process that I can't get rid of. It's on of those "Windows Alerts" that says there are critical problems that need to be adderssed quickly. So I should go to their website and buy their registry cleaner.

I have run Avast several times, Ad-Aware, Spy-Bot search and destroy, CCcleaner, and RegsrcubXP and still am getting the thing popping up. It's set to "alert" me about every 4-5 min and saves up the info so that I have to close out all of them. So if I log off the computer for say 30min I will have like 6 messages to close out.

Please help!!
__________________
The impossible often has a kind of integrity to it which the merely improbable lacks.---Douglas Adams
dlpetey is offline   Reply With Quote
Old October 30th, 2005, 01:01 PM     #2 (permalink)
Not Really a Member
 
Join Date: Oct 2001
Posts: 25,368
run hijackthis and give us the log it creates

did you update the applications with the latest definitions before scanning?

you can also try trendmicro online scan tool... its free
vass0922 is offline   Reply With Quote
Old October 30th, 2005, 01:01 PM     #3 (permalink)
Instigator
 
Atomic Rooster's Avatar
 
Join Date: Oct 2001
Location: Healdsburg, CA
Posts: 12,257
Send a message via AIM to Atomic Rooster Send a message via Yahoo to Atomic Rooster
Those pop-ups may be using the Windows Messenger service. Try this: go to Control Panel > Administrative Tools > Services. Scroll down to Messenger, right click and select Properties. Under Startup type select Disabled. Then under Service status, click the Stop button. Click Apply and hopefully that should kill the pop-ups.
Atomic Rooster is offline   Reply With Quote
Old October 30th, 2005, 01:12 PM     #4 (permalink)
Member
 
Join Date: Nov 2004
Location: SLC, UT
Posts: 182
Here's the log file, also I did what Atomic Rooster said, we'll see if that works.


Logfile of HijackThis v1.99.1
Scan saved at 9:17:36 AM, on 10/30/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
F:\Installed\Upkeep\Avast\aswUpdSv.exe
F:\Installed\Upkeep\Avast\ashServ.exe
F:\Installed\Internet\PC anywhere\awhost32.exe
H:\WINDOWS\System32\CTHELPER.EXE
F:\INSTAL~1\Upkeep\Avast\ashDisp.exe
F:\Installed\Media\Damon Tools\daemon.exe
F:\Installed\Internet\Ad-Aware SE Professional\Ad-Watch.exe
H:\WINDOWS\System32\CTsvcCDA.exe
F:\Installed\Upkeep\Outpost Firewall\outpost.exe
F:\Installed\Upkeep\Avast\ashMaiSv.exe
F:\Installed\Upkeep\Avast\ashWebSv.exe
G:\Temp Apps\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\apps\Documents\Adobe\Reader\ActiveX\AcroIEHelpe r.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - H:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] H:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] H:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [avast!] F:\INSTAL~1\Upkeep\Avast\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Outpost Firewall] F:\Installed\Upkeep\Outpost Firewall\outpost.exe /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] F:\Installed\Upkeep\Outpost Firewall\feedback.exe /dumps_startup
O4 - HKLM\..\Run: [DAEMON Tools-1033] "F:\Installed\Media\Damon Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [AWMON] "F:\Installed\Internet\Ad-Aware SE Professional\Ad-Watch.exe"
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - F:\Installed\Upkeep\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1130036549289
O20 - AppInit_DLLs: f:\apps\upkeep\outpos~1\wl_hook.dll F:\INSTAL~1\Upkeep\OUTPOS~1\wl_hook.dll
O20 - Winlogon Notify: PCANotify - H:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - F:\Installed\Upkeep\Avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - F:\Installed\Upkeep\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - F:\Installed\Upkeep\Avast\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - F:\Installed\Upkeep\Avast\ashWebSv.exe" /service (file missing)
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - F:\Installed\Internet\PC anywhere\awhost32.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - H:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - F:\Installed\Upkeep\Outpost Firewall\outpost.exe
dlpetey is offline   Reply With Quote
Old October 30th, 2005, 01:20 PM     #5 (permalink)
Super F@D Folder
 
Join Date: Jun 2004
Posts: 5,083
Send a message via AIM to sr71000
first of all..you should probably move hjt from your temp apps folder to a more permanant folder!! Then, go to my site http://k-techcomputers.us and look for the link to the two online analyzers. post your log in those and it'll check it for common problems....and we'll go through the one posted here for other problems If you make any fixes in the log...post a new one here so we don't just repeat the work of the online analyzers
sr71000 is offline   Reply With Quote
Old October 30th, 2005, 01:23 PM     #6 (permalink)
The FNG
 
rrcn's Avatar
 
Join Date: Nov 2003
Location: SoCal
Posts: 5,605
I scanned your log and I don't see anything unusual.

