Page 1 of 2 12 LastLast
Results 1 to 10 of 15

Thread: Suspected Spyware?

  1. #1
    Member Atsuke's Avatar
    Join Date
    Feb 2006
    Posts
    29

    Question Suspected Spyware?

    I think my comp is acting wierd but im not sure sinxce i just installed a new software... can you guys check if this is normal?

    Logfile of HijackThis v1.99.1
    Scan saved at 3:54:12 PM, on 4/26/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\Program Files\Roxio\GoBack\GBPoll.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    D:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Roxio\GoBack\GBTray.exe
    D:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Network Associates\VirusScan\shstat.exe
    D:\Program Files\AIM\aim.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Yahoo!\browser\ybrowser.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\Yahoo!\browser\ybrwicon.exe
    D:\Program Files\Hijack This\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/dsl
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/dsl
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [YPC] C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
    O4 - HKCU\..\Run: [NBJ] "D:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    O4 - HKCU\..\Run: [Systweak Wallpaper Changer] wallpaper.exe -minimize
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: McAfee Stat.lnk = C:\Program Files\Network Associates\VirusScan\shstat.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
    O4 - Global Startup: SmartUI.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st_current.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resourc...scbase3401.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122145812718
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1123119616593
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: GBPoll - Roxio, Inc. - C:\Program Files\Roxio\GoBack\GBPoll.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

  2. #2
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Other than the bho (no file) and the spysweeper (missing file)
    your log looks ok.

    What problems are you having ?

  3. #3
    Member Atsuke's Avatar
    Join Date
    Feb 2006
    Posts
    29

    Default

    panda scan says i have lots of stuff ><


    Incident Status Location

    Adware:adware/swimsuitnetwork Not disinfected c:\windows\system32\MYDLL.dll
    Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\Jimmy Ly\Local Settings\Temporary Internet Files\Ssk.log
    Adware:adware/dollarrevenue Not disinfected c:\windows\winsysupd51.dat
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Guest\Cookies\guest@atwola[1].txt
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.tribalfusion.com/]
    Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.mediaplex.com/]
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.tribalfusion.com/]
    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[ad.yieldmanager.com/]
    Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.as-eu.falkag.net/]
    Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.doubleclick.net/]
    Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.questionmarket.com/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.atdmt.com/]
    Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.questionmarket.com/]
    Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.fastclick.net/]
    Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.casalemedia.com/]
    Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.zedo.com/]
    Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.ads.pointroll.com/]
    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.statcounter.com/]
    Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.advertising.com/]
    Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.trafficmp.com/]
    Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.adrevolver.com/]
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Jimmy Ly\Application Data\Mozilla\Firefox\Profiles\vjqdsr9i.default\cookies.txt[.com.com/]
    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jimmy Ly\Cookies\jimmy ly@ad.yieldmanager[1].txt
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jimmy Ly\Cookies\jimmy ly@atwola[1].txt
    Spyware:Cookie/Microsofte Not disinfected C:\Documents and Settings\Jimmy Ly\Cookies\jimmy ly@microsofteup.112.2o7[1].txt
    Spyware:Cookie/go Not disinfected C:\Documents and Settings\John Ly\Cookies\john ly@go[1].txt
    Possible Virus. Not disinfected C:\Program Files\SBC Self Support Tool\bin\closeAll.exe
    Possible Virus. Not disinfected C:\Program Files\Yahoo!\browser\ybcBrowser.dll
    Possible Virus. Not disinfected C:\WINDOWS\Downloaded Installations\{C32ACEF8-937B-40BC-84B0-FB81EE655AB4}\Sunbelt CounterSpy.msi[unk_0076]
    Potentially unwanted tool:Application/Restart Not disinfected C:\WINDOWS\system32\Tools\Restart.exe

  4. #4
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Hi

    Delete
    c:\windows\winsysupd51.dat

    rename and leave it in place >
    c:\windows\system32\MYDLL.dll
    Then delete cookies and temporary internet files via your browsers options

  5. #5
    Member Atsuke's Avatar
    Join Date
    Feb 2006
    Posts
    29

    Default

    Hi,

    on MyDLL, i just rename the file to anything I want right?


    Thanks

  6. #6
    Member Atsuke's Avatar
    Join Date
    Feb 2006
    Posts
    29

    Default

    Hi,

    OK, I did what you told me to do. Am I all clear?

  7. #7
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Yes unless a problem surfaces.

    Stay safe

  8. #8
    Member Atsuke's Avatar
    Join Date
    Feb 2006
    Posts
    29

    Default

    Umm.. One last question.. Remember on Panda Scan, it said there was a possible virus? Can you tell me more about that?

  9. #9
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    ? didnt we just address those files ?

    Possible Virus. Not disinfected C:\Program Files\SBC Self Support Tool\bin\closeAll.exe
    Possible Virus. Not disinfected C:\Program Files\Yahoo!\browser\ybcBrowser.dll
    Possible Virus. Not disinfected C:\WINDOWS\Downloaded Installations\{C32ACEF8-937B-40BC-84B0-FB81EE655AB4}\Sunbelt CounterSpy.msi[unk_0076]
    Potentially unwanted tool:Application/Restart Not disinfected C:\WINDOWS\system32\Tools\Restart.exe

    False passitives

  10. #10
    Member Atsuke's Avatar
    Join Date
    Feb 2006
    Posts
    29

    Default

    Oh I see. So they're not really causing any harm to my computer...


    Thanks! You're the best x] I should make you an award by using adobe photoshop and letting you put it in your sig XD

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •