Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Anti-spyware popups driving me nuts!

[Fixed] Hijackthis! Logs - [Fixed] Anti-spyware popups driving me nuts! posted in the Security & Safety forums; I fell for something and opened a certain .exe file, ever since I get popups every 5 minutes. I included a new HJT log, hopefully you can do something with ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-07-2005
Jeroen's Avatar
Mac User
My PC
 
Join Date: Oct 2005
Location: Hong Kong
Posts: 312
PC Experience: Diversely Experienced
Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page Jeroen - See this Members User comments on their Profile page
Send a message via MSN to Jeroen
Default [Fixed] Anti-spyware popups driving me nuts!

I fell for something and opened a certain .exe file, ever since I get popups every 5 minutes. I included a new HJT log, hopefully you can do something with it.

TIA
Attached Files
File Type: txt hijackthis.log.txt (9.0 KB, 7 views)


__________________
Rules - Prework - Reputation System - Dark Style - Publish PC Specs
Been helped by anyone? Click and consider a Donation!
Always have a copy of Knoppix handy!
  #2  
Old 11-07-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Ge64,

Let me take a look at your log and see where you are at.


TTFN

LGW


  #3  
Old 11-07-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

OK Ge64,

Yup, you clicked on something bad. But I think we can get you up and running again.

First, I would like you to run one or two online virus scans, you have a trojan that is not being picked up by your Norton AV. Try one of these


Free Online Virus Scanners


The following is a list of Free online virus scanners. It is a good idea to use more than one as no individual company could possibly be able to keep up with all of the hundreds of viruses released.[*]Housecall by Trend Micro[*]Activescan by Pandasoft[*][ulr=http://www.bitdefender.com/scan8/ie.html]Bitdefender Online Scanner[/url] by Bitdefender[*]Security Check by Semantec[*]Kaspersky File Scanner by Kaspersky[*]RAV Online Virus Scanner by RAV includes a free notification system



Before beginning please do the following;


Show hidden files and folders:
For 98/2000/ME:

1.double-click the My Computer icon
2.Click on the View menu, click Folder Options
3.Advanced Settings box, under the "Hidden files" folder, click Show all files.
4.If you see a warning message, click Yes.
5.Click Apply.
6.Click OK.


Pre-work clean up

Download CCleaner, Install and run it. Make sure that all options are checked including Advanced, click OK to all warnings. Click on the Analyze button, let it run. When it is finished, click on the Run Cleaner button, exit CCleaner.

Download the following and run it,
CWShredder

Download Ewido Security Suite
  • Install Ewido Security Suite.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu
  • Launch Ewido, there should be a big "E" icon on your desktop, double-click it.
  • The program will prompt you to update click the "OK" button
  • The program will now go to the main screen
  • You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
  • The update will start and a progress bar will show the updates being installed.*
  • After the updates are installed, exit ewido.
Once the updates are installed do the following:
  • If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Reboot into Safe Mode, restart your computer, tap the F8* key. Use your up arrow key to highlight Safe Mode, then hit enter.
Close all open windows/programs/folders and then run Ewido.* Have nothing else open while ewido performs its scan!
  • Click on Scanner , Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK, Complete system scan
  • Let the program scan the machine
  • If ewido finds anything, it will pop up a notification.*
NOTE:* We have been finding some cases of false positives with the new version of Ewido, so you need to step through the fixes one-by-one.* If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged.* In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action.*

DO NOT check "Perform action with all infections."* If you are unsure of an entry, select "none" for the time being.* We will see that in the log when you post it later and let you know if ewido needs to be run again.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.

Click Save report. Save the report to your desktop, exit ewido


Note:

If during your scan Ewido "crashes" or "hangs", please try scanning again. Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'. Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems. Click 'OK' and run a new scan.


Then run HijackThis choosing the top option to save a log file, save it to your desktop. When you post, please include a description of the problem you are having, and Attach your HijackThis log plus the Ewido log.


Next Run HijackThis!

Check and then fix the following entries, deleting the items in bold if they are still there.


C:\windows\sp2update00.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O3 - Toolbar: @msdxmLC.dll,-1@1043,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx possibly corrupted version of WPM, reinstall after fix
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)
O20 - Winlogon Notify: IPConfMSP - C:\WINNT\system32\m8280ifue8280.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\SmVyb2Vu\command.exe



STOP and Disable a bad Added Service

Click Start>Run and type in: services.msc
Click OK
In the Services window find: Command Service
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open HJT and click config > misc tools > “delete an NT service”
Copy and past: cmdService
Click OK.

Run CCleaner again, and reboot your computer. Run HJT once more and post your log back here.

Look forward to your reply,

TTFN

LGW



  #4  
Old 11-07-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Boot in safemode before fixing things with hjt.

And also add these to the fix list:


O4 - HKLM\..\Run: [msresearch] c:\windows\msresearch.exe
O4 - HKLM\..\Run: [sp2update] C:\windows\sp2update00.exe
O4 - HKLM\..\Run: [ntdll.dll] C:\windows\msresearch.exe
and delete the files in bold.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 11-08-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

:kiss: Thanks for keeping watch over my shoulder Joe, you are the best.

LGW


  #6  
Old 11-08-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

No prob ofcourse. You are doing a great job.

Only why did you add this:

O3 - Toolbar: @msdxmLC.dll,-1@1043,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

possibly corrupted version of WPM, reinstall after fix


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #7  
Old 11-08-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

That entry only showed up in HJTs and thread posts where a hijack had taken place, the regular listing of msdxm.ocx showed up without the @msdxmLC.dll,-1@1043 in all of the searches I did. So I figured if there was a chance it was corrupted, better safe than sorry and that WMP could be reinstalled.

Tj