Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection » Computer with a NASTY spyware issue...
Closed Thread
Old 10-07-2007, 03:24 PM   #1 (permalink)
 
Super Techie

Join Date: Sep 2004

Posts: 302

eipeks is on a distinguished road

Default Computer with a NASTY spyware issue...

Here's the scoop...

I go to Google, and search for something, anything. When I get the search results and click on the link, I am redirected to dumb false advertising websites...all the time!

ie: I search for cheese on Google. The second result is cheese.com, so I click on that link and I am redirected to a completely unrelated advertising site!

This happens no matter what I search for!!! HELP!!!

Here's what I have done...

1. I have updated and scanned with AVG
2. I have run Spybot S&D
3. I have run Hijack This

NOthing has worked so far!

Here's the HJT log...

*******
Logfile of HijackThis v1.99.1
Scan saved at 1:19:53 PM, on 10/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\VTTimer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1160876018265
O17 - HKLM\System\CCS\Services\Tcpip\..\{EAEE614C-9797-42F1-9581-B42DE7535A4B}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: pasksa - pasksa.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: xartcd5 - xartcd5.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
***


If someone has heard of this happening or can help fix this issue, I'd be very thankful!!!


Thanks!!!
eipeks is offline  
Old 10-07-2007, 04:07 PM   #2 (permalink)
 
Super Techie

Join Date: Sep 2004

Posts: 302

eipeks is on a distinguished road

Default Re: Computer with a NASTY spyware issue...

I deleted these entries...


O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222


Nothing has changed!!


GRRRR!!!!
eipeks is offline  
Old 10-07-2007, 05:18 PM   #3 (permalink)
jay_bo's Avatar
 
Ultra Techie

Join Date: Jul 2006

Posts: 898

jay_bo is on a distinguished road

Default Re: Computer with a NASTY spyware issue...

reformat your hard drive worth a try but i had to buy a new hard drive because my isp said my pc was sending out spam so i already tired reformating it n i think it worked but i had used a key gen so tht teached me but i used my old hard drive now as a usb external hard drive, mine was that i used a key gen, never use 1 of them again the pop ups gave me **** n slow down on my pc.

A reformat should do it!!!
__________________
jay_bo is offline  
Old 10-07-2007, 07:30 PM   #4 (permalink)
 
Super Techie

Join Date: Sep 2004

Posts: 302

eipeks is on a distinguished road

Default Re: Computer with a NASTY spyware issue...

keygen? huh...?


Are there any suggestions that DO NOT involve a reformat?
eipeks is offline  
Old 10-07-2007, 10:21 PM   #5 (permalink)
superdave1984's Avatar
 
Repeat Offender

Join Date: Aug 2006

Location: Union City, TN

Posts: 1,928

superdave1984 is on a distinguished road

Default Re: Computer with a NASTY spyware issue...

Is it just in IE or does it do that using other browsers?
__________________
superdave1984 is offline  
Old 10-08-2007, 11:03 AM   #6 (permalink)
 
Super Techie

Join Date: Sep 2004

Posts: 302

eipeks is on a distinguished road

Default Re: Computer with a NASTY spyware issue...

I havent tried in any other browser. It's my fathers PC and all he has is IE.
Ill get firefox and check it out.


1) if it is just IE, suggestions?

2) if it turns out to be both...suggestions?


thanks!
eipeks is offline  
Old 10-08-2007, 02:22 PM   #7 (permalink)
superdave1984's Avatar
 
Repeat Offender

Join Date: Aug 2006

Location: Union City, TN

Posts: 1,928

superdave1984 is on a distinguished road

Default Re: Computer with a NASTY spyware issue...

If it turns out to be both, go through Warez' guide and see what happens.
http://www.tech-forums.net/pc/f51/wa...-guide-114061/
__________________
superdave1984 is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
A switch, and a router....Aren't they the same? ReikokuKo Networking Tips, Tricks & FAQ 10 04-10-2009 06:24 PM
POST Troubleshooting Guide SYL\X/3K Hardware Troubleshooting 7 03-07-2009 11:24 AM
Along came a hub, a switch, and a router....Aren't they the same? ReikokuKo Articles 16 06-23-2008 08:24 AM
Router Issue when switching computer Kloppstock Computer Networking & Internet Access 6 08-17-2007 09:32 AM