home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Reply

SR431qh0.exe a possible spyware/virus?

 
Thread Tools Search this Thread
Currently Active Users: 2305
Discussions: 207,853, Posts: 2,459,458, Members: 253,353
Get bargains at  »  Dealighted.com
Old August 30th, 2008, 08:10 PM   Digg it!   #1 (permalink)
Junior Member
 
Join Date: Aug 2008
Posts: 2
SR431qh0.exe a possible spyware/virus?

I have been having a problem for about two weeks with popups appearing randomly on my desktop. I have run many anti-spyware and anti-virus programs such as spybot, adaware, spysweeper, windows defender, Eusing Registry cleaner... maybe one or two more. Each have failed to end the popups however.

When the popups occur, my internet explorer will open (not always a window I can see but it can always be seen in my windows task manager) and will run a random add. This can interrupt other programs, close the IE window I have open or just open a new one (and often use alot of memory in the process).

Here is my hijackthis report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:47:10 PM, on 8/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\M-Audio\Black Box\MAUSBBBInst.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\M-Audio\Black Box\BlackBoxHelper.exe
C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\SR431qh0.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Extras\Downloads\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Black Box Helper] C:\Program Files\M-Audio\Black Box\BlackBoxHelper.exe
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://plugin.fileopen.com/current/FileOpen.CAB
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: M-Audio BlackBox Installer (MAudioBlackBoxService) - Avid Technology, Inc. - C:\Program Files\M-Audio\Black Box\MAUSBBBInst.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe



The one specific file that I know has something to do with these popups is SR431qh0.exe. If I choose to end the its process tree, the IE window open with the add will also close. If I search and delete the .exe, the popups will disappear for awhile until SR431qh0.exe re-appears in my list of processes running in windows task manager (and is also back in the place I deleted it from). I don't know what the file is, how or when it appeared on my computer, or how to get rid of it. If anyone can help, thanks

Benjamik is offline   Reply With Quote
Old August 31st, 2008, 02:44 AM     #2 (permalink)
Junior Member
 
Join Date: Aug 2008
Posts: 1
ya im having the same problem. i notice that it comes up in IE explorer, but i dont have ie explorer installed on my comp, so its definitely a virus, and the window its running in is definitely a fake version of ie. im working on deleting it out of my registry, and just doing a whole sweep of my copmuter, this one is quite nasty. I think it came from adobe, or something that looked like it

beneharris is offline   Reply With Quote
Old August 31st, 2008, 06:26 AM     #3 (permalink)
Member
 
Join Date: Jun 2005
Posts: 445
if spyware protection doesnt fix it, get a different virus protector.

Download avast and after everything is setup with avast, run it's on demand scanner.

also, go to run, type in regedit then go to -
HKEY-Current User > Software > Microsoft > Windows > CurrentVersion > Run or RunOnce or anything else that begins with Run.

also go to -
HKEY-Local Machine > Software > Microsoft > Windows > CurrentVersion > Run or RunOnce or anything else that begins with Run.

(Do not go into subfolders of runonce, etc...)

You are looking for programs on the right that do NOT need to load on startup.
Hopefully, you will be seeing quite a few that aren't necessary. If you do not know which to delete, search every program on yahoo before deleting.
shizzzon is offline   Reply With Quote
Old August 31st, 2008, 09:33 AM     #4 (permalink)
Member
 
videoman1994's Avatar
 
Join Date: May 2008
Location: Norway, MI
Posts: 137
Send a message via MSN to videoman1994
I agree with the post above me get avast antivirus its free at avast! 4 Home Edition - FREE antivirus software - Download

Then if you do download it it will ask if you want to have avast scan when you boot click yes and avast should catch it. Good luck
__________________
gto!
videoman1994 is offline   Reply With Quote
Old August 31st, 2008, 05:51 PM     #5 (permalink)
Junior Member
 
Join Date: Aug 2008
Posts: 2
Thanks, I think avast may have finally been able to end this thing. I will let you know if for some reason it comes back.

Benjamik is offline   Reply With Quote
Ask a Tech Question (free)!
Most Active Discussions
Is It Just Me? (1014)
Intel Core i7 920 heat issue help p.. (19)
I need help building a computer. 40.. (33)
Best gaming GPU for $200 or less? (17)
Nvidia GeForce gt 220 problems (21)
Trouble connecting to Apartment Int.. (16)
net use command (13)
cant find drivers (8)
Wireless coverage over 3 hotel floo.. (17)
Laptop Battery issue? (10)
Zombie Cookies Privacy Lawsuit Targ.. (6)
Rate My First Computer Build (8)
new video card- screen changes to c.. (8)
Geforce vs. Radeon? (20)
Recent Discussions
Trouble connecting to Apartment Inter.. (16)
Wireless coverage over 3 hotel floors (17)
Can't open zip files in vista??? (16)
Rate My First Computer Build (8)
Server 2008 "read only" (0)
120G External Drive, USB 2.0: Works o.. (2)
Help Dell Latitude D610 Power Problem.. (6)
Intel Core i7 920 heat issue help ple.. (19)
new woot (5)
Which Graphic is better? (1)
On startup my monitor clicks forever .. (1)
Cavalier Internet (12)
Laptop Battery issue? (10)
PC turns on, gets normal post beep bu.. (0)
D drive failure? (3)
In need of Help! (1)
DVD Recorder Set-Up (3)
System fans not working (2)
good video card around 100-200 dollar.. (3)
Linux had disk space full (3)
Minidump Help (1)
I need help building a computer. 400-.. (33)
cant find drivers (8)
Redirect malware won't go away (6)
laptop keys broken!!1 (3)

Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
PLease need virus/Spyware help! shadowbot66 Security and Privacy Issues 11 July 25th, 2008 09:18 PM
I've got a virus/spyware DC4man Security and Privacy Issues 1 October 1st, 2007 01:55 PM
Buddy.exe Spyware Removal Phibz// Security and Privacy Issues 8 May 5th, 2005 06:48 PM
msnmgr32.exe spyware ltkenbo Technical Support 1 February 19th, 2005 05:09 PM
virus spyware what is this? mbandela000 Security and Privacy Issues 35 February 9th, 2005 07:50 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

All times are GMT -4. The time now is 07:42 PM.
TechIMO Copyright 2010 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28