Jump to content


Photo

SPYWARE PROBLEM


  • Please log in to reply
3 replies to this topic

#1 somers24

somers24

    Member

  • New Member
  • Pip
  • 4 posts

Posted 24 June 2004 - 10:44 PM

Guys, I have been reading your thread alot and trying to fix my spyware problem. SO basically I am going word for word on what you are instructing me to do. Here is my log file, please take a peek if you can and let me know what to do next. THANKS alot in advance and no I will not PM or e-mail and bug the crap out of anyone. Just need a little help and will gladly pass on any info to the next guy looking.

Here it is...

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Common files\WinTools\WToolsS.exe
C:\WINDOWS\system32\appao.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common files\WinTools\WToolsA.exe
C:\WINDOWS\System32\fmdnquc.exe
C:\WINDOWS\system32\iebg.exe
C:\WINDOWS\System32\mcc.exe
C:\Documents and Settings\fs\Application Data\ttdu.exe
C:\WINDOWS\System32\windll32.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Common files\WinTools\WSup.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\fs\Local Settings\Temporary Internet Files\Content.IE5\GTGFSVS3\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\iplro.dll/sp.html#1953722985
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://iplro.dll/index.html#1953722985
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://iplro.dll/index.html#1953722985
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\iplro.dll/sp.html#1953722985
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://iplro.dll/index.html#1953722985
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\iplro.dll/sp.html#1953722985
R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - {CE6391C4-346E-13E9-03A2-E8708CCA3B6A} - C:\WINDOWS\system32\ntrh.dll
O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [fazlrjfocis] C:\WINDOWS\System32\fmdnquc.exe
O4 - HKLM\..\Run: [intdctrr] C:\WINDOWS\System32\idctup20.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [iebg.exe] C:\WINDOWS\system32\iebg.exe
O4 - HKLM\..\Run: [zSearch] C:\Program Files\zSearch\Zstb.exe
O4 - HKLM\..\Run: [Multimedia Codecs] C:\WINDOWS\System32\mcc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [Smob] C:\Documents and Settings\fs\Application Data\ttdu.exe
O4 - HKCU\..\Run: [windll32.exe] C:\WINDOWS\System32\windll32.exe
O4 - HKCU\..\Run: [zSearch] C:\Program Files\zSearch\Zstb.exe
O4 - HKLM\..\RunOnce: [ipzk32.exe] C:\WINDOWS\system32\ipzk32.exe
O4 - HKLM\..\RunOnce: [winzt32.exe] C:\WINDOWS\winzt32.exe
O4 - HKLM\..\RunOnce: [javaak32.exe] C:\WINDOWS\system32\javaak32.exe
O4 - HKLM\..\RunOnce: [winqm.exe] C:\WINDOWS\winqm.exe
O4 - HKLM\..\RunOnce: [msfb.exe] C:\WINDOWS\system32\msfb.exe
O4 - HKLM\..\RunOnce: [ipeb32.exe] C:\WINDOWS\system32\ipeb32.exe
O4 - HKLM\..\RunOnce: [addvf32.exe] C:\WINDOWS\system32\addvf32.exe
