home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > General Tech Discussion
Ask a Tech Support Question (free)!

Please help, hijacked by spyware!!

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1397
Discussions: 200,507, Posts: 2,374,396, Members: 245,831
Old October 30th, 2005, 12:54 PM   Digg it!   #1 (permalink)
Member
 
Join Date: Nov 2004
Location: SLC, UT
Posts: 179
Please help, hijacked by spyware!!

Ok I need some help, I'm at a loss as what to do. I recently had to reinstall windows and I got a peice of spyware in the process that I can't get rid of. It's on of those "Windows Alerts" that says there are critical problems that need to be adderssed quickly. So I should go to their website and buy their registry cleaner.

I have run Avast several times, Ad-Aware, Spy-Bot search and destroy, CCcleaner, and RegsrcubXP and still am getting the thing popping up. It's set to "alert" me about every 4-5 min and saves up the info so that I have to close out all of them. So if I log off the computer for say 30min I will have like 6 messages to close out.

Please help!!
__________________
The impossible often has a kind of integrity to it which the merely improbable lacks.---Douglas Adams
dlpetey is offline   Reply With Quote
Old October 30th, 2005, 01:01 PM     #2 (permalink)
Not Really a Member
 
Join Date: Oct 2001
Posts: 25,215
run hijackthis and give us the log it creates

did you update the applications with the latest definitions before scanning?

you can also try trendmicro online scan tool... its free
vass0922 is offline   Reply With Quote
Old October 30th, 2005, 01:01 PM     #3 (permalink)
Instigator
 
Atomic Rooster's Avatar
 
Join Date: Oct 2001
Location: Healdsburg, CA
Posts: 12,253
Send a message via AIM to Atomic Rooster Send a message via Yahoo to Atomic Rooster
Those pop-ups may be using the Windows Messenger service. Try this: go to Control Panel > Administrative Tools > Services. Scroll down to Messenger, right click and select Properties. Under Startup type select Disabled. Then under Service status, click the Stop button. Click Apply and hopefully that should kill the pop-ups.
Atomic Rooster is online now   Reply With Quote
Old October 30th, 2005, 01:12 PM     #4 (permalink)
Member
 
Join Date: Nov 2004
Location: SLC, UT
Posts: 179
Here's the log file, also I did what Atomic Rooster said, we'll see if that works.


Logfile of HijackThis v1.99.1
Scan saved at 9:17:36 AM, on 10/30/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
F:\Installed\Upkeep\Avast\aswUpdSv.exe
F:\Installed\Upkeep\Avast\ashServ.exe
F:\Installed\Internet\PC anywhere\awhost32.exe
H:\WINDOWS\System32\CTHELPER.EXE
F:\INSTAL~1\Upkeep\Avast\ashDisp.exe
F:\Installed\Media\Damon Tools\daemon.exe
F:\Installed\Internet\Ad-Aware SE Professional\Ad-Watch.exe
H:\WINDOWS\System32\CTsvcCDA.exe
F:\Installed\Upkeep\Outpost Firewall\outpost.exe
F:\Installed\Upkeep\Avast\ashMaiSv.exe
F:\Installed\Upkeep\Avast\ashWebSv.exe
G:\Temp Apps\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\apps\Documents\Adobe\Reader\ActiveX\AcroIEHelpe r.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - H:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] H:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] H:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [avast!] F:\INSTAL~1\Upkeep\Avast\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Outpost Firewall] F:\Installed\Upkeep\Outpost Firewall\outpost.exe /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] F:\Installed\Upkeep\Outpost Firewall\feedback.exe /dumps_startup
O4 - HKLM\..\Run: [DAEMON Tools-1033] "F:\Installed\Media\Damon Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [AWMON] "F:\Installed\Internet\Ad-Aware SE Professional\Ad-Watch.exe"
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - F:\Installed\Upkeep\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1130036549289
O20 - AppInit_DLLs: f:\apps\upkeep\outpos~1\wl_hook.dll F:\INSTAL~1\Upkeep\OUTPOS~1\wl_hook.dll
O20 - Winlogon Notify: PCANotify - H:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - F:\Installed\Upkeep\Avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - F:\Installed\Upkeep\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - F:\Installed\Upkeep\Avast\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - F:\Installed\Upkeep\Avast\ashWebSv.exe" /service (file missing)
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - F:\Installed\Internet\PC anywhere\awhost32.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - H:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - F:\Installed\Upkeep\Outpost Firewall\outpost.exe
dlpetey is offline   Reply With Quote
Old October 30th, 2005, 01:20 PM     #5 (permalink)
Super F@D Folder
 
Join Date: Jun 2004
Posts: 5,080
Send a message via AIM to sr71000
first of all..you should probably move hjt from your temp apps folder to a more permanant folder!! Then, go to my site http://k-techcomputers.us and look for the link to the two online analyzers. post your log in those and it'll check it for common problems....and we'll go through the one posted here for other problems If you make any fixes in the log...post a new one here so we don't just repeat the work of the online analyzers
sr71000 is offline   Reply With Quote
Old October 30th, 2005, 01:23 PM     #6 (permalink)
The FNG
 
rrcn's Avatar
 
Join Date: Nov 2003
Location: SoCal
Posts: 5,605
I scanned your log and I don't see anything unusual.

