I believe my computer is being hyjacked by a software company
Stythis New Member Date Joined Mar 2006 Total Posts : 1 Posted 3-28-2006 2:57 (GMT +1) I have cleaned my computer from top to bottom, ran numerous virus scans by numerous programs, but I still am getting a message that I have a critical systems error on my computer for further information click here and up pops this wonderful add from a spy removal company. I have run the log that you requested I am hoping some one can help; my computer is what I work from, my lively hood. I teach on-line and several universities and at this moment I am afraid to go into my classrooms or send my students any correspondences. Here is the log: Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd. exe C:\Program Files\Common Files\AOL\1129174546\ee\services\sscF irewallPlugin\ver1_10_3_1\aolavupd.ex e C:\Program Files\Symantec\LiveUpdate\ALUSchedule rSvc.exe C:\WINDOWS\System32\DRIVERS\CDANTSRV. EXE C:\WINDOWS\system32\CTsvcCDA.EXE C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshi eld.exe C:\Program Files\mcafee.com\personal firewall\MPFService.exe C:\Program Files\Spyware Doctor\sdhelp.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wdfmgr.exe C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\htpatch.exe C:\WINDOWS\System32\WScript.exe C:\Program Files\Winamp\Winampa.exe C:\Program Files\Microsoft IntelliType Pro\type32.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.ex e C:\Program Files\mcafee.com\antivirus\oasclnt.ex e C:\Program Files\mcafee.com\personal firewall\MPfTray.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\WINDOWS\System32\alg.exe C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe D:\Christopher-D-Drive\iTunesHelper.e xe C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Common Files\AOL\1129174546\ee\AOLSoftware.e xe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\mcafee.com\antivirus\mcvsescn.e xe C:\Program Files\Common Files\AOL\1129174546\ee\services\sscA ntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe C:\Program Files\Common Files\AOL\ACS\AOLDial.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Spyware Doctor\swdoctor.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\palmOne\HOTSYNC.EXE C:\Program Files\Common Files\AOL\1129174546\ee\services\sscF irewallPlugin\ver1_10_3_1\SSCEvtHdlr. exe C:\WINDOWS\System32\wbem\wmiprvse.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe c:\progra~1\Support.com\client\bin\tg cmd.exe c:\program files\common files\aol\1129174546\ee\aolssc.exe C:\Program Files\Netscape\Netscape\Netscp.exe C:\WINZIP\winzip32.exe C:\unzipped\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.companion.yahoo.com/slv/ych eck/as/*http://www.yahoo.com/search/i e.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.companion.yahoo.com/slv/ych eck/as/*http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/yessent ials/defaults/*http://my.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/yessent ials/defaults/su/*http://www.yahoo.co m R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/yessent ials/defaults/sb/*http://www.yahoo.co m/search/ie.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsear ch.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/yessent ials/defaults/*http://my.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.companion.yahoo.com/slv/ych eck/as/*http://search.yahoo.com/searc h?p=%s N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.snet.net"); (C:\Program Files\Netscape\Users\Gadget's\prefs.j s) O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB } - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC } - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C } - C:\Program Files\AOL Toolbar\toolbar.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88 } - C:\Program Files\Yahoo!\Companion\Installs\cpn\y t.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F } - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\serv er.vbs O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe" O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.ex e O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1129174546\ee\services\sscF irewallPlugin\ver1_10_3_1\SSCRun.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.ex e O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTa skbarInit O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe" O4 - HKLM\..\Run: [iTunesHelper] "D:\Christopher-D-Drive\iTunesHelper. exe" O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~ 1\ISUSPM.exe -startup O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1129174546\ee\AOLSoftware.e xe O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.e xe O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1129174546\ee\services\sscA ntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.e xe" boot O4 - HKCU\..\Run: [Iinl] C:\Documents and Settings\James\Application Data\emia.exe O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\microsoftOffice\Office10\OSA.EX E O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsea rch.html O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbac klinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcac he.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\E XCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsim ilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtra ns.html O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501 } - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501 } - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84 } - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C } - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C } - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897 } - C:\WINDOWS\System32\shdocvw.