spyware remover programs freeze up

tommydees

New Member
Ok I opened a web site the other day and before it opened all the way this file opened on its own. It was so fast that i couldnt really see it but it had something to do with spyware software. It was nothing i wanted or clicked on. My pc has been running like crap ever sense. Everytime i try and run spyware remover programs spybot s&d, and ad-aware se. It always runs really slow and ends up freezing my pc. the ad-aware se will run all the way through if i turn of the deep system registry scan it finds all kinds of problems but after i delete them they come back. ug never had this much trouble getting a bug off my pc. HELP!!!

Logfile of HijackThis v1.99.1
Scan saved at 4:17:35 AM, on 1/15/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\Software Programs\hijackthis\HijackThis1991.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Pro\CCHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2006\MemOptimizer.exe" autostart
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Installer) - http://supportcenter.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} - http://softdev.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136191248890
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5287868C-5529-4384-874C-A478EA2781F8}: NameServer = 85.255.116.121,85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5B0B31E-631A-4CB9-A1BF-FE4F316DFECE}: NameServer = 85.255.116.121,85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\..\{DAFDB704-B6DA-465B-B30B-E4EF0E4D1A92}: NameServer = 85.255.116.121,85.255.112.225
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
 
Ok i finally got the ad-aware to run in safe mode found a few problems and fixed them but now in my hijackthis log file theres something that i just cant figure out what it is i have searched on google with no luck. any ideas? also how does the rest of my logfile look is it clean?


Logfile of HijackThis v1.99.1
Scan saved at 6:22:38 PM, on 1/15/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\TuneUp Utilities 2006\MemOptimizer.exe
C:\Program Files\AIM95\aim.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Owner\Desktop\Software Programs\hijackthis\HijackThis1991.exe

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Pro\CCHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2006\MemOptimizer.exe" autostart
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136191248890
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5287868C-5529-4384-874C-A478EA2781F8}: NameServer = 85.255.116.121,85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5B0B31E-631A-4CB9-A1BF-FE4F316DFECE}: NameServer = 85.255.116.121,85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\..\{DAFDB704-B6DA-465B-B30B-E4EF0E4D1A92}: NameServer = 85.255.116.121,85.255.112.225
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe



this is what i cant figure out what it is

O17 - HKLM\System\CCS\Services\Tcpip\..\{5287868C-5529-4384-874C-A478EA2781F8}: NameServer = 85.255.116.121,85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5B0B31E-631A-4CB9-A1BF-FE4F316DFECE}: NameServer = 85.255.116.121,85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\..\{DAFDB704-B6DA-465B-B30B-E4EF0E4D1A92}: NameServer = 85.255.116.121,85.255.112.225
 
Why not remove (Fix) those items you're suspicious of (Be sure you have backups turned on with HiJack) and see how it runs.
 
I deleted (fixed) those files. So far everthing still seems to be operating fine. Does the rest of the log look clean? anything suspicious. I didnt see anything but im still new to the whole hijackthis thing. But back to the problem, My hijackthis log looks clean to me but my spybot s&d still wont run right. It starts then freezes up and i have to control+alt+delete it to end it. I have uninstalled it and reinstalled and no help. Also i d/l CCleaner and if i run the issues with the registry program i have to uncheck the MISSING SHARED DLLs or it freezes it will check every other one except that one. any ideas what it is
 
Last edited:
If you already fixed these!

O17 - HKLM\System\CCS\Services\Tcpip\..\{5287868C-5529-4384-874C-A478EA2781F8}: NameServer = 85.255.116.121,85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5B0B31E-631A-4CB9-A1BF-FE4F316DFECE}: NameServer = 85.255.116.121,85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\..\{DAFDB704-B6DA-465B-B30B-E4EF0E4D1A92}: NameServer = 85.255.116.121,85.255.112.225

The rest of your log is clean!
 
How are you suppose remove this kind of spyware if you cant run your spyware remover programs? I fixed it, I got tired of messing with it so I formated the hard drive and done a clean install. It's the first time sense I have owned the pc bought it back in 2003. It prolly needed it anyways.
 
Back
Top