thecosmoguy
New member
My connection is actively downloading and uploading when I have a connection even if I'm on a blank page it still is active. This isn't normal because I watch for this and it just started a few days ago. I have used the newest versions with all updates of HijackThis and Spybot and clear out (Smitfraud, Nurech.A and SpySheriff) and all looks clear but I have a feeling my connection is being redirected to download this crap again (all without an Explorer window even open). I normally don't have any problem cleaning out viruses, trojans malware with Spybot and HijackThis but this one is not going away.
Does anyone know what's going on here? How can I fix this OR find out where my connection is communicating with ...I think there is some sort of hidden redirect on my computer that is connecting with a site that keeps downloading new bugs. also automatic updates for my Windows turned off. Could I have an unidentified (as of yet) virus?
ALSO: I have a copper wire connection/phone modem that normally connects at many different speeds (19000,26000,36000 43000 etc...) but now is ALWAYS connecting at 24,000 no matter if I switch from anyone of 5 dial up connection phone numbers This is also very weird.
Bottom line is my connection is actively exchanging information with something even when no web page is directed. I think my PC is being controlled by some unfound software. Any help will be greatly appreciated, thanks in advance.
windows xp pro 5.1 build 2600xpsp_sp2
explorer v 6.0 sp2
VundoFix.exe found nothing
Here is my Hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 8:35:46 AM, on 3/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\RED1\Desktop\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
Spybot is clean:
Activescan was tested:
(all "Not Disinfected" incidents were manually deleated by me.)
Results:
Incident Status Location
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\RED1\Desktop\smitfraud\SmitfraudFix\Process.exe
Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\RED1\Desktop\smitfraud\SmitfraudFix\restart.exe
Adware:adware/ncase Not disinfected C:\WINDOWS\180ax.exe
Virus:Trj/Alanchum.UL Disinfected C:\WINDOWS\system32\adirka.exe
Virus:Trj/Alanchum.UM Disinfected C:\WINDOWS\system32\adirss.exe
Virus:Trj/Alanchum.UA Disinfected C:\WINDOWS\system32\dd.exe
Adware:Adware/SpyAway Not disinfected C:\WINDOWS\system32\eumyuvjp.exe
Virus:Trj/Alanchum.MT Disinfected C:\WINDOWS\system32\google.png.exe
Virus:Trj/Downloader.MDW Disinfected C:\WINDOWS\system32\gykkewtw.amz
Virus:Trj/Downloader.NRW Disinfected C:\WINDOWS\system32\hqwmqnzk.exe
Virus:Trj/Downloader.NDY Disinfected C:\WINDOWS\system32\hulwpzji.exe
Virus:Trj/Downloader.NDY Disinfected C:\WINDOWS\system32\huyeqzuz.exe
Adware:Adware/SpyAway Not disinfected C:\WINDOWS\system32\idleserv.exe
Adware:Adware/SpySoldier Not disinfected C:\WINDOWS\system32\intr32.dll
Virus:Trj/Alanchum.UL Disinfected C:\WINDOWS\system32\ma.exe.exe
Virus:W32/Nurech.H.worm Disinfected C:\WINDOWS\system32\rsvp32_2.dll
Virus:W32/Nurech.H.worm Disinfected C:\WINDOWS\system32\rsvp32_2.dll435
Virus:W32/Nurech.H.worm Disinfected C:\WINDOWS\system32\rsvp32_2.dll534g
Virus:Trj/Alanchum.UA Disinfected C:\WINDOWS\system32\sc.exe.tmp
Virus:Trj/Alanchum.RX Disinfected C:\WINDOWS\system32\setup.exe.tmp
Virus:Trj/Alanchum.UA Disinfected C:\WINDOWS\system32\sm.exe
Virus:Trj/Alanchum.UM Disinfected C:\WINDOWS\system32\smt.exe
Virus:Trj/Gagar.DM Disinfected C:\WINDOWS\system32\uczkidfe.exe
Virus:Trj/Alanchum.TS Disinfected C:\WINDOWS\system32\vjxghotj.exe
Virus:Trj/Downloader.NDY Disinfected C:\WINDOWS\system32\vwbvhmtj.exe
Adware:Adware/SpyAway Not disinfected C:\WINDOWS\system32\xtlzgnuf.exe
Adware:adware/topconvert Not disinfected C:\WINDOWS\updatetc.exe
Does anyone know what's going on here? How can I fix this OR find out where my connection is communicating with ...I think there is some sort of hidden redirect on my computer that is connecting with a site that keeps downloading new bugs. also automatic updates for my Windows turned off. Could I have an unidentified (as of yet) virus?
ALSO: I have a copper wire connection/phone modem that normally connects at many different speeds (19000,26000,36000 43000 etc...) but now is ALWAYS connecting at 24,000 no matter if I switch from anyone of 5 dial up connection phone numbers This is also very weird.
Bottom line is my connection is actively exchanging information with something even when no web page is directed. I think my PC is being controlled by some unfound software. Any help will be greatly appreciated, thanks in advance.
windows xp pro 5.1 build 2600xpsp_sp2
explorer v 6.0 sp2
VundoFix.exe found nothing
Here is my Hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 8:35:46 AM, on 3/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\RED1\Desktop\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
Spybot is clean:
Activescan was tested:
(all "Not Disinfected" incidents were manually deleated by me.)
Results:
Incident Status Location
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\RED1\Desktop\smitfraud\SmitfraudFix\Process.exe
Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\RED1\Desktop\smitfraud\SmitfraudFix\restart.exe
Adware:adware/ncase Not disinfected C:\WINDOWS\180ax.exe
Virus:Trj/Alanchum.UL Disinfected C:\WINDOWS\system32\adirka.exe
Virus:Trj/Alanchum.UM Disinfected C:\WINDOWS\system32\adirss.exe
Virus:Trj/Alanchum.UA Disinfected C:\WINDOWS\system32\dd.exe
Adware:Adware/SpyAway Not disinfected C:\WINDOWS\system32\eumyuvjp.exe
Virus:Trj/Alanchum.MT Disinfected C:\WINDOWS\system32\google.png.exe
Virus:Trj/Downloader.MDW Disinfected C:\WINDOWS\system32\gykkewtw.amz
Virus:Trj/Downloader.NRW Disinfected C:\WINDOWS\system32\hqwmqnzk.exe
Virus:Trj/Downloader.NDY Disinfected C:\WINDOWS\system32\hulwpzji.exe
Virus:Trj/Downloader.NDY Disinfected C:\WINDOWS\system32\huyeqzuz.exe
Adware:Adware/SpyAway Not disinfected C:\WINDOWS\system32\idleserv.exe
Adware:Adware/SpySoldier Not disinfected C:\WINDOWS\system32\intr32.dll
Virus:Trj/Alanchum.UL Disinfected C:\WINDOWS\system32\ma.exe.exe
Virus:W32/Nurech.H.worm Disinfected C:\WINDOWS\system32\rsvp32_2.dll
Virus:W32/Nurech.H.worm Disinfected C:\WINDOWS\system32\rsvp32_2.dll435
Virus:W32/Nurech.H.worm Disinfected C:\WINDOWS\system32\rsvp32_2.dll534g
Virus:Trj/Alanchum.UA Disinfected C:\WINDOWS\system32\sc.exe.tmp
Virus:Trj/Alanchum.RX Disinfected C:\WINDOWS\system32\setup.exe.tmp
Virus:Trj/Alanchum.UA Disinfected C:\WINDOWS\system32\sm.exe
Virus:Trj/Alanchum.UM Disinfected C:\WINDOWS\system32\smt.exe
Virus:Trj/Gagar.DM Disinfected C:\WINDOWS\system32\uczkidfe.exe
Virus:Trj/Alanchum.TS Disinfected C:\WINDOWS\system32\vjxghotj.exe
Virus:Trj/Downloader.NDY Disinfected C:\WINDOWS\system32\vwbvhmtj.exe
Adware:Adware/SpyAway Not disinfected C:\WINDOWS\system32\xtlzgnuf.exe
Adware:adware/topconvert Not disinfected C:\WINDOWS\updatetc.exe