ComputerForum.com ComputerForum.com  

Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 09-20-2008, 08:35 AM   #1 (permalink)
Platinum Member
 
MBGraphics's Avatar
 
Join Date: Dec 2007
Location: Garden Grove CA
Age: 18
Posts: 811
Exclamation Need help please(I may have a virus/adware)

Hey there everybody, Just recently I have noticed my computer getting a little slower, so I did a sweep with Spy Sweeper. It caught 32 items overall One of them being "Adware". So I quarentined everything, restarted, then went back in and deleted it all then restarted again. This did absolutly nothing, I was still laging a LOT. And it was only getting worse. I was getting a few pop-ups but not many. Now there are maybe 1-2 pop-ups (nothing im THAT worried about).

My main concern is that now my internet is COMLETLY down, it wont let me access any websites or anything. I know it's not an internet problem because my dad's computer gets his internet through a router and my computer has the main line, so if I have no internet, he has no internet (but he has internet right now, and I dont, so I know it's somthing to do with thats messing with my computer).

The strange thing is everything else seems to be running pretty normal. Start-ups are horrible though, I had to force shut down (hold the power button) about 8-10 times today before it finaly let me fully boot.

Right now im running in "SafeMode with Networking" and internet works just fine (a bit slow and jumpy, but i think thats due to the safe mode.


Does anybody have any ideas of whats going on or how to fix it?
I can get a HijackThis log if needed.

Thanks in advanced!
-Mike
__________________
Mike Pics of my rig HERE
Case:Lian Li with Swiftek apogee watercooling
CPU: Intel Q6600 (2.4 GHz)
Video: NVIDIA GeForce 8800GTX BFG OC Edition. LG 23" 1080HD and Sharp 19"
RAM/Storage:4GB Kingston Hyper X DDR2/320GB(7,200RPM) an 160GB(10,000 RPM) internals, and 320GB External
Sound Card: Creative X-Fi XtremeGamer Fatality
OS: Windows Vista Home Premium (64-bit)
M-B-Photos
Winner of Photo Tournaments: Automobiles and Birds
MBGraphics is online now   Reply With Quote


Old 09-20-2008, 11:57 AM   #2 (permalink)
Diamond Member
 
cohen's Avatar
 
Join Date: Jan 2008
Location: Melbourne, Australia
Age: 15
Posts: 8,361
Default

Pls post a hijackthis log, and might be worth Downloading and installing + run Malware bytes, if you do, can you pls post that log.

thanks
__________________
Cohen
cohen is offline   Reply With Quote
Old 09-20-2008, 09:10 PM   #3 (permalink)
Platinum Member
 
MBGraphics's Avatar
 
Join Date: Dec 2007
Location: Garden Grove CA
Age: 18
Posts: 811
Default

Ok, here is the HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:37 PM, on 9/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://members.freewebs.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IntelMeM] "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe " -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [BJCFD] "C:\Program Files\BroadJump\Client Foundation\CFD.exe"
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [YOP] "C:\PROGRA~1\Yahoo!\YOP\yop.exe" /autostart
O4 - HKLM\..\Run: [UserFaultCheck] C:\WINDOWS\system32\dumprep 0 -u
O4 - HKLM\..\Run: [StxTrayMenu] "C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [{88263159-d7ea-a00a-302d-778d20c39157}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\dcftwsccwjivny.dll" DllStub
O4 - HKLM\..\Run: [BMc3f18164] "Rundll32.exe" "C:\WINDOWS\system32\nfxbdohd.dll",s
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [c0c2b2f8] rundll32.exe "C:\WINDOWS\system32\efcBtSkI.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Rainlendar2] "C:\Program Files\Rainlendar2\Rainlendar2.exe"
O4 - Startup: AutoBackup Launcher.lnk = C:\Program Files\Memeo\AutoBackup\MemeoLauncher.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: UltraMon.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1136011116468
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/4...l/gtdownls.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.44 85.255.112.180
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.44 85.255.112.180
O20 - AppInit_DLLs: xwvexa.dll gxnotq.dll dfhnhc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AutoBackup (BMUService) - Memeo - C:\Program Files\Memeo\AutoBackup\MemeoService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

--
End of file - 10034 bytes
__________________
Mike Pics of my rig HERE
Case:Lian Li with Swiftek apogee watercooling
CPU: Intel Q6600 (2.4 GHz)
Video: NVIDIA GeForce 8800GTX BFG OC Edition. LG 23" 1080HD and Sharp 19"
RAM/Storage:4GB Kingston Hyper X DDR2/320GB(7,200RPM) an 160GB(10,000 RPM) internals, and 320GB External
Sound Card: Creative X-Fi XtremeGamer Fatality
OS: Windows Vista Home Premium (64-bit)
M-B-Photos
Winner of Photo Tournaments: Automobiles and Birds
MBGraphics is online now   Reply With Quote
Old 09-20-2008, 09:16 PM   #4 (permalink)
Diamond Member
 
Respital's Avatar
 
Join Date: Aug 2007
Location: Canada
Age: 15
Posts: 2,646
Default

You mite want to clean up your start up entries as there are a lot. Otherwise I suggest taking a deeper look.

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.
__________________
Winner of Photo Tourney: Twilight
/My Rig:/
/Case :/ Antec Sonata III
/Power Supply :/ Antec Earthquake 500W
/Motherboard :/ Gigabyte P35-DSR3
/Processor :/ Intel E6850@3.4Ghz
/Ram :/ Consair 2x 1 Gb 800mhz
/Video Card :/ Zotac 8800 GT
/Monitor:/Samsung T220 w 20 000 : 1 Contrast and 2ms response time
/3DMark06 Score :/ 11730
Respital is offline   Reply With Quote
Old 09-21-2008, 12:30 AM   #5 (permalink)
Diamond Member
 
cohen's Avatar
 
Join Date: Jan 2008
Location: Melbourne, Australia
Age: 15
Posts: 8,361
Thumbs up

Quote:
Originally Posted by Respital View Post
You mite want to clean up your start up entries as there are a lot. Otherwise I suggest taking a deeper look.

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.
Yes do this, post the combo fix log and a fresh hijackthis.

Also for the next hijackthis log, can you pls do it in the full mode.

Thanks,
__________________
Cohen
cohen is offline   Reply With Quote


Old 09-21-2008, 01:30 AM   #6 (permalink)
Platinum Member
 
MBGraphics's Avatar
 
Join Date: Dec 2007
Location: Garden Grove CA
Age: 18
Posts: 811
Default

Well I just tried doing this, and it's not letting me get to any of those websites while on "Safe Mode with Networking" and whatever is infecting my computer has gotten bad enough to the point where Its literally impossible to boot normaly. Every time it will do one of a few things, freeze on the welcome screen so I have to re-boot, freeze after logging in so I have to re-boot or go to a blue screen.

Any other ideas?
__________________
Mike Pics of my rig HERE
Case:Lian Li with Swiftek apogee watercooling
CPU: Intel Q6600 (2.4 GHz)
Video: NVIDIA GeForce 8800GTX BFG OC Edition. LG 23" 1080HD and Sharp 19"
RAM/Storage:4GB Kingston Hyper X DDR2/320GB(7,200RPM) an 160GB(10,000 RPM) internals, and 320GB External
Sound Card: Creative X-Fi XtremeGamer Fatality
OS: Windows Vista Home Premium (64-bit)
M-B-Photos
Winner of Photo Tournaments: Automobiles and Birds
MBGraphics is online now   Reply With Quote
Old 09-21-2008, 01:32 AM   #7 (permalink)
Diamond Member
 
cohen's Avatar
 
Join Date: Jan 2008
Location: Melbourne, Australia
Age: 15
Posts: 8,361
Default

Google search and Download Malware Bytes Anti Malware, run it and post the log of that, if it works, and then we can go from there.
__________________
Cohen
cohen is offline   Reply With Quote
Old 09-21-2008, 01:39 AM   #8 (permalink)
TFT
VIP Member
 
TFT's Avatar
 
Join Date: Oct 2006
Location: Yorkshire, UK
Posts: 3,664
Default

Locate this one, it's a Trojan downloader and delete it
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe

Valid svchost files only reside in the system32 folder. I don't know enough on how to clean your system but by deleting that file may give you a start.
__________________
Operator: Dave
Operating System: XP Professional SP2
Processor: Intel E6750 Core Duo@3.20GHz
Graphics: Nvidia 8500GT
C: Drive 500GB
D: Drive 200GB
Memory: 2GB
Monitor: 22" Widescreen

------------------------------------------------
Winner of Photo Tournament - Eerie, Dark, Creepy--etc.
TFT is offline   Reply With Quote
Old 09-21-2008, 01:59 AM   #9 (permalink)
Platinum Member
 
MBGraphics's Avatar
 
Join Date: Dec 2007
Location: Garden Grove CA
Age: 18
Posts: 811
Default

Cohen, I just did a search and im not finding one like that, the title says thats what it is but it trys to make me DL somthing like AVG, Advance Anti Virus and some others. I'm not finding any that are actually called Malware Bytes Anti Malware.

TFT, I just went into HijackThis and checked that and hit "fix selected" so that should be fixed now.

any other ideas?
__________________
Mike Pics of my rig HERE
Case:Lian Li with Swiftek apogee watercooling
CPU: Intel Q6600 (2.4 GHz)
Video: NVIDIA GeForce 8800GTX BFG OC Edition. LG 23" 1080HD and Sharp 19"
RAM/Storage:4GB Kingston Hyper X DDR2/320GB(7,200RPM) an 160GB(10,000 RPM) internals, and 320GB External
Sound Card: Creative X-Fi XtremeGamer Fatality
OS: Windows Vista Home Premium (64-bit)
M-B-Photos
Winner of Photo Tournaments: Automobiles and Birds
MBGraphics is online now   Reply With Quote
Old 09-21-2008, 02:04 AM   #10 (permalink)
Diamond Member
 
cohen's Avatar
 
Join Date: Jan 2008
Location: Melbourne, Australia
Age: 15
Posts: 8,361
Default

Dowload and run this - http://www.malwarebytes.org/
__________________
Cohen
cohen is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus/Adware problems PunterCam Computer Security 2 03-18-2008 07:21 PM


All times are GMT +1. The time now is 09:55 PM.


Powered by: vBulletin Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.