Gerry Posted December 16, 2007 Report Share Posted December 16, 2007 Hi Folks!I'm new here so please bear with me if I slip up on something.First of all I would like to say that I am extremely impressed with the professional set-up of this website and the quick manner in which a new member can get involved.My problem: I suspect that my PC is infected with all types of Spyware because of the following:1. For months now it has reacted strange. I find it difficult to access websites (takes a long time to respond to clicks - I use Firefox). And then it acts erratically. My PC is extremely slow - just about impossible to work with.2. I invested in SpyZooka in July (I know - bad investment) and it could not detect any infections3. I also downloaded NoAdware.net and it detected 47 infections after a scan, some critical (keyloggers)4. XoftSpy detected 6 infections.I have downloaded the latest version of HijackThis and have copied the log below for your info.I will appreciate it if one of your experts could analyze this and advise me.I use Windows 98SE.Looking forward to your great assistance.Many thanks.Gerry--------------------------------------------------------------------------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 02:37:05, on 07/12/16Platform: Windows 98 SE (Win9x 4.10.2222A)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Boot mode: NormalRunning processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\SYSTEM\RPCSS.EXEC:\WINDOWS\TASKMON.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\PROGRAM FILES\TEXTBRIDGE CLASSIC 2.0\BIN\INSTANTACCESS.EXEC:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXEC:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXEC:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXEC:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXEC:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXEC:\WINDOWS\SYSTEM\WMIEXE.EXEC:\PROGRAM FILES\SPYZOOKA\SPYZOOKA.EXEC:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXEC:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXEC:\WINDOWS\SYSTEM\PSTORES.EXEC:\PROGRAM FILES\XSINET\DIALER.EXEC:\WINDOWS\SYSTEM\RNAAPP.EXEC:\WINDOWS\SYSTEM\TAPISRV.EXEC:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXEC:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXER1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_BAND_SEARCHBAR_HTMLR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htmR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = F1 - win.ini: run=hpfschedO2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLLO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLLO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCXO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLLO4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exeO4 - HKLM\..\Run: [systemTray] SysTray.ExeO4 - HKLM\..\Run: [instantAccess] C:\PROGRA~1\TEXTBR~1.0\BIN\INSTAN~1.EXE /hO4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\BIN\REGIST~1.EXEO4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exeO4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeO4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUPO4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXEO4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXEO4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exeO4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorunO4 - HKCU\..\Run: [spyZooka] C:\PROGRAM FILES\SPYZOOKA\SpyZookaLdr.exeO4 - HKCU\..\Run: [NBJ] "C:\PROGRAM FILES\AHEAD\NERO BACKITUP\NBJ.EXE"O4 - HKUS\.DEFAULT\..\Run: [spyZooka] C:\PROGRAM FILES\SPYZOOKA\SpyZookaLdr.exe (User 'Default user')O4 - HKUS\.DEFAULT\..\Run: [Asmw Soft Popups Burner] (User 'Default user')O4 - HKUS\.DEFAULT\..\Run: [NBJ] "C:\PROGRAM FILES\AHEAD\NERO BACKITUP\NBJ.EXE" (User 'Default user')O4 - .DEFAULT Startup: Reboot.exe (User 'Default user')O4 - Startup: Reboot.exeO8 - Extra context menu item: Search Using Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXTO9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRAM FILES\COPERNIC AGENT\COPERNICAGENT.EXEO9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRAM FILES\COPERNIC AGENT\COPERNICAGENT.EXEO9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRAM FILES\COPERNIC AGENT\COPERNICAGENT.EXEO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion...canner37570.cabO16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (Download Helper Class) - http://activex.microgaming.com/DLhelper/ve...n7/dlhelper.cabO16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://webolr1.microgaming.com/360/webolr/OCX/FlashAX.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cabO20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL--End of file - 5156 bytes Quote Link to post Share on other sites
rmurphy Posted December 16, 2007 Report Share Posted December 16, 2007 Hi Gerry, welcome to BestTechie! I'm Ryan, and I'll be helping you clean your computer.Before we start cleaning, I would like to see an uninstall list:Open HijackThis, click Config, click Misc ToolsClick "Open Uninstall Manager"Click "Save List" (generates uninstall_list.txt)-Ryan Quote Link to post Share on other sites
Gerry Posted December 17, 2007 Author Report Share Posted December 17, 2007 Hello RyanThanks for taking the time to assist me.As requested I have copied the Uninstall list below for your info.Thanks, Ryan.Gerry----------------------------------------------------------------------------------------------------------Ad-Aware SE PersonalAdobe Acrobat - Reader 6.0.2 UpdateAdobe Acrobat and Reader 6.0.3 UpdateAdobe Acrobat and Reader 6.0.4 UpdateAdobe Acrobat and Reader 6.0.5 UpdateAdobe Download Manager 1.2 (Remove Only)Adobe Flash Player PluginAdobe Reader 6.0.1Asmw PC-Optimizer ProAVG Free EditionBackRex Outlook Express Backup DemoChinese (Simplified) Language SupportChinese (Simplified) Menus and Dialogs for Internet Explorer 6Chinese (Traditional) Language SupportChinese (Traditional) Menus and Dialogs for Internet Explorer 6ColorPage-Vivid Pro IIConvert ImageCopernic Agent BasicEasyCleanerFoxit ReaderFreshDiagnoseFreshUIHijackThis 2.0.2HP DeskJet 710C Series (Remove only)HP Photosmart EssentialHP Software UpdateInternet Explorer Q903235Internet Explorer Q916281IrfanView (remove only)Microsoft .NET Framework (English) v1.0.3705Microsoft Data Access Components KB870669Microsoft Internet Explorer 6 SP1 and Internet ToolsMicrosoft Office 97, Professional EditionMicrosoft Outlook Express 6Microsoft VGX Q833989Microsoft Windows Critical Update NotificationMozilla Firefox (2.0.0.11)Nero SuiteNoAdware v5.0Outlook Express Q837009Panda ActiveScanPCI Audio DriverPiggs Peak CasinoRegistry MechanicRegRepair 2000 (C:\Program Files\Easy Desk Utilities\RegRepair 2000\)Spybot - Search & Destroy 1.4Startup Delayer v2.3 (build 130)Sterling House CasinoSUPERAntiSpyware Free EditionTextBridge Classic 2.0The Unzip WizardUSB Flