Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Closed Thread
Old 03-03-2006, 12:36 AM   #1 (permalink)
 
Ultra Techie

Join Date: Feb 2005

Posts: 970

AnthraX is on a distinguished road

Default Spyware, constant internet usage

Alright, I have some pretty bad spyware. Usually spyware and viruses aren't an issue for me, but I guess I've been kinda slackin off lately.

Today I noticed that Counter-Strike Source was running rather laggy for me. First thing I thought was maybe it was due to some programs I had open. After a little bit of an inspection I noticed that my internet was constantly going, even when I wasn't doing anything. I've ran Ad-Aware, Spybot, MS Defender at least 6 times, and NOD32 twice. Half of the times I did them it was in safe mode. Everything is up to date, except for MS Defender which says there are no new updates. I thought that would have gotten rid of it, but nope, my internet is still being used constantly. It's not as bad right now however, it goes for about it a minute then stops for a little while, but starts again. I rad a HijackThis and heres my log:

Quote:
Logfile of HijackThis v1.99.1
Scan saved at 9:25:29 PM, on 3/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Config\svchost.exe
D:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\UltraMon\UltraMon.exe
D:\Program Files\UltraMon\UltraMonTaskbar.exe
D:\Program Files\Valve\Steam\Steam.exe
D:\Program Files\Xfire\Xfire.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Winamp\Winamp.exe
C:\WINDOWS\system32\taskmgr.exe
D:\AnthraX's Folder\Downloads\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: UltraMon.lnk = D:\Program Files\UltraMon\UltraMon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'xfire_lsp_9425.dll' missing
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\system32\win_160.dll
O20 - Winlogon Notify: Mixer - C:\WINDOWS\SYSTEM32\sndmixex.dll
O21 - SSODL: SysTray.Exgl - {636821FC-6F5C-2f1b-B164-E67214F678E2} - (no file)
O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Hardware Check - Stanford University - C:\WINDOWS\Config\svchost.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - D:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
If anyone has any suggestions, that would be most appreciated. I really don't think I've over looked anything, and I didn't want to mess around with HijackThis because this is the first time I've used it.
__________________
<br><br><font color=\"black\"><b>There's No Place Like </b></font><font color=\"red\"><b>127.0.0.1</b></font><br>
AnthraX is offline  
Old 03-03-2006, 10:36 AM   #2 (permalink)
 
Junior Techie

Join Date: Nov 2005

Posts: 81

Emperor

Default

svchost.exe - this process is not running from the System32 folder as it is supposed to be.

Delete 'svchost.exe' from the following directory -C:\WINDOWS\Config\svchost.exe.
Emperor is offline  
Old 03-04-2006, 12:29 AM   #3 (permalink)
 
Ultra Techie

Join Date: Feb 2005

Posts: 970

AnthraX is on a distinguished road

Default

Well, I would if I could. I kept getting these stupid errors, that I dont know if it was at all related.

I didn't want to deal with that crap so I just redid everything from my earlier Ghost image. Norton Ghost rocks!
__________________
<br><br><font color=\"black\"><b>There's No Place Like </b></font><font color=\"red\"><b>127.0.0.1</b></font><br>
AnthraX is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On