New Pornstar Interviews - [more]
Introducing Lady LorReign

"Good oral on me turns me on. Also, knowing that my partner is enjoying themself,"
All Forums > Tech Talk > Tech Talk Forum Page 41 > Help (again) I've been Hijacked!
AuthorPost
JAGnLA All-Star Supporter
All-Star Member


people pay me NOT to get naked
1944 Posts
2/04
Posted - Jul 13 2006 : 2:22AM
The summer of my (computer's) discontent continues:

I have scads of protection on my PC, but somehow my homepage has been and continues to get hijscked everytime I reset it! The site is www.syssecuritysite.net, and thers is an accompanying pop-up to www.entertainpage.net.

I am running Symantec Anti-Virus and have run a full system scan. I have also scanned using Spysweeper , Spybot Search and Destroy and Ad-Aware , rebooting each time. All picked up nothing and the hijacking continues. Another component of this is an icon that randomly appears in my system tray. It is a yield sign with a pop-up alerting of spyware on my computer.

Has anyone ever experienced this or something like it and/or does anyone have any suggestions?

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 13 2006 : 4:22AM
This seems to be the best advice.

Doing a little more searching, there seems to be some question about whether you need to do more than just run the SmitFraudFix tool in Safe mode, so maybe you can just do that.

Edited by - hardware on 7/13/2006 4:52:15 AM

PL
Senior Member

God hates us all, you know it's true, God hates this place. - Slayer
1726 Posts
10/03
Posted - Jul 13 2006 : 7:06AM
Ya I ran in to it a lot when i was a comp tech.... the situation sucks.

First - PLEASE tell me you are using FireFox. I have yet had this happen to anyone using this browser, but that's not to say it can't.... Anyway, this should fix the hijacked homepage problem, but it may not fix that prog from popping up...

Second, the link provided is about the only way to get rid of it. However, be warned Hijackthis can fuck your shit up if you don't follow the instructions the person helping you gives.

Unfortunately I'm leaving for work related stuff come tomorrow and I'll be gone for a good week. I wanna see that Hijackthis log, so I'll check in as often as I can to see it. Maybe I can help, maybe others here can too. That forum looked like a good spot to try as well.

Good luck!

"The universe is hostile, So impersonal. Devour to survive." - Tool

JAGnLA All-Star Supporter
All-Star Member

people pay me NOT to get naked
1944 Posts
2/04
Posted - Jul 13 2006 : 8:38PM
I will give it a shot. I've been ruminating about Firefox for some while...I guess my lack of tchnological knowledge and experience just makes me insecure about changing.

Thanks again guys

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 13 2006 : 8:49PM
Several sources cite the ZLOB Trojan virus as the cause of this problem. Changing browsers may stop the page hijack but, obviously, it isn't going to remove the virus from your PC.
 
JAGnLA All-Star Supporter
All-Star Member

people pay me NOT to get naked
1944 Posts
2/04
Posted - Jul 13 2006 : 9:20PM
ran the smitfraud and it appears to have cleaned everything...seems to be functioning normally now.

Really don't know how to tell or what to do if it is in fact the newest trojan that caused this all.

I would be better prepared to deal with situations like this if I used the internet for somewthing other than surfing for porn!

Thanks again dudes

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 14 2006 : 3:33AM
Take a look at your SmitFraudFix log file. If you follow the thread on the site I sent you to you'll see that after-scan report ends with:
If your log file has a similar entry showing an EXE and/or DLL file then you've still got work to do, and you should continue through the rest of the steps outlined by the Tweaks.com moderator.
JAGnLA All-Star Supporter
All-Star Member

people pay me NOT to get naked
1944 Posts
2/04
Posted - Jul 15 2006 : 2:53AM
SHIT! You mean I STILL have to do ALL THAT??
here goes...
Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 15 2006 : 3:35AM
Only if you've got infected executables on your drive.
JAGnLA All-Star Supporter
All-Star Member

people pay me NOT to get naked
1944 Posts
2/04
Posted - Jul 15 2006 : 4:38AM
Well, I had the exact same ending to my report - so I followed all the mods steps. Took quite awhile, and I'm now hung up on the final step.

The mod there mentions that you have to turn off Sytem Restore and turn it back on again or the virus can remain. He directs to http://www.pchell.com/virus/systemrestore.shtml for instructions on how to do this.