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263 } - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBA R.DLL O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21 } - C:\WINDOWS\System32\shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683 } - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683 } - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/va iopeople O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.1.5.21 /mahjong/mahjong-ob-assets.cab O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet-5.9 .1.18/squelchies/squelchies-ob-assets .cab O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.2.0.30 /holdem/holdem-ob-assets.cab O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.1.5.21 /peaks/peaks-ob-assets.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E } (Musicnotes Viewer) - http://aol.musicnotes.com/download/mn viewer.cab O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814 } (MeadCo ScriptX Advanced) - http://www.stonyfield.com/coupons/scr iptX/smsx.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700 } (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linki d=39204 O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35 } - http://a19.g.akamai.net/7/19/7125/126 9/ftp.coupons.com/v6/brix6ie.cab O16 - DPF: {2C8EEB84-6D60-11D4-BD64-0050048A82BF } (eshare communications NetAgent Customer ActiveX Control version 2) - http://tech-c.mhi.aol.com/netagent/ob jects/custappx2.CAB O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB } (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3 } (MUWebControl Class) - http://update.microsoft.com/microsoft update/v6/V5Controls/en/x86/client/mu web_site.cab?1125770828859 O16 - DPF: {72770C4F-967D-4517-982B-92D6B9015649 } (DigWebHelper Class) - http://photos.msn.com/resources/neutr al/controls/DigWebX.cab?9,0,712,0 O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C } - http://a19.g.akamai.net/7/19/7125/404 7/ftp.coupons.com/v3123/cpbrkpie.cab O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000 } (YahooYMailTo Class) - c:\program files\yahoo!\installs\ymmapi.dll O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF } (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Msn MessengerSetupDownloader.cab O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D } (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15 .28/ttinst.cab O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB } (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/Pho toUC/MsnPUpld.cab O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA } (Java Runtime Environment 1.4.0_01) - O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6 } (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O16 - DPF: {FF054BED-D972-4215-897E-726C3488DDBB } (sonyctl.sonycm) - http://supportcentral4.sel.sony.com/s dccommon/download/sonyctl.CAB O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd. exe O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1129174546\ee\services\sscF irewallPlugin\ver1_10_3_1\aolavupd.ex e O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedule rSvc.exe O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV. EXE O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~ 1.EXE O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshi eld.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\S ptisrv.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppSer ver) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServe r-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing) O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServe r-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTT P (file missing) O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppSer ver) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServe r-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HT TP (file missing) O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe Please if anyone can help, let me know. Back to Top
Andrei Ionescu Junior Member Date Joined Dec 2005 Total Posts : 58 Posted 4-1-2006 1:17 (GMT +1) Hi Stythis, The log you have posted here seems to be created by the new 2.0 version of HijackThis. Even if this new version is more complex and more helpful if you plan to fight the infection yourself, the 1.99 version suits us better because it creates a log that is a lot more simpler to follow. 1. So please try to download the 1.99 version of HijackThis from this link: http://majorgeeks.com/downloadget.php?id=3155&file=1&evp=3304750663b552982a8baee6434cfc13 2. Place the .exe file into a newly created folder, on your desktop for instance. 3. Run the application and use the "Do a system scan and save a log file" option. 4. After the scan finishes, the log will be created in the same folder in which you have placed the application itself. 5. Please open the log in Notepad, copy its content and then paste it as a erply to this thread.
Andrei Cristian Ionescu
Support Team Member
BullGuard Software Ltd.
Cell phone: +40 724.276.719
YM!: ionescu1982 ; Skype: ionesan
Please start your own thread by clicking the new topic button. Do NOT post your problem in someone elses thread.
Do not PM me with logfiles. They will be deleted
Back to Top
rpggamergirl Forum Moderator Date Joined Dec 2005 Total Posts : 1534 Posted 4-1-2006 11:53 (GMT +1)
merijn's quote: March 29, 2006:
"I haven't forgotten about HijackThis, nor have I stopped development on it. The 1.99.2 update will arrive eventually, but I'm up to my head into classes and, sorry to say, those are my priority."
Hijackthis 1.99.2 is not release yet.
The doublespacing is probably caused by wordwrap.
Please rescan with HiJackThis and when the notepad opens up, go up to "Format " and uncheck "Word Wrap, then copy and paste the log into this topic.
~If you're still waiting for a reply, pm me the link to your thread. Back to Top
Forum Information Currently it is Saturday, March 13, 2010 5:09 AM (GMT +1) There are a total of 76.142 posts in 17.592 threads. In the last 3 days there were 8 new threads and 56 reply posts. View Active Threads Who's Online This forum has 31124 registered members. Please welcome our newest member, teddy . 31 Guest(s), 0 Registered Member(s) are currently online. Details 5 Latest Threads