Jump to content


Photo

Progressive Hijack Problems...


  • Please log in to reply
3 replies to this topic

#1 guysiner

guysiner

    Member

  • Full Member
  • Pip
  • 5 posts

Posted 30 July 2004 - 03:10 PM

Serious infestation of my machine by these criminals. It started (I think) with lop.com. Reidrection of browser, resetting of start page etc. Then a new (blue) toolbar appeared. Now it's much worse - where sometimes I can't navigate at all and dreadful pop up ads appear all the time. Icons are even appearing on my desk top... I always know when they are altering my system because a tiny smiley appears at the end of my curser when navigating in explorer as the page is being re-set at their pleasure.

I've tried everything - Ad Aware, Spybot, Spyferret, Aluria and Hijackthis. Some items come up and are deleted, but they come straight back - even without re-boot because I'm on a broadband connection. I have tried to follow all your instructions but to no avail.

I enclose a logfile from HJT. But deleting things using that is (so far) a waste of time. Thus the first (RO) item in the log is obviously a redirection but it will reappear (or one similar) immediately when deleted by HJT.

Interestingly - I couldn't find any of the offending entries named in doxdesk... either files OR registry entries.

I need - and would much appreciate the help of an expert.

Thank you very much.

Guy Siner



Logfile of HijackThis v1.97.7
Scan saved at 20:40:09, on 30/07/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\csrss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Mixer.exe
F:\PROGRA~1\Avast4\ashDisp.exe
F:\PROGRA~1\Avast4\ashmaisv.exe
F:\Program Files\Philips ToUcam Camera\VProperty.exe
F:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
F:\Program Files\Messenger Plus! 3\MsgPlus.exe
F:\WINDOWS\System32\ctfmon.exe
F:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
F:\Program Files\Adsubtract\AdSub.exe
f:\progra~1\intern~1\iexplore.exe
F:\WINDOWS\System32\alg.exe
F:\Program Files\Avast4\aswUpdSv.exe
F:\Program Files\Avast4\ashServ.exe
F:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
f:\progra~1\intern~1\iexplore.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\Program Files\Tiny Personal Firewall\PERSFW.EXE
F:\WINDOWS\System32\tcpsvcs.exe
F:\WINDOWS\System32\snmp.exe
F:\WINDOWS\System32\svchost.exe
F:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\QuoteTracker\stocks.exe
F:\Documents and Settings\All Users\Start Menu\Programs\Security\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.wmkqtwbeb...GId/KRpqClV.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:3005
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - F:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar1.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - F:\Program Files\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar1.dll
O3 - Toolbar: AdSubtract Toolbar - {F14AABDD-0232-4e5a-9B52-4178AC0A62B5} - F:\WINDOWS\System32\adsubtb.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Fix-It AV] F:\PROGRA~1\Ontrack\Fix-It\MemCheck.exe
O4 - HKLM\..\Run: [avast!] F:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] F:\PROGRA~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [ToUcamVProperty] F:\Program Files\Philips ToUcam Camera\VProperty.exe
O4 - HKLM\..\Run: [Motive SmartBridge] F:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [amen bits] F:\PROGRA~1\HELPDE~1\warn multi mode.exe
O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: AdSubtract.lnk = F:\Program Files\Adsubtract\AdSub.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = F:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O8 - Extra context menu item: AdSubtract: Bypass Site - res://F:\Program Files\Adsubtract\AdSub.exe/360
O8 - Extra context menu item: AdSubtract: Cloak Image - res://F:\Program Files\Adsubtract\AdSub.exe/361
O8 - Extra context menu item: AdSubtract: Report Site - res://F:\Program Files\Adsubtract\AdSub.exe/359
O16 - DPF: ppctlcab - http://www.pestscan....er/ppctlcab.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan....r/axscanner.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab

#2 guysiner

guysiner

    Member

  • Full Member
  • Pip
  • 5 posts

Posted 30 July 2004 - 05:24 PM

Won't somebody please help me?

#3 guysiner

guysiner

    Member

  • Full Member
  • Pip
  • 5 posts

Posted 31 July 2004 - 07:59 AM

I know you guys are really busy...

Just thought I'd report that I've fixed several problems and may be on the way to a clean machine!

I'm sure you already know this - but Messenger Plus 3 was the main culprit in my case. This person - a woman I think - spyware/adware with her program. She hijacks your machine for her own use and earns a fortune for doing it. She's made my life hell for weeks.

My advice - consign the bitch to the recycle bin where she belongs.

Thanks for your time.

GS

#4 guysiner

guysiner

    Member

  • Full Member
  • Pip
  • 5 posts

Posted 31 July 2004 - 07:59 AM

bump




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button