Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Spyware problems and i have no idea how to fix it.

[Fixed] Hijackthis! Logs - [Fixed] Spyware problems and i have no idea how to fix it. posted in the Security & Safety forums; i got hit by a plethora of spyware the likes of which i have never witnessed. my wallpaper is now a 'warning' of sorts that reads: SPYWARE INFECTION (in red) ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-02-2006
philmydinger's Avatar
Bronze Member
 
Join Date: Jan 2006
Posts: 7
philmydinger - See this Members User comments on their Profile page
Default [Fixed] Spyware problems and i have no idea how to fix it.

i got hit by a plethora of spyware the likes of which i have never witnessed. my wallpaper is now a 'warning' of sorts that reads:

SPYWARE INFECTION (in red)
Your system is infected with spyware. Windows recommends you to use a spyware removal tool to prevent loss of important data and imcrease system performance. Using this PC before having it cleaned from spyware threads is highly discouraging.

I ran adaware and SpyBot in Safe Mode, and although things seem to be working better (the invasion of popups and programs that i never installed) are no longer present (or so i think) but the wall paper remains the same message, as if heckling me in some crude manner.

below is my hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 1:22:57 AM, on 1/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:



i thank whoever can help me or give suggestions.



Last edited by joe5; 01-03-2006 at 05:27 AM.
  #2  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Philmydinger , welcome to pchf.

You have indeed a severall nasty buggers on there. Can you first follow the instructions in the "Prework" link below and then attach the Ewido log and a new hjt log to a post?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 01-02-2006
philmydinger's Avatar
Bronze Member
 
Join Date: Jan 2006
Posts: 7
philmydinger - See this Members User comments on their Profile page
Default

for some reason i cannot run the setup applications for the two programs that the instructions say to run. i ran hijack this again here is the log:
Attached Files
File Type: log hijackthis.log (7.2 KB, 1 views)


  #4  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by philmydinger
for some reason i cannot run the setup applications for the two programs that the instructions say to run. i ran hijack this again here is the log:
Thats not very nice from them is it? lol. Oh well.


Make sure you still have system restore disabled , and hidden files set to show.


Please download Process Explorer by Systernals from HERE.

Also download KillBox by Option^Explicit from HERE.



Then uninstall these in add/remove programs if present:


Red Swoosh/rssoft
SoftwareOnline
SpySheriff


After that boot in safe mode (hit f8 when booting up)




Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of avpe32.dll once and then click the kill button.
After you have killed all of the avpe32.dll's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of avpe32.dll then click the kill button.

Once you have done that click OK again.


And then fix these with hjt:
(if still present)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} - (no file)
O2 - BHO: (no name) - {C5AF2622-8C75-4dfb-9693-23AB7686A456} - C:\WINDOWS\DH.dll
O4 - HKLM\..\Run: [lspins] "C:\WINDOWS\system32\igps.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SOProc_DAP] rundll32 shell32.dll,ShellExec_RunDLL C:\PROGRA~1\SOFTWAREONLINE\soproc.exe -pack DAP
O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSSoft\RSEDNClient.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\system32\sywsvcs.exe
O18 - Filter: text/html - {3551784B-E99A-474f-B782-3EC814442918} - (no file)
O20 - Winlogon Notify: avpe32 - C:\WINDOWS\SYSTEM32\avpe32.dll
Then delete the files in bold , and see if you can run ccleaner now.

Then manually delete these files if present from youre pc:

C:\WINDOWS\System32\avpe32.dll
C:\WINDOWS\System32\avpe64.sys
C:\WINDOWS\System32\klgcptini.dat
C:\WINDOWS\System32\qz.dll
C:\WINDOWS\System32\qz.sys
C:\WINDOWS\System32\stt82.ini
C:\WINDOWS\Web\wallpaper.html
C:\WINDOWS\Web\desktop.html
C:\Windows\Desktop.html
C:\wp.exe
C:\wp.bmp
C:\Program Files\SpySheriff <--- the whole folder
C:\Documents and Settings\username\Start Menu\Programs\SpySheriff <-whole folder
C:\Documents and Settings\username\Application Data\Install.dat



Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\WINDOWS\SYSTEM32\avpe32.dll

Click the red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)

After your computer has rebooted please Download this reg fix:
unzip and dubbel click on it and enter it to the registry.

http://users.telenet.be/marcvn/regfi...desktopfix.zip


Then run Hijackthis again and post a new Hijackthis log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 01-02-2006
philmydinger's Avatar
Bronze Member
 
Join Date: Jan 2006
Posts: 7
philmydinger - See this Members User comments on their Profile page
Default

still having trouble with it opening the apps.

now there is no warning message on the screen but the wall paper is just all black now. it also would let me remove 'red swoosh'
Attached Files
File Type: txt hijackthis2.txt (7.3 KB, 1 views)


  #6  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Did you stop after the "redswoosh" part? Everything is still there.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fixed] Somebody Help me! iexplore problems due to spyware! Osiris09 [Fixed] Hijackthis! Logs 110 02-25-2006 01:43 AM
Strange video problems Dihnekis Windows XP/2000 16 11-18-2005 08:32 PM
Microsoft Targets Sony 'Spyware' joe5 Security Watch 0 11-16-2005 04:34 AM
[Pending] Problems with Windows ME and Harddrive! gunnaknow Hard Drives 1 07-29-2005 02:55 PM
[Pending] Help With Spyware Bad!!!!! idigfoo9 Spyware / AdWare 1 07-11-2005 09:53 PM


All times are GMT +1. The time now is 10:38 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top