1
   

Spyware Adware woes

 
 
egererf
 
Reply Thu 8 Jul, 2004 02:06 pm
I read the post from timberlandko
Posted: Mon Mar 22, 2004 4:54 pm Post: 611527 - Spyware, Browser Hijacks, or other Yuckware? Check here 1st
I did all the steps and am posting the Hijack this results (see below). I would appreciate any help on whether I have cleared my machine or not... before I did this, my maching basically was unuseable.... now it seems fine but I want to make sure I have gotten rid of them all. Thanks

Semper Fidelis
egererf

Logfile of HijackThis v1.98.0
Scan saved at 3:53:03 PM, on 7/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\gearsec.exe
C:\documents and settings\manager\local settings\temp\oU7krxw.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\3B Software\Windows Registry Repair Pro\Windows Registry Repair Pro.exe
C:\WINDOWS\System32\VetMsgNT.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\NDrv.exe
C:\Program Files\AccuWeatherDesktop\AccuWeatherDesktop.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Manager\Local Settings\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O4 - HKLM\..\Run: [AtariBanner] "C:\Program Files\Infogrames\Atari Anniversary Edition\Volume 2\Banner.exe" /0
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common Files\Java\breg.exe"
O4 - HKLM\..\Run: [oU7krxw] C:\documents and settings\manager\local settings\temp\oU7krxw.exe
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINDOWS\ARUpdate.exe
O4 - HKLM\..\Run: [Dsi] C:\WINDOWS\System32\dp-him.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [0F5V37j] lodll.exe
O4 - HKLM\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\Windows Registry Repair Pro.exe -X
O4 - HKLM\..\Run: [BTV] C:\Program Files\BTV\btv.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [NDrv] C:\WINDOWS\System32\NDrv.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q
O4 - Global Startup: AccuWeather.comĀ® Desktop.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,377 • Replies: 6
No top replies

 
Craven de Kere
 
  1  
Reply Thu 8 Jul, 2004 03:03 pm
What problems are you experiencing (personally I don't do "just in case" as I do not have the time to audit tedious logs when there is no problem)?
0 Replies
 
egererf
 
  1  
Reply Thu 8 Jul, 2004 03:39 pm
I guess I am really looking to know what all the processes are that are running as my computer is still a little slower than I remember. (my nieces visited and went crazy while I was overseas) so I have no idea what they may have downloade and the processes that are active. For example: what is oU7krxw.exe ??

SF/ E
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 8 Jul, 2004 04:05 pm
It's most likely spyware.

I'll audit your log.
0 Replies
 
Cyanure
 
  1  
Reply Thu 8 Jul, 2004 04:06 pm
egererf
Why don't you try a System Restore back to the date just before your nieces visit? Then you could see all processes running. And try to see which process is monopolizing your CPU resources.
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 8 Jul, 2004 04:32 pm
Re: Spyware Adware woes
Do not use system restore.


Fix = Use HJT to fix the entry
Uninstall = Use control panel to uninstall a program
Delete = First kill the process in the task manager. Manually delete the file, backup to removable media if you want to be protected from a possible id-10-t error on my part. You may have to boot into safemode to delete it.

egererf wrote:

C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Support.com\bin\tgcmd.exe


Both of these are supportware with privacy implications. They are not dangerous really, but unecessary.

Quote:
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe


Looks fishy, backup and delete.

Quote:
C:\documents and settings\manager\local settings\temp\oU7krxw.exe


Delete


Quote:
C:\Program Files\3B Software\Windows Registry Repair Pro\Windows Registry Repair Pro.exe


I do not know this software. I would uninstall it.

Quote:
C:\WINDOWS\System32\NDrv.exe


Delete

Quote:
C:\Program Files\AccuWeatherDesktop\AccuWeatherDesktop.exe


Uninstall or delete if uninstall is not possible.

Quote:
C:\WINDOWS\System32\HPZipm12.exe


I do not recognize. I would quarentine (copy to a removeable media, delete and see if it causes problems, if so, restore it).

Quote:
C:\Documents and Settings\Manager\Local Settings\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe


In the future, do not run HJT from a temporary directory. Save it to it's own directory in a memorable place.

Quote:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing


Fix

Quote:
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)


Fix

Quote:
O4 - HKLM\..\Run: [AtariBanner] "C:\Program Files\Infogrames\Atari Anniversary Edition\Volume 2\Banner.exe" /0
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe


Fix


Quote:
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf


Fix



Quote:
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe


Fix

Quote:
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe



These are from HP photo or print software. I would not have them, run on startup.

Quote:
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common Files\Java\breg.exe"


Fix


Quote:
O4 - HKLM\..\Run: [oU7krxw] C:\documents and settings\manager\local settings\temp\oU7krxw.exe


Fix, and delete the file

Quote:
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINDOWS\ARUpdate.exe


Fix and delete the file.

Quote:
O4 - HKLM\..\Run: [Dsi] C:\WINDOWS\System32\dp-him.exe


Fix, I'd also quarentine

Quote:
O4 - HKLM\..\Run: [0F5V37j] lodll.exe


Fix and delete

Quote:
O4 - HKLM\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\Windows Registry Repair Pro.exe -X


Fix


Quote:
O4 - HKLM\..\Run: [BTV] C:\Program Files\BTV\btv.exe


Fix and delete

Quote:
O4 - HKCU\..\Run: [NDrv] C:\WINDOWS\System32\NDrv.exe


Fix and delete

Quote:
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q


Fix and uninstall.

I do not know or trust this program and as you have about as infested a computer as possible it's obviously doing precious little good for you.

Quote:
O4 - Global Startup: AccuWeather.comĀ® Desktop.lnk = ?


Fix


Quote:
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe


Fix and delete

Quote:
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe


Fix and delete


Quote:
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com


Fix

Quote:
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab


Fix

Quote:

O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab


Fix


When you are done, reboot and do the following:

1) Run all your windows updates.

http://windowsupdate.microsoft.com/

Do this religiously. There are trojans on your computer that took advantage of the RPC exploit and if that is not patched your computer has a gaping hole.

2) Update your AV software (eZtrust) and run a full scan. Consider investing in decent AV software such as Norton.

3) In IE make IE prompt you for all active x download both signed and unsigned (maybe even just disable the unsigned ones).

In IE

Tools > Internet Options > Advanced

4) Don't let people download junk on your computer, make a non-admin account for them. I have seen fewer more infested machines, if this were mine I'd reformat it.

5) Download, Install, Update and run Spybot and AdAware

6) Reboot and let us know if you are clean now, this will help us help others
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 8 Jul, 2004 04:34 pm
Incidentally that took me about 30 minutes, I mention this to explain my earlier trepidation with auditing logs with no problem reported (nothing more frustrating than spending 30 minutes looking for a problem when the user "just wanted to check").
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Spyware Adware woes
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.05 seconds on 12/23/2025 at 05:31:10