PDA

View Full Version : New user needs help.



Bugzor
2006-11-01, 03:08
First...
I'd like to apologize in advance if the following isn't exactly proper etiquette for posting problems on these forums(I kinda posted this in a hurry and didn't have time to read any stickys).

Onto my problem...
Today I recieved 2 IE error messages saying something along the lines of "This page contains known security flaws." and it gave me the option to cancel. So I cancel and a repeat error popup comes up. I cancel again. No more popup.

I have probably had IE used on this computer twice by friends...And I think it was only for myspace.

I'm a regular user of Spybot and occasionally Adaware...So I decided to run a scan
When I was through scanning with spybot I noticed a unusual file in the end result
"Win32.small.ddx"
I briefly read up on the topic and saw several explinations about what it is and how to fix it...It left me slightly confused.

So I just fixed it via spybot and took some advice from reading posts here and cleared my cookies then blocked them from the sites:
emjcd.com
c.cenhance.com
apmebf.com

Upon doing this I ran another scan and came up with:
Tagasaurus

I fixed that and blocked cookies from:
ad.yeildmanager.com (Not so sure it came from this site..I don't totally recall if thats why I blocked this. Sorry I have bad memory..)

I ran another scan and came up with cookies from Fastclick.net.

I didn't visit any sites in the time between scans other than These forums and Yahoo.com to check my mail for the registry verification email.
As for today in general, I've only visited 3 sites(none of which are unusual from my daily browsing. This is excluding Yahoo.com and These forums.):
www.Myspace.com
www.Thottbot.com
www.Google.com(My homepage)

I've never had any such spybot results before..
And I really don't browse many sites other than the few I view every day.

Oh...and Upon checking just now I see that I've got FastClick cookies again without me going to a site.

Hopefully someone can point me in the right direction to fixing all this.

Thank you for taking the time to read this.

pskelley
2006-11-01, 14:14
Welcome to the forum, the best thing I can do for you is point you towards the stickys (pinned) because you can't get started here until you read and follow at least these instructions.

Please be advised that most forums Pin the information you need at the top of the page. These two links are a must before you can proceed, but I suggest you review all Pinned (Sticky) information.
UPDATED WINDOWS - Your first line of defence, links and tips
http://forums.spybot.info/showthread.php?t=425
"BEFORE you POST" -Preliminary Steps and scanning with SPYBOT-S&D
http://forums.spybot.info/showthread.php?t=288
Use the "Post Reply" to post the information in the instructions.

I'll toss in this information, cookies are a part of doing business on the web. Some sites are not available without a cookie, much security involves cookies as well as passwords. I will post information for controlling cookies, both IE and Firefox.

http://www.mvps.org/winhelp2002/cookies.htm
http://www.microsoft.com/windows/ie/using/howto/privacy/config.mspx

http://privacy.getnetwise.org/browsing/tools/firefox1/ffdisablecookies
http://www.mozilla.org/projects/security/pki/psm/help_21/using_priv_help.html

Since IE-7 and Firefox 2.0 have been released, this information may have changed.

Thanks

Bugzor
2006-11-01, 23:09
Okay...I ran HJT and heres the log:

Logfile of HijackThis v1.99.1
Scan saved at 4:05:53 PM, on 11/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\Files\Downloads\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1104779077781
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54GSSVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe" "WMP54GSv1_1.exe (file missing)

Is that any more help?

pskelley
2006-11-01, 23:18
To tell you the truth, what would be helpful would be if you would review the information I am posting for you and follow the instructions.
Please open this link: http://forums.spybot.info/showthread.php?t=288 and read the instructions tashi has posted: Please take the following steps before you post.

Thanks

pskelley
2006-11-01, 23:28
Logfile of HijackThis v1.99.1 Scan saved at 4:05:53 PM, on 11/1/2006

I see nothing wrong in this HJT log except an out of date Java program which will get you infectted. see this information:
http://forums.spybot.info/showpost.php?p=12880&postcount=2
C:\Program Files\Java\jre1.5.0_06\ <<< out of date

Perhaps the virus scan required before posting will show something. The stuff you mentioned all looks like cookies. Make sure you post the exact name and location of anything found and the name of the program that located it.

Thanks

tashi
2006-11-07, 19:58
This topic is closed due to lack of a response.

If you need it re-opened please send me a private message (pm) and provide a link to the thread.

Applies only to the original topic starter.