However, that site gives directions for turning System Restore
on & off if you are running Windows ME or Windows XP.

I am running Windows 2000 Professional. I have tried both ways and neither applies. I cannot find the Sytem Restore Tab (or in the case of ME, cannot find the Performance, File System or Troubleshooting tabs) I have been trying all sorts of variations and I cannot seem to figure out how to turn this off and back on !

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 15 2006 : 1:45PM
I don't think Windows 2000 has the system restore feature, which would explain why you can't find it.
Redish All-Star Supporter
Poetic Moderator

Long and Cursive road to the Ivory Pagoda in the province of Loraine
4076 Posts
12/03
Posted - Jul 16 2006 : 1:59AM
Don't feel bad Jag, I got this earlier this year with Firefox. It came thru another way.

JAGnLA All-Star Supporter
All-Star Member

people pay me NOT to get naked
1944 Posts
2/04
Posted - Jul 16 2006 : 2:08AM
So having completed all the other cleansing actions absent of the System Restore...should I still be okay?
Redish All-Star Supporter
Poetic Moderator

Long and Cursive road to the Ivory Pagoda in the province of Loraine
4076 Posts
12/03
Posted - Jul 16 2006 : 2:42AM
Run hijack this again and for something out of the ordinary.

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 16 2006 : 2:51AM
Yes, you should be OK. You can run Hijackthis and post the log file if you want us to take a look and see.
 
JAGnLA All-Star Supporter
All-Star Member

people pay me NOT to get naked
1944 Posts
2/04
Posted - Jul 17 2006 : 4:16AM
Things appear to be okay, but here's the latest HiJack this log. Again, thanks for your assistance!

Logfile of HijackThis v1.99.1
Scan saved at 1:11:02 AM, on 7/17/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss .exe
C:\WINNT\system32\winlogon .exe
C:\WINNT\system32\services .exe
C:\WINNT\system32\lsass .exe
C:\WINNT\system32\svchost .exe
C:\WINNT\System32\svchost .exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr .exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr .exe
C:\WINNT\system32\spoolsv .exe
C:\WINNT\system32\netdde .exe
C:\Program Files\Symantec AntiVirus\DefWatch .exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService .exe
C:\Program Files\ewido anti-spyware 4.0\guard .exe
C:\WINNT\system32\regsvc .exe
C:\WINNT\system32\MSTask .exe
C:\WINNT\system32\stisvc .exe
C:\Program Files\Symantec AntiVirus\Rtvscan .exe
C:\WINNT\System32\WBEM\WinMgmt .exe
C:\WINNT\system32\mspmspsv .exe
C:\WINNT\system32\svchost .exe
C:\WINNT\Explorer .exe
C:\WINNT\system32\LVComS .exe
C:\WINNT\system32\pctspk .exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\PROGRA~1\SYMANT~1\VPTray .exe
C:\Program Files\GE\USB 2.0 Card Reader\shwicon2k .exe
C:\WINNT\system32\faxsvc .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\iPod\bin\iPodService .exe
C:\Program Files\Labtec Wireless Desktop\MagicKey .exe
C:\Program Files\Labtec Wireless Desktop\MulMouse .exe
C:\Program Files\Labtec Wireless Desktop\OSD .exe
C:\WINNT\system32\java .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Mozilla Firefox\firefox .exe
C:\PROGRA~1\INCRED~1\bin\IMApp .exe
C:\Documents and Settings\John\Desktop\HijackThis .exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.yahoo.com/config/login?.page=p1&.partner=&.intl=us&.src=my&.done=http://my.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {f7d40011-29bb-43eb-9c97-875ce89e9e36} - C:\WINNT\system32\hp100.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync .exe /logon
O4 - HKLM\..\Run: [LVCOMS] C:\WINNT\system32\LVComS .exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart .exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray .exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk .exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook .exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINNT\p_981116 .exe /Q:A
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck .exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon .exe"
O4 - HKLM\..\Run: [seekmo] "c:\program files\seekmo\seekmo .exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook .exe /auto
O4 - HKLM\..\Run: [winlog] winlog .exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates .exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp .exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray .exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\GE\USB 2.0 Card Reader\shwicon2k .exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper .exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched .exe" -osboot
O4 - HKLM\..\RunServices: [winlog] winlog .exe
O4 - HKCU\..\Run: [bwt8RRGml] qca49 .exe
O4 - HKCU\..\Run: [POPUPWATCH] C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\PopUpWatch .exe /STARTUP
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ .exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl .exe
O4 - Global Startup: Enable Labtec Wireless Desktop.lnk = C:\Program Files\Labtec Wireless Desktop\MagicKey .exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA .exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download with Go!Zilla - file://C:\Program Files\Go!Zilla\download-with-gozilla.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim .exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager .exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager .exe
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr .exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc .exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr .exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch .exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService .exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin .exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard .exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT .exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam .exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc .exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc .exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan .exe

