home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1883
Discussions: 188,471, Posts: 2,244,170, Members: 232,723
Old December 1st, 2006, 07:11 PM   Digg it!   #1 (permalink)
Member
 
Join Date: Oct 2004
Posts: 125
ADWARE PROBLEM

Hi,

Each time I right-click my recycle bin there's a web address there ..

javascript:{http://sex something or other}

I've tried 5 or 6 different spyware/adware programs .. but neither of them deleted the problem.

Any suggestions would be greatly appreciated.

Thanks,
Wik.

Wikaveli is offline   Reply With Quote
Old December 1st, 2006, 07:23 PM     #2 (permalink)
Banned
 
Join Date: Oct 2006
Location: Chicago, IL
Posts: 232
Send a message via MSN to vick.x6
whats programs have you tryed so far and when did this start happening?

vick.x6 is offline   Reply With Quote
Old December 1st, 2006, 07:23 PM     #3 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,774
Blog Entries: 5
have you tried hijackthis?

HijackThis Analyzer & Tutorial

GroundZero3 is offline   Reply With Quote
Old December 1st, 2006, 07:27 PM     #4 (permalink)
Ultimate Member
 
mjolnir1134's Avatar
 
Join Date: Jan 2005
Location: The Internet
Posts: 1,999
Dunno if it helps, but did you try "Ad-Aware SE Personal" yet out of those 5-6 programs? Its really good, and theres like an update almost everyday that you can download, so you know they're up to date on the malwares. :|
http://www.download.com/Ad-Aware-SE-...bj=dl&tag=top5

So when you right click your recycle bin, you mean you see an option in the right-click-menu that says "javascript:{http://sex something or other}"?

Or do you mean you find a file with a link that says "javascript:{http://sex something or other}" in there?

To add on, did you also try a virus-scanner as well?
__________________
Rationalrant.com - My website.
e6420—2GB RAM—8800GT—ASUS P5LD2—XP / EEE 1000H
mjolnir1134 is offline   Reply With Quote
Old December 2nd, 2006, 11:16 AM     #5 (permalink)
Member
 
Join Date: Oct 2004
Posts: 125
Ok .. this started about 2 weeks ago. The funny thing is, as far as I know, no adult sites have been visited.

I've tried:
advanced spyware remover
ad-aware se personal
spybot - search & destroy
avg - anti-spyware
spyware blaster
spyware nuker xt
bulletproof spyware remover
zonelab

When I 'right click the bin, i see an option in the right-click-menu that says "javascript:{http://sex something or other}". I haven't clicked it.

Right-Click Menu:
Open
javascript:{http://sex something or other}
Explore
Empty Recycle Bin

I have also tried virus scaners:
zonelabs
online norton

I'll look into the hijackthis link ..

Thanks again!

Wik
Wikaveli is offline   Reply With Quote
Old December 2nd, 2006, 11:36 AM     #6 (permalink)
Member
 
Join Date: Oct 2004
Posts: 125
Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 10:25:46 AM, on 12/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
K:\Installed Programs\Security\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\! Utilities - Software\Diskeeper Professional Premier Setup\Program Files\DkService.exe
C:\Program Files\! Media - Creation\Nero Suite 6\Nero InCD 4\InCD\InCDsrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\! Utilities - Software\Alcohol120\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\! Security\ZoneAlarmPro\zlclient.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\!SECUR~1\ZONEAL~1\MAILFR~1\mantispm.ex e
K:\Setup Files\Utilities\System\hijackthis\hijackthis_199\H ijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www1.royalbank.com/cgi-bin/r...NGUAGE=ENGLISH
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = (value not set)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Take A Ride ... On The Information Highway!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = localhost:2323
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - (no file)
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-ca\msntb.dll
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-ca\msntb.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\! Security\ZoneAlarmPro\zlclient.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-ca\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\!APPLI~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\!APPLI~1\MICROS~1\OFFICE11\REFIEBAR.DL L
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) - http://www.2ontario.com/download/CfxIEAx.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1136005489840
O16 - DPF: {72C9EA8F-8965-40C2-ABAD-D460A5815F86} (hostCntrlIE Class) - http://host.oddcast.com/hostClientIE.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ps.intuitcanada.com/quickbook...les/msxml4.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O18 - Protocol: intu-res - {9CE7D474-16F9-4889-9BB9-53E2008EAE8A} - C:\Program Files\Common Files\Intuit\intu-res.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - K:\Installed Programs\Security\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\! Utilities - Software\Diskeeper Professional Premier Setup\Program Files\DkService.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\! Media - Creation\Nero Suite 6\Nero InCD 4\InCD\InCDsrv.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\! Utilities - Software\Alcohol120\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Wikaveli is offline   Reply With Quote
Old December 2nd, 2006, 11:59 AM     #7 (permalink)
Member
 
Join Date: Oct 2004
Posts: 125
I posted my hijackthis log above .. I'm not really sure what to do with it.

Any suggestions would be wonderful .. thanks.
Wikaveli is offline   Reply With Quote
Old December 2nd, 2006, 12:06 PM     #8 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,774
Blog Entries: 5
Quote:
Originally Posted by GroundZero3 View Post
have you tried hijackthis?

HijackThis Analyzer & Tutorial
follow the thread on what you do with the log
GroundZero3 is offline   Reply With Quote
Old December 2nd, 2006, 06:32 PM     #9 (permalink)
Member
 
Join Date: Oct 2004
Posts: 125
Quote:
Originally Posted by GroundZero3 View Post
follow the thread on what you do with the log


Gotcha .. thanks alot.
Wikaveli is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Adware Virus problem ltkenbo Technical Support 5 June 30th, 2006 05:50 PM
Spyware, Adware problem Nathan74565 Technical Support 32 February 14th, 2006 05:58 PM
Adware problem Ebisoba Technical Support 22 December 18th, 2005 06:52 PM
Problem deleting Spyware/AdWare magicfreak32 Technical Support 2 March 11th, 2005 06:26 PM
Ad Aware/adware problem TODComp Applications and Operating Systems 4 November 9th, 2004 03:09 PM

Most Active Discussions
Is It Just Me? (2996)
"mastermind" of London at.. (65)
Intel Pentium 4 531 (7)
Please don't divorce us (40)
AMD Phenom II X4 940 Black Edition (11)
Replacing integrated video card (5)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
Recent Discussions
How to rip a DVD and edit DVD o.. (0)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Bought the Visiontek Radeon 387.. (1)
CPU Overheating ?? (18)
Computer will not boot(powers o.. (2)
*TechIMO's Top 30 PCs* (44)
New psu question (1)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 06:00 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28