O4 - HKLM\..\RunOnce: [sysyp32.exe] C:\WINDOWS\system32\sysyp32.exe
O4 - HKLM\..\RunOnce: [ntld.exe] C:\WINDOWS\ntld.exe
O4 - HKLM\..\RunOnce: [crkl.exe] C:\WINDOWS\crkl.exe
O4 - HKLM\..\RunOnce: [winfp32.exe] C:\WINDOWS\winfp32.exe
O4 - HKLM\..\RunOnce: [javaze32.exe] C:\WINDOWS\system32\javaze32.exe
O4 - HKLM\..\RunOnce: [winwn32.exe] C:\WINDOWS\winwn32.exe
O4 - HKLM\..\RunOnce: [atlmv.exe] C:\WINDOWS\atlmv.exe
O4 - HKLM\..\RunOnce: [mszr.exe] C:\WINDOWS\mszr.exe
O4 - HKLM\..\RunOnce: [d3kd.exe] C:\WINDOWS\d3kd.exe
O4 - HKLM\..\RunOnce: [ieon32.exe] C:\WINDOWS\system32\ieon32.exe
O4 - HKLM\..\RunOnce: [netgv.exe] C:\WINDOWS\system32\netgv.exe
O4 - HKLM\..\RunOnce: [ievl32.exe] C:\WINDOWS\system32\ievl32.exe
O4 - HKLM\..\RunOnce: [atlda.exe] C:\WINDOWS\system32\atlda.exe
O4 - HKLM\..\RunOnce: [winqg.exe] C:\WINDOWS\system32\winqg.exe
O4 - HKLM\..\RunOnce: [netvt32.exe] C:\WINDOWS\netvt32.exe
O4 - HKLM\..\RunOnce: [crtb.exe] C:\WINDOWS\crtb.exe
O4 - HKLM\..\RunOnce: [winru32.exe] C:\WINDOWS\system32\winru32.exe
O4 - HKLM\..\RunOnce: [nethi.exe] C:\WINDOWS\nethi.exe
O4 - HKLM\..\RunOnce: [appmq.exe] C:\WINDOWS\system32\appmq.exe
O4 - HKLM\..\RunOnce: [sysyc.exe] C:\WINDOWS\system32\sysyc.exe
O4 - HKLM\..\RunOnce: [appwp.exe] C:\WINDOWS\appwp.exe
O4 - HKLM\..\RunOnce: [ntgt.exe] C:\WINDOWS\system32\ntgt.exe
O4 - HKLM\..\RunOnce: [cruz.exe] C:\WINDOWS\cruz.exe
O4 - HKLM\..\RunOnce: [javato32.exe] C:\WINDOWS\javato32.exe
O4 - HKLM\..\RunOnce: [sdkcn32.exe] C:\WINDOWS\sdkcn32.exe
O4 - HKLM\..\RunOnce: [sysog32.exe] C:\WINDOWS\sysog32.exe
O4 - HKLM\..\RunOnce: [crpv.exe] C:\WINDOWS\system32\crpv.exe
O4 - HKLM\..\RunOnce: [netwa32.exe] C:\WINDOWS\netwa32.exe
O4 - HKLM\..\RunOnce: [netkr.exe] C:\WINDOWS\netkr.exe
O4 - HKLM\..\RunOnce: [apigg32.exe] C:\WINDOWS\system32\apigg32.exe
O4 - HKLM\..\RunOnce: [ntoz32.exe] C:\WINDOWS\system32\ntoz32.exe
O4 - HKLM\..\RunOnce: [winex.exe] C:\WINDOWS\winex.exe
O4 - HKLM\..\RunOnce: [ntjq32.exe] C:\WINDOWS\system32\ntjq32.exe
O4 - HKLM\..\RunOnce: [ipxx32.exe] C:\WINDOWS\ipxx32.exe
O4 - HKLM\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\RunOnce: [crwc32.exe] C:\WINDOWS\crwc32.exe
O4 - HKLM\..\RunOnce: [ieey32.exe] C:\WINDOWS\ieey32.exe
O4 - HKLM\..\RunOnce: [msqd.exe] C:\WINDOWS\msqd.exe
O4 - HKCU\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for ¸وج: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

#2 somers24

somers24

    Member

  • New Member
  • Pip
  • 4 posts

Posted 24 June 2004 - 11:07 PM

bump

#3 somers24

somers24

    Member

  • New Member
  • Pip
  • 4 posts

Posted 25 June 2004 - 11:10 AM

bump (please help)

#4 somers24

somers24

    Member

  • New Member
  • Pip
  • 4 posts

Posted 25 June 2004 - 12:22 PM

bumpety bump bump, someone pleaseeeeeeeeeeeee help me




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button