Adware/Spyware Problems, A Hijack This Log - testmy.net resource / tool
Home
Welcome, Guest. Please login or register.
Did you miss your activation email?

 



donations help testmy.net pay for the very high cost to run the site. Any amount is greatly appreciated.
Click to read why...

  spcr
    
News : angel Do you think your good enough to write news for testmy.net?  Shoot me a PM and you may be accepted to write for us, a title of nobility Smile September 07, 2008, 10:59:48 AM
testmy.net Broadband  |  Main Forum  |  PC Security  |  Security Threats  |  Topic: Adware/Spyware Problems, A Hijack This Log Advanced search
  0 Members and 1 Guest are viewing this topic. « previous next »
Pages 1 Go Down
Author
Topic: Adware/Spyware Problems, A Hijack This Log  (Read 2257 times)
Altoidz
Full Member
*
Offline Offline

Gender: Male
Posts: 50



View Profile
« on: May 29, 2006, 08:46:19 AM »

Logfile of HijackThis v1.99.1
Scan saved at 10:43:45 AM, on 5/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Cacheman\Cacheman.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TuneUp Utilities 2006\MemOptimizer.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Adobe\Adobe Photoshop CS2\Photoshop.exe
C:\DOCUME~1\Luong\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\Luong\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Opera 9 Beta\Opera.exe
C:\Documents and Settings\Luong\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.accoona.com/search?q=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
R3 - Default URLSearchHook is missing
O1 - Hosts: 70.85.169.18 update.nprotect.com
O1 - Hosts: 70.85.169.18 update.nprotect.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE 4.x-6.x BHO for Internet Download Accelerator - {2A646672-9C3A-4C28-9A7A-1FB0F63F28B6} - C:\PROGRA~1\IDA\idaiehlp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: IDA Bar - {C70E30C7-140A-4166-A2E8-43557E62B41A} - C:\Program Files\IDA\idabar.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [Cacheman] C:\Program Files\Cacheman\Cacheman.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2006\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [startsign] C:\DOCUME~1\Luong\APPLIC~1\FILMRE~1\win more link.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O8 - Extra context menu item: Download ALL with IDA - C:\Program Files\IDA\idaieall.htm
O8 - Extra context menu item: Download with IDA - C:\Program Files\IDA\idaie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe
O9 - Extra 'Tools' menuitem: &Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://9dragons.acclaim.com/acclaim.cab
O16 - DPF: {7B41B7AC-3496-4C13-A70F-DE6B60A6A8A8} (MGAME manager Class) - http://www.legendofares.com/download/mgusamanagerv1001.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: LMIinit - LMIinit.dll (file missing)
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
O23 - Service: Access Remote PC Service 4.9 - Unknown owner - C:\Program Files\Access Remote PC 4.9\rpcsetup.exe" /service (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe



The problem is that lately, I've been having pop-ups from ad.firstsolutionad.com or something, and I've tried spybot scans, ad-aware scans, ewido scans, xoftspy scans, all of that and even in safemode. I've also tried a virus scan and no luck, but hijack this seems to solve most problems, so hopefully you guys can help me out here. Very Happy
Logged

[
Coknuck
Global Moderator
TMN Sr. Veteran
*
Offline Offline

Gender: Male
Posts: 4626


Insightbb. Kentucky 10Mbps/1Mbps


View Profile
« Reply #1 on: May 29, 2006, 08:51:37 AM »

I ran your log and this is what I got:
http://hijackthis.de/logfiles/09879edd865e5d6036b697907fccca45.html

If this link dose not work for you copy your log and post it here:

http://hijackthis.de/
Logged

Read these "3" topics first Before posting speed problems  http://testmy.net/topic-2097 & http://testmy.net/forum/t-3924 & http://www.testmy.net/t-4257
                     
"Life is not a journey to the grave with the intention of arriving safely in a pretty and well-preserved body, but rather to skid in broadside, thoroughly used up, totally worn out and loudly proclaiming, WOW! What a ride!"
dlewis23
Global Moderator
TMN Seasoned Veteran
*
Online Online

Gender: Male
Posts: 9608


HEY! ill put it down when im good and ready.


View Profile
« Reply #2 on: May 29, 2006, 08:56:15 AM »

Altoidz are your popups just totally random in windows, they come up even if IE is not open?
Logged

Altoidz
Full Member
*
Offline Offline

Gender: Male
Posts: 50



View Profile
« Reply #3 on: May 29, 2006, 09:16:35 AM »

Thanks for such a quick reply coknuck. That's a nice site! So far, 5 minutes since reboot and things seem ok. I hope they stay that way. Also dlewis, yes. They pop-up even if IE isn't open. I use Opera by the way.
Logged

[
Altoidz
Full Member
*
Offline Offline

Gender: Male
Posts: 50



View Profile
« Reply #4 on: May 29, 2006, 05:48:49 PM »

Dang it. They're back! It was good for about an hour or so. My hijackthis log is clean. Anybody have anything else I should try?
Logged

[
the_webninja
New Member
*
Offline Offline

Posts: 5


View Profile
« Reply #5 on: January 27, 2008, 05:27:33 AM »

REMOVE: Google Tool Bar, Yahoo Tool Bar, MSN Messenger, Tune Up, And what in the hll is Alcohol Soft? Remove that too.
Looks like you have a Habbit of Downloading a lot of Crap which is what got you into this mess in the  first place.
If you want a Clean Problem Free machine, the first step is to keep it Clean and not Download a bunch of Crap.
All these Google Desk Top and Tool bars and Messengers these things all screw with your system performance. Not to mention leave you open for Scripts and Bugs constantly.
Get rid of all that Garbage.
Yes you can use Yahoo and MSN Messengers and Chat features without screwing up your System, but you have to reinstall them every so often to keep the Files in order, otherwise they get everything all screwed up. And I would not use Google Desk Top or Tool Bars because they have been Hacked quite often.
This allows a Hacker to put Bugs and Scripts and Garbage on your Machine.

At this point maybe it is best you just Format your Hard drive and start over. And next time THINK before you download something.

You can try Defraging your Hard Drive first to see if maybe that will help. Then Re-install Windows, and all your Messenger stuff, see how that works.
Go to START>RUN>Type in "Msconfig"
Go To: START TAB
Un Check everything you are not using on the Boot.
If you don't know what it is, then do not uncheck it.

Uninstall all programs that you are not using.
Defrag your Hard Drive
START>PROGRAMS>ACESSORIES>SYSTEM TOOLS>DEFRAG
This should make your computer run better.

Download Ad-aware at Lavasoft.com
It's free and it works!

This should help, if it doesn't re-install windows.
Or Download Linux at Linux.com

 cool
Logged
Print  Pages 1 Go Up
testmy.net Broadband  |  Main Forum  |  PC Security  |  Security Threats  |  Topic: Adware/Spyware Problems, A Hijack This Log « previous next »
Jump to:  

    
testmy.net's forum is proudly Powered by SMF | SMF © 2006-2007, Simple Machines LLC
Bookmark: Del.icio.us    StumbleUpon
 
 

 

© 1999-2008 testmy.net - Contact - Legal - Facts & FAQs
Page Loading Stats: This forum Page created in 0.124 seconds with 35 queries.