Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Virus and Adware Removal
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Virus and Adware Removal  
Forum Quick Jump
 
New Topic Post reply to : Virus and Adware Removal Printable version of : Virus and Adware Removal
[ << Previous Thread | Next Thread >> ]

Pliskin
New Member


Date Joined Jan 2005
Total Posts : 3
 
   Posted 1-12-2005 3:44 (GMT +2)    Quote: Virus and Adware RemovalAlert an admin about: Virus and Adware Removal
I just recently got infested with a bunch of adware/spyware and i used adaware to remove most of it, then i ran Norton and it found some SAHAgent stuff yet it couldn't delete it. When i go to the directory where Norton said the files were i cant find them even i turn on hidden files and turn off protect system files.
 
Also my google has been acting up, no matter what i search for my first few pages are links to ads that have nothing to do with my topic and they are the same everytime i do a search yet it has happened to know one else i know. Even if i enter a empty search it will take me to the ad pages and when i click next it will take me back to the google home page. does anyone know anything about this? Help Would be appreciated.
 
i'll add my HiJack This file just to be safe.
 
Logfile of HijackThis v1.99.0
Scan saved at 8:39:22 PM, on 1/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HiJack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\system32\DSMANA~1.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: Zero Popup Pro - {EB23F789-F17F-4bcc-988B-6B70A3A67E9C} - C:\PROGRA~1\ZEROPO~1\ZERO-P~1.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [\\PC-PDAD\EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P29 "\\PC-PDAD\EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Back to Top
 

Pliskin
New Member


Date Joined Jan 2005
Total Posts : 3
 
   Posted 1-12-2005 3:46 (GMT +2)    Quote: Virus and Adware RemovalAlert an admin about: Virus and Adware Removal
Also, the history from google shows the google searchs within a site that is only an IP

69.50.163.6

does anyone know of that IP?
Back to Top
 

dannyboy4uwo
New Member


Date Joined Jan 2005
Total Posts : 2
 
   Posted 1-16-2005 5:03 (GMT +2)    Quote: Virus and Adware RemovalAlert an admin about: Virus and Adware Removal
I am having the same problem.

Here are the symptoms:

My homepage is www.google.com and remains to be such but, when I search anything I get a "google looking" page with a list of PAY per CLICK sites. It is a clever looking site. Same logos, etc, etc. Even some links work as if they are really GOOGLE's. If I scroll to the bottom and use the next and previous buttons to get to more search results, the TRUE results are displayed. The ABOUT GOOGLE links work as they should.

The latest Norton and Ad-Aware detect nothing.

Searching using Google Images or News works fine...just searching the Google's web gets redirected to the following address:

http://61.131.54.618.cc/

I can post Hijack THis logs or whatever info you need to help

SOMEBODY MUST BE ABLE TO SHED SOME LIGHT?!?!??!!?
Back to Top
 

chrisman
New Member


Date Joined Jan 2005
Total Posts : 1
 
   Posted 1-17-2005 12:17 (GMT +2)    Quote: Virus and Adware RemovalAlert an admin about: Virus and Adware Removal
This should help:

http://www.chrissweeney.co.uk/spyware.htm
Back to Top
 

Pliskin
New Member


Date Joined Jan 2005
Total Posts : 3
 
   Posted 1-18-2005 3:53 (GMT +2)    Quote: Virus and Adware RemovalAlert an admin about: Virus and Adware Removal
Thank you so Much, it work like a charm, i owe you one :)
Back to Top
 

dannyboy4uwo
New Member


Date Joined Jan 2005
Total Posts : 2
 
   Posted 1-18-2005 6:01 (GMT +2)    Quote: Virus and Adware RemovalAlert an admin about: Virus and Adware Removal
YES THANKS. IT WAS THE DSMANAGER.DLL FILE CAUSING THE PROBLEM.

THANKS CHRISMAN
Back to Top
 
New Topic Post reply to : Virus and Adware Removal Printable version of : Virus and Adware Removal
 
Forum Information
Currently it is Thursday, September 02, 2010 10:23 PM (GMT +2)
There are a total of 79.571 posts in 17.981 threads.
In the last 3 days there were 4 new threads and 20 reply posts. View Active Threads
Who's Online
This forum has 32134 registered members. Please welcome our newest member, goodlooking.
32 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Material Handling Equipment (0)02-09-2010 17:50:50 (aayushinfo56)
Beta testers for our latest product: Internet Security 10 - win an HTC Desire! (5)02-09-2010 16:56:21 (x ZauX x)
How to Remove Trojan.Gen? (10)02-09-2010 10:33:47 (NooBRuLz)
My gaming experience was worse with this (4)02-09-2010 09:07:51 (jesso2000)
Redirected to different sites from links on Google (4)02-09-2010 05:11:45 (Rabnud)