Jump to content


Photo

Total chaos


  • Please log in to reply
4 replies to this topic

#1 Eye Spy

Eye Spy

    Member

  • New Member
  • Pip
  • 3 posts

Posted 21 July 2004 - 06:10 AM

Hi,
I'm stuck with spyware, and it is seriously damagin' my computer
First of all, every time i run iexplorer i get 'Home search' as homepage refering to res://rgsgx.dll/index.html#96676 (in the adress field)
second, if i type something in google in order to find something, it get a second window opened doing the same search but than with 'http://search-to-fin...q=dae&pin=96676'
Now the last thing is the most annoying one, every time i run my computer i can't get my desktop, if i press ctrl alt del, i see under processes many programs running under the same name, f.e. javaxd32.exe (15 times), if i trie to end its proces it just reappears, so it eats memory (so other applications can't run)
it happens over and over again, but than with other names

I hope u gurus can help me out!

Thx in advance
(srry for postin' it originally in the wrong forum)

Edited by Eye Spy, 21 July 2004 - 06:16 AM.


#2 H@ns

H@ns

    Forum Deity

  • Retired Staff - Helper
  • PipPipPipPipPip
  • 2,630 posts

Posted 21 July 2004 - 06:51 AM

Hi Eye spy and welcome to the forum :wave:

Could you please post an HijackThis log?

Download HijackThis (link below), save it to a permanent folder, like C:\HJT, double-click to run it, click on "Scan", click on "Save Log", now save it elsewere. Notepad will show up with your HijackThis log. Use Ctrl + A to select all, then use Copy and Paste to post your log here :cool:

Edit: DON'T FIX THINGS IN HIJACKTHIS YOURSELF! HijackThis shows also good entries who are needed for your system.

Edited by H@ns, 21 July 2004 - 07:06 AM.

Nucia Security Forums - Dutch Anti-Malware Support

#3 Eye Spy

Eye Spy

    Member

  • New Member
  • Pip
  • 3 posts

Posted 21 July 2004 - 07:24 AM

Here u are,


Logfile of HijackThis v1.97.7
Scan saved at 14:30:31, on 21-07-04
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\CTsvcCDA.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\nvsvc32.exe
D:\PROGRA~1\NeoWatch\NWSERVICE.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\javaxd32.exe
C:\WINNT\system32\iels.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\David Vermeersch\Desktop\Hijack this\HijackThis.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [CTStartup] D:\program files\Creative\SBAudigy\Program\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [Jet Detection] d:\program files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [zzzHPSETUP] E:\Setup.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Overnet] D:\Overnet\Overnet.exe -t
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [iels.exe] C:\WINNT\system32\iels.exe
O4 - HKCU\..\Run: [TaskTray] d:\program files\Creative\SBAudigy\Taskbar\CTLTray.exe
O4 - HKCU\..\Run: [Taskbar] d:\program files\Creative\SBAudigy\Taskbar\CTLTask.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKLM\..\RunOnce: [atlbg.exe] C:\WINNT\atlbg.exe
O4 - HKLM\..\RunOnce: [ipjg32.exe] C:\WINNT\system32\ipjg32.exe
O4 - HKLM\..\RunOnce: [crmz.exe] C:\WINNT\system32\crmz.exe
O4 - HKLM\..\RunOnce: [d3vg.exe] C:\WINNT\system32\d3vg.exe
O4 - HKLM\..\RunOnce: [apiou.exe] C:\WINNT\apiou.exe
O4 - HKLM\..\RunOnce: [crdd.exe] C:\WINNT\system32\crdd.exe
O4 - HKLM\..\RunOnce: [sysbw32.exe] C:\WINNT\sysbw32.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = D:\Program Files\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NeoWatch Startup.lnk = D:\Program Files\NeoWatch\NeoWatchTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &NeoTrace It! - D:\PROGRA~1\NeoWatch\NTXcontext.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macr...director/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.micr...922/wmv9VCM.CAB
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.googl...g/GoogleNav.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8026.4521643519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

#4 Eye Spy

Eye Spy

    Member

  • New Member
  • Pip
  • 3 posts

Posted 21 July 2004 - 09:00 AM

It really doesn't matter if u fix some of those

#5 H@ns

H@ns

    Forum Deity

  • Retired Staff - Helper
  • PipPipPipPipPip
  • 2,630 posts

Posted 21 July 2004 - 09:01 AM

I'm sorry. Before I can check some logs, I must become a Helper or better. You have to wait for an expert :)
Nucia Security Forums - Dutch Anti-Malware Support




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button