home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

virus spyware what is this?

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1500
Discussions: 200,906, Posts: 2,378,908, Members: 246,276
Old February 7th, 2005, 09:24 AM   Digg it!   #1 (permalink)
Senior Member
 
Join Date: Jan 2005
Posts: 594
virus spyware what is this?

i ran my spysweeper today and it said i had some **** like CWS on it
browser hijacker and what not. i ran adaware and spysweeper and they told me they removed it, but when i scanned again, other **** popped up like porn and stuff .also i realized that i should start to use a firewall but i hate the windows one becuase it restricts download (BT,p2p) what firewall should i use?
thx. hereis the hijackthis logfile hope yall can tellme something


Logfile of HijackThis v1.99.0
Scan saved at 5:21:35 AM, on 2/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ABC\ABC.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: raid_tool.exe.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: Download Using &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sygate Personal Firewall - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

Edited by Phenious
mbandela000 is offline   Reply With Quote
Old February 7th, 2005, 09:47 AM     #2 (permalink)
27
Ultimate Member
 
27's Avatar
 
Join Date: Jun 2004
Location: England
Posts: 1,407
Slam your hijack this log here
http://www.help2go.com/modules.php?name=HJTDetective

or here

http://hijackthis.de/index.php?langselect=english

Here's a good free firewall that can be customised to allow P2P

http://soho.sygate.com/download/download.php?pid=spf
27 is offline   Reply With Quote
Old February 7th, 2005, 09:48 AM     #3 (permalink)
27
Ultimate Member
 
27's Avatar
 
Join Date: Jun 2004
Location: England
Posts: 1,407
Here's some good free AntiVirus too
http://www.avast.com/eng/down_home.html
27 is offline   Reply With Quote
Old February 7th, 2005, 09:59 AM     #4 (permalink)
Ultimate Member
 
Undeadlord's Avatar
 
Join Date: Oct 2001
Location: Philadelphia, PA
Posts: 1,548
Send a message via ICQ to Undeadlord Send a message via AIM to Undeadlord Send a message via Yahoo to Undeadlord
I hate to admit it, but Microsoft's Antispyware really impressed me in how it found and took care of spyware. Its available here for free http://g.microsoft.com/mh_mshp/787

Just a quick glance at your Hijack logs, but they look clean.


Undeadlord
__________________
"Mercy for the guilty is treason to the innocent"
Undeadlord is offline   Reply With Quote
Old February 7th, 2005, 11:25 AM     #5 (permalink)
27
Ultimate Member
 
27's Avatar
 
Join Date: Jun 2004
Location: England
Posts: 1,407
Quote:
Originally Posted by Undeadlord

Just a quick glance at your Hijack logs, but they look clean.


Undeadlord

It's nt clean. There are a few bits of eeevil on that computer.
27 is offline   Reply With Quote
Old February 7th, 2005, 12:04 PM     #6 (permalink)
Senior Member
 
Join Date: Jan 2005
Posts: 594
ok i will slamm it there
and what eeevil are there on this comp(only 3 days old lol)
is that the problem with my downloads?
mbandela000 is offline   Reply With Quote
Old February 7th, 2005, 12:06 PM     #7 (permalink)
Senior Member
 
Join Date: Jan 2005
Posts: 594
how do i configure this sygate thing to accept BT and my Bearshare Lite?
mbandela000 is offline   Reply With Quote
Old February 7th, 2005, 12:11 PM     #8 (permalink)
Banned
 
pphalan's Avatar
 
Join Date: Nov 2004
Location: BACK in the USA
Posts: 1,823
CW remove program
http://cwshredder.net/cwshredder/cwschronicles.html
CoolWebSearch Chronicles
pphalan is offline   Reply With Quote
Old February 7th, 2005, 12:15 PM     #9 (permalink)
Senior Member
 
Join Date: Jan 2005
Posts: 594
is there an allaround spyware/adware/virus/trojan/malware solution??
mbandela000 is offline   Reply With Quote
Old February 7th, 2005, 12:21 PM     #10 (permalink)
Banned
 
pphalan's Avatar
 
Join Date: Nov 2004
Location: BACK in the USA
Posts: 1,823
Quote:
Originally Posted by Undeadlord
I hate to admit it, but Microsoft's Antispyware really impressed me in how it found and took care of spyware. Its available here for free http://g.microsoft.com/mh_mshp/787

Just a quick glance at your Hijack logs, but they look clean.


Undeadlord

Undeadlord gave you a link to the best one Ive seen get before microsoft starts charging for it
pphalan is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
I got infected with startpag.hi, how do I clean it? Ruahrc Security and Privacy Issues 16 November 17th, 2004 10:06 AM
Help get rid of Java Virus Bizkitkid2001 Technical Support 7 September 29th, 2004 12:02 AM
multiple XP users..spyware q? John Prophet Applications and Operating Systems 7 June 25th, 2004 09:40 PM
HOW DID THIS HAPPEN?! durante IMO Community 36 August 7th, 2003 11:12 PM
ARGH! AOL Service squeech Applications and Operating Systems 16 June 17th, 2003 04:59 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2809)
Is the PSU I received dead? (10)
California Passes Anti-Flat-HDTV Le.. (38)
Install XP pro and a Vista laptop ?.. (8)
Fox uses old news clips to inflate .. (33)
A good PSU? (10)
HIS HD5770 graphic card question (14)
Foreign voltage (6)
New Computer wont recognize XP disc (7)
Dept. of HS: NSA 'Helped' Develop V.. (12)
Ideal cheap graph card for PC-Gamin.. (15)
Print spooler problem (5)
EVGA 9800 gtx help with finding a g.. (6)
Mysterious Boot manager (9)
Recent Discussions
Need hard disk drivers (4)
Asus P4G8X Mobo (1)
windows 7 internet problem (4)
windows vista security holes (1)
What OS for a home server? (other tha.. (1)
Boot Problem? (0)
Logitech G9 laser gaming mouse $59.95.. (2)
$5 off any item with the purchase of .. (1)
Foreign voltage (6)
Ideal cheap graph card for PC-Gaming? (15)
HIS HD5770 graphic card question (14)
Install XP pro and a Vista laptop ?? (8)
Cloning old drive to new drive (6)
Amptron monitor G17FP-Black (0)
EVGA 9800 gtx help with finding a goo.. (6)
A good PSU? (10)
Is the PSU I received dead? (10)
HP Pavillion Laptop ze4220 won't turn.. (7)
Dept. of HS: NSA 'Helped' Develop Vis.. (12)
Convert 5 pin Keyboard to USB (11)
Print spooler problem (5)
hybernate option (2)
Steam ID's, Gamertags etc... (1)
New Computer wont recognize XP disc (7)
World's largest Monopoly Game using G.. (328)


All times are GMT -4. The time now is 08:09 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28