Did you try running tredmicro's online virus scan like Vass suggested?
rrcn is offline   Reply With Quote
Old October 30th, 2005, 01:30 PM     #7 (permalink)
Member
 
Join Date: Nov 2004
Location: SLC, UT
Posts: 179
When I try to do trendmicro's virus scan I get "HouseCall ActiveX component is not ready." Not sure what it wants.

Edit: sr7100 BTW the link for your site took me to a page that said the address had changed and if posted on a fourm to alert the poster

Last edited by dlpetey : October 30th, 2005 at 01:38 PM.
dlpetey is offline   Reply With Quote
Old October 30th, 2005, 06:30 PM     #8 (permalink)
Member
 
Join Date: Jan 2002
Posts: 269
I had the same problem, I would leave my machine on over night and wake up to find like 100 alerts or so. I ran Ad-aware, Spybot, CCleaner, The Cleaner, and changed my anti virus from Symantec to AVG. I also ran highjack this and ran the log through the above mentioned site (KC computers). After all that I got rid of all the alerts. The only spyware I can't get rid of yet is this stupid huntbar? Hope this helps.

Jutah
jutah is offline   Reply With Quote
Old October 31st, 2005, 12:31 AM     #9 (permalink)
Member
 
Join Date: Nov 2004
Location: SLC, UT
Posts: 179
As an update Atomic Roosters suggestion seems to have done the trick. I haven't had any of the popups since following that advice. As for the highjack this stuff everything seems to be fine. So thanks guys.
dlpetey is offline   Reply With Quote
Old October 31st, 2005, 12:34 AM     #10 (permalink)
Instigator
 
Atomic Rooster's Avatar
 
Join Date: Oct 2001
Location: Healdsburg, CA
Posts: 12,253
Send a message via AIM to Atomic Rooster Send a message via Yahoo to Atomic Rooster
Good to hear all is well. I'm glad I could help.
Atomic Rooster is online now   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
am i hijacked? simbob Applications and Operating Systems 2 June 10th, 2005 09:39 PM
IE hijacked rex028 Technical Support 5 April 7th, 2005 07:51 AM
hijacked by nowfind ad5mb Security and Privacy Issues 5 March 13th, 2005 01:18 AM
Help with Homepage being hijacked maximus01can Security and Privacy Issues 5 May 15th, 2004 07:51 AM
Hijacked browser? renton Security and Privacy Issues 3 March 8th, 2004 02:40 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (1635)
FT HOOD attack: 7 killed 12 injured (66)
Review My Build (5)
HELP!!! What do you think of this s.. (16)
Looking for a graphic card that wil.. (30)
Assosiations (21496)
My 1st pc build (40)
Aero in Vista (7)
PC Modern Warfare 2: it's much wors.. (12)
core i7 extreme 975, nvidia 9400gt (9)
How to Ship a PC (16)
Building my first computer (13)
slaving laptop drive (7)
[F@H SPAM 11/1/09]New month . . . n.. (33)
Recent Discussions
sell cvv us-uk-eu-au...very good. who.. (0)
how to convert mod to wmv/avi/mp4/mov.. (0)
FAT32 to NTFS file system in Win2kpro (3)
Motherboards and my curse... (25)
Review My Build (5)
HELP!!! What do you think of this sys.. (16)
New Processor, Monitor will not turn .. (2)
2009 Build (4)
Internet very slow since updating AVG.. (7)
My 1st pc build (40)
Freezing During Music/Movies (1)
Windows Experience Index is screwed u.. (2)
ext. sound card laptop to stereo syst.. (2)
Remote Desktop via SSH and error mess.. (2)
Help and Support disappeared from my .. (0)
[F@H SPAM 11/1/09]New month . . . new.. (33)
Basic applications needed for "r.. (1)
core i7 extreme 975, nvidia 9400gt (9)
hard drive problem (2)
Win7 TrustedInstaller Permissions (2)
Speed up Win 7 boot time a bit (1)
Hard Drive test program (2)
wireless westell versalink model 327w (1)
New build 10 second reboot cycle! Won.. (3)
New Linksys Routers (2)


All times are GMT -4. The time now is 05:09 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28