Hi there.. This is the first measure I've ever had to post on any board desire this (always been very obtain and if I did get anything my security programs would rub thing clean quickly).. but this week I just got the nasty "Web Buying" bug which seems to have come along with several other "telecommunicate domiciliate" type viruses or trojans. All of a sudden. I started getting weird pop-ups and warnings. Most have the "Brought to you by web buying" stuff at the bottom. This is on a Dell XPS m1210 laptop and it's a critical laptop I use when traveling but I don't conclude safe on it just yet. I've seen a few other threads here about this problem (or something similar to it) so I've run HJT. SAS and CF and have the logs ready. I have Kaspersky and Spy Sweeper too (although I think KIS was possibly disabled for a apprise period when this happened.. not sure but I experience I didn't download anything funky so I'm guessing it came from an infected summon somehow). Is one of the Super Gurus here able to bring home the bacon with me on this? I have very good computer knowledge and have the logs create from raw material to go.. just want to make sure I'm working with someone very skilled and heading down the right path!Thanks in advance for your help - it means a LOT to me! (And a donation to you the site or wherever!)TMM
Hi MFD!Thanks for your fast response. Here's the HJT log. Also. I had run ComboFix to get a log (before this latest HJT log) and SuperAntiSpyware.. both based on another similiar post I open here. The only thing I let act any actions was SAS and had it quarantine everything. I did undergo KIS 7.0 and SpySweeper doing some cleaning before I found this board but not sure if that made any difference or helped. After SAS quarantined the pop-ups in IE seemed to stop. I undergo gotten a few weird firewall warnings with KIS comfort. Regardless.. here's the log. I look forward to getting my computer clean!Thanks,TMM
Logfile of turn Micro HijackThis v2.0.2Scan saved at 7:27:04 PM on 9/15/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\schedule Files\Common Files\Logitech\Bluetooth\LBTSERV. EXEC:\schedule Files\Intel\Wireless\Bin\EvtEng exeC:\schedule Files\Intel\Wireless\Bin\S24EvMon exeC:\Program Files\Intel\Wireless\Bin\WLKeeper exeC:\WINDOWS\Explorer. EXEC:\WINDOWS\system32\spoolsv exec:\program files\common files\logitech\lvmvfm\LVPrcSrv exeC:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp exeC:\schedule Files\WIDCOMM\Bluetooth Software\bin\btwdins exeC:\Program Files\Common Files\Creative Labs Shared\function\CreativeLicensing exeC:\WINDOWS\system32\CTsvcCDA exeC:\schedule Files\Diskeeper Corporation\Diskeeper\DkService exeC:\WINDOWS\eHome\ehRecvr exeC:\WINDOWS\eHome\ehSched exeC:\Program Files\explore\Common\Google Updater\GoogleUpdaterService exeC:\Program Files\Dell\QuickSet\NICCONFIGSVC exeC:\WINDOWS\system32\nvsvc32 exeC:\schedule Files\Novatel Wireless\run\run PCS Connection Manager\OSCMUtilityService exeC:\Program Files\Intel\Wireless\Bin\RegSrvc exeC:\WINDOWS\SYSTEM32\Rpcnet exeC:\WINDOWS\system32\stacsv exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\Tablet exeC:\schedule Files\Webroot\Spy Sweeper\SpySweeper exeC:\Program Files\Synaptics\SynTP\SynTPEnh exeC:\WINDOWS\system32\rundll32 exeC:\Program Files\Intel\Wireless\bin\ZCfgSvc exeC:\schedule Files\Intel\Wireless\Bin\ifrmewrk exeC:\Program Files\Dell\Media Experience\DMXLauncher exeC:\schedule Files\Creative\SBAudigy\Surround Mixer\CTSysVol exeC:\WINDOWS\system32\Rundll32 exeC:\WINDOWS\system32\LVCOMSX. EXEC:\Program Files\Logitech\Video\CameraAssistant exeC:\DOCUME~1\Chris\LOCALS~1\Temp\clclean.0001C:\schedule Files\Common Files\InstallShield\UpdateService\issch exeC:\WINDOWS\System32\DLA\DLACTRLW. EXEC:\Program Files\j2 Messenger 4.2\J2GDllCmd exeC:\schedule Files\Mindjet\MindManager 7\MMReminderService exeC:\Program Files\Microsoft Office\Office12\GrooveMonitor exeC:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp exeC:\WINDOWS\system32\ctfmon exeC:\schedule Files\Mindjet\MindManager 7\PDF-XChange\pdfSaver\pdfSaver3 exeC:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon exeC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware exeC:\Program Files\WIDCOMM\Bluetooth Software\BTTray exeC:\schedule Files\Google\Google Updater\GoogleUpdater exeC:\WINDOWS\system32\WTablet\TabUserW exeC:\Program Files\Microsoft Office\Office12\ONENOTEM. EXEC:\WINDOWS\system32\dllhost exeC:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg exeC:\WINDOWS\System32\svchost exeC:\schedule Files\Adobe\Acrobat 7.0\Reader\AcroRd32 exeC:\schedule Files\NoteTab lighten\NoteTab exeC:\Documents and Settings\Chris\gotomypc_428 exeC:\DOCUME~1\Chris\LOCALS~1\Temp\G2_428\g2viewer exeC:\Documents and Settings\Chris\Desktop\HiJackThis exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,fail_Search_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,go away summon = R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper dllO2 - BHO: CmjBrowserHelperObject disapprove - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - C:\Program Files\Mindjet\MindManager 7\Mm7InternetExplorer dllO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W. DLLO2 - BHO: (no label) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\schedule Files\Siber Systems\AI RoboForm\roboform dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1. DLLO2 - BHO: explore Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\schedule files\google\googletoolbar1 dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\schedule Files\explore\GoogleToolbarNotifier\2.1.615.5858\swg dllO2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE dllO3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1 dllO4 - HKLM\..\Run: [SynTPEnh] "C:\schedule Files\Synaptics\SynTP\SynTPEnh exe"O4 - HKLM\..\Run: [NVHotkey] "rundll32 exe" nvHotkey dll,StartO4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc exe"O4 - HKLM\..\Run: [IntelWireless] "C:\schedule Files\Intel\Wireless\Bin\ifrmewrk exe" /tf Intel PROSet/WirelessO4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher exe"O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy\adjoin Mixer\CTSysVol exe" /rO4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA. DLL,MBMonO4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg. EXEO4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX. EXEO4 - HKLM\..\Run: [LogitechCameraAssistant] "C:\Program Files\Logitech\Video\CameraAssistant exe"O4.
Forex Groups - Tips on Trading
Related article:
http://forums.techguy.org/showthread.php?t=624164&goto=newpost
comments | Add comment | Report as Spam
|