Did you try running tredmicro's online virus scan like Vass suggested?
rrcn is offline   Reply With Quote
Old October 30th, 2005, 01:30 PM     #7 (permalink)
Member
 
Join Date: Nov 2004
Location: SLC, UT
Posts: 182
When I try to do trendmicro's virus scan I get "HouseCall ActiveX component is not ready." Not sure what it wants.

Edit: sr7100 BTW the link for your site took me to a page that said the address had changed and if posted on a fourm to alert the poster

Last edited by dlpetey : October 30th, 2005 at 01:38 PM.
dlpetey is offline   Reply With Quote
Old October 30th, 2005, 06:30 PM     #8 (permalink)
Member
 
Join Date: Jan 2002
Posts: 269
I had the same problem, I would leave my machine on over night and wake up to find like 100 alerts or so. I ran Ad-aware, Spybot, CCleaner, The Cleaner, and changed my anti virus from Symantec to AVG. I also ran highjack this and ran the log through the above mentioned site (KC computers). After all that I got rid of all the alerts. The only spyware I can't get rid of yet is this stupid huntbar? Hope this helps.

Jutah
jutah is offline   Reply With Quote
Old October 31st, 2005, 12:31 AM     #9 (permalink)
Member
 
Join Date: Nov 2004
Location: SLC, UT
Posts: 182
As an update Atomic Roosters suggestion seems to have done the trick. I haven't had any of the popups since following that advice. As for the highjack this stuff everything seems to be fine. So thanks guys.
dlpetey is offline   Reply With Quote
Old October 31st, 2005, 12:34 AM     #10 (permalink)
Instigator
 
Atomic Rooster's Avatar
 
Join Date: Oct 2001
Location: Healdsburg, CA
Posts: 12,257
Send a message via AIM to Atomic Rooster Send a message via Yahoo to Atomic Rooster
Good to hear all is well. I'm glad I could help.
Atomic Rooster is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
am i hijacked? simbob Applications and Operating Systems 2 June 10th, 2005 09:39 PM
IE hijacked rex028 Technical Support 5 April 7th, 2005 07:51 AM
hijacked by nowfind ad5mb Security and Privacy Issues 5 March 13th, 2005 01:18 AM
Help with Homepage being hijacked maximus01can Security and Privacy Issues 5 May 15th, 2004 07:51 AM
Hijacked browser? renton Security and Privacy Issues 3 March 8th, 2004 02:40 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2799)
Is the PSU I received dead? (10)
Install XP pro and a Vista laptop ?.. (8)
California Passes Anti-Flat-HDTV Le.. (38)
A good PSU? (10)
Fox uses old news clips to inflate .. (33)
Foreign voltage (5)
New Computer wont recognize XP disc (7)
HIS HD5770 graphic card question (11)
Dept. of HS: NSA 'Helped' Develop V.. (12)
Print spooler problem (5)
EVGA 9800 gtx help with finding a g.. (6)
Ideal cheap graph card for PC-Gamin.. (13)
Mysterious Boot manager (9)
Recent Discussions
Install XP pro and a Vista laptop ?? (8)
HIS HD5770 graphic card question (11)
Need hard disk drivers (3)
Cloning old drive to new drive (6)
Asus P4G8X Mobo (0)
Amptron monitor G17FP-Black (0)
windows vista security holes (0)
EVGA 9800 gtx help with finding a goo.. (6)
A good PSU? (10)
Is the PSU I received dead? (10)
Ideal cheap graph card for PC-Gaming? (13)
HP Pavillion Laptop ze4220 won't turn.. (7)
Dept. of HS: NSA 'Helped' Develop Vis.. (12)
Foreign voltage (5)
Convert 5 pin Keyboard to USB (11)
Print spooler problem (5)
hybernate option (2)
Steam ID's, Gamertags etc... (1)
New Computer wont recognize XP disc (7)
World's largest Monopoly Game using G.. (328)
Modern Warfare 2: Who Bought It? (60)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (28)
blender help (2)
Hard drive freezes boot (1)
Mysterious Boot manager (9)


All times are GMT -4. The time now is 02:32 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28