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 17 2006 : 10:59AM
You probably want to get rid of that adware program.
JAGnLA All-Star Supporter
All-Star Member

people pay me NOT to get naked
1944 Posts
2/04
Posted - Jul 17 2006 : 5:57PM
Yeah, I just noticed that...I wonder why all of these different programs left it? I ran Ad Aware, Symantec Anti-virus, Spysweeper, SpyBot Search & Destruy, and then later the ATF Cleaner and Ewido!

Should I re-run any one (or all) of these?

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 17 2006 : 6:37PM
If you're positive that you have the latest definition files for those programs then running them again won't help. However, if you aren't positive then that's the place to start. Also, it may be necessary to use them in Safe Mode.

If you're comfortable with editing the registry you can follow the instructions here. They seem pretty straight forward.

Note the tool they claim will automagically remove it for you. I have no info about these guys, so use it at your own risk.

Here's another site that claims to be able to remove it. Again, I don't know anything about them.

JAGnLA All-Star Supporter
All-Star Member

people pay me NOT to get naked
1944 Posts
2/04
Posted - Jul 18 2006 : 6:46AM
Hardware, thanks tons, man!
I deleted the files manually after doing some research and finding out that the link was to a software that would only detect them, but one had to buy the "full version" to remove them.

Here is my last HiJack this report...it appears okay to my uneducated eyes.

Logfile of HijackThis v1.99.1
Scan saved at 3:36:26 AM, on 7/18/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss .exe
C:\WINNT\system32\winlogon .exe
C:\WINNT\system32\services .exe
C:\WINNT\system32\lsass .exe
C:\WINNT\system32\svchost .exe
C:\WINNT\System32\svchost .exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr .exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr .exe
C:\WINNT\system32\spoolsv .exe
C:\WINNT\system32\netdde .exe
C:\Program Files\Symantec AntiVirus\DefWatch .exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService .exe
C:\Program Files\ewido anti-spyware 4.0\guard .exe
C:\WINNT\system32\regsvc .exe
C:\WINNT\system32\MSTask .exe
C:\WINNT\system32\stisvc .exe
C:\Program Files\Symantec AntiVirus\Rtvscan .exe
C:\WINNT\Explorer .exe
C:\WINNT\System32\WBEM\WinMgmt .exe
C:\WINNT\system32\mspmspsv .exe
C:\WINNT\system32\svchost .exe
C:\WINNT\system32\LVComS .exe
C:\WINNT\system32\pctspk .exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
C:\WINNT\system32\faxsvc .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\PROGRA~1\SYMANT~1\VPTray .exe
C:\Program Files\GE\USB 2.0 Card Reader\shwicon2k .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\iPod\bin\iPodService .exe
C:\Program Files\Labtec Wireless Desktop\MagicKey .exe
C:\Program Files\Labtec Wireless Desktop\MulMouse .exe
C:\Program Files\Labtec Wireless Desktop\OSD .exe
C:\Program Files\Mozilla Firefox\firefox .exe
C:\Documents and Settings\John\Desktop\antispy_virus\HijackThis .exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.yahoo.com/config/login?.page=p1&.partner=&.intl=us&.src=my&.done=http://my.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {f7d40011-29bb-43eb-9c97-875ce89e9e36} - C:\WINNT\system32\hp100.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync .exe /logon
O4 - HKLM\..\Run: [LVCOMS] C:\WINNT\system32\LVComS .exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart .exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray .exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk .exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook .exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINNT\p_981116 .exe /Q:A
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck .exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon .exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook .exe /auto
O4 - HKLM\..\Run: [winlog] winlog .exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates .exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp .exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray .exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\GE\USB 2.0 Card Reader\shwicon2k .exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper .exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched .exe" -osboot
O4 - HKLM\..\RunServices: [winlog] winlog .exe
O4 - HKCU\..\Run: [bwt8RRGml] qca49 .exe
O4 - HKCU\..\Run: [POPUPWATCH] C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\PopUpWatch .exe /STARTUP
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ .exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl .exe
O4 - Global Startup: Enable Labtec Wireless Desktop.lnk = C:\Program Files\Labtec Wireless Desktop\MagicKey .exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA .exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download with Go!Zilla - file://C:\Program Files\Go!Zilla\download-with-gozilla.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim .exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager .exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager .exe
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr .exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc .exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr .exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch .exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService .exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin .exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard .exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT .exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam .exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc .exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc .exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan .exe

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 18 2006 : 11:39AM
Looks clean to me.

If you deleted the files but not the registry entries you may get some error messages at startup. However, the program itself can't run without those files.

BTW, I found out that you got the Seekmo adware courtesy of Logitech. Apparently they bundle (bundled?) it with their mouse driver software. Just goes to show that you should never just 'accept all' when doing a software install, no matter who it's from.

At any rate, this probably explains why none of your spyware/adware programs dealt with it.

BigBobxxx
Senior Member

2681 Posts
5/04
Posted - Jul 18 2006 : 2:57PM
JAG, I strongly suggest that you download and use the following two programs:
Counter Spy (for spyware & adware, etc.)
AVG Anti-Virus (for virus protection)

I'm saying get them and use them in addition to what you already have -- at least to run now that you think you've fixed your problem(s). I'm betting that they will find things that have been missed to date.

AVG offers a totally-free version for personal use only on one computer.
100% Virus Detection by AVG...
GRISOFT once again received the VB100% Award by independent malware advisor, Virus Bulletin, in June 2006. AVG Anti-Virus proved itself by detecting all In the Wild viruses, while generating no false positives, during both on-demand and on-access scanning in Virus Bulletin's comparative tests.

It will find things other programs have missed :)

AVG Anti-Virus Home Page

AVG Free Edition

Counter Spy offers a free 15-day trial.
This is a top-rated adware/spyware program, and is very much worth running it for at least the two free weeks.
It will find things other programs have missed :)

Counter Spy Home Page

Counter Spy 15-day Free Trial

I was so pleased with both of these products, that I went ahead and purchased them.

Counter Spy is rated #1 by PC World:

http://www.pcworld.com/reviews/article/0,aid,119572,pg,2,00.asp#

http://www.pcworld.com/reviews/article/0,aid,119572,00.asp

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Jul 18 2006 : 3:44PM
Whoa, big fella! You should never run more than one antivirus program on your PC at a time. If Jag wants to replace what he's got that's fine but, if so, he should download the new program, uninstall his current one and only then load the new one (and don't forget to cancel your subscription to the old one!).
BigBobxxx
Senior Member

2681 Posts
5/04
Posted - Jul 18 2006 : 4:26PM
Yes, I know that.
I should have been clearer.

In the case of running the AVG Anti-virus, disable your other anti-virus program(s) before running it.
You don't have to run every anti-virus program on your computer even though it is installed.
Most anti-virus programs will place an icon in the Task Bar "Tray" that you can usually right-click on and turn features on and off.

IF you find that AVG is finding things Symantec has missed (not real hard to do), I think the decision as to which one to keep and use will become obvious... certainly by the time you need to send Symantec more money again.

In the case of my Counter Spy recommendation, you can run these adware/spyware programs as needed without a conflict problem.
Note: You already are doing this now, as you stated you are using Spybot Search and Destroy and Ad-Aware.
Counter Spy is even better.
The 15-day free trial may find things that Spybot Search and Destroy and Ad-Aware missed.

cobalt60
Knuckle Dragger

2046 Posts
2/03
Posted - Jul 19 2006 : 3:28PM
Fucking HijackThis logs on ADT. Hell freezeth over.
 
Bornyo
Deactivated Member

803 Posts
12/04
Posted - Jul 19 2006 : 3:33PM
Hey Cobalt, How's it going?
All Forums > Tech Talk > Tech Talk Forum Page 41Help (again) I've been Hijacked!

Previous topic: best dvd player for imports
Next topic: Anti-Spyware



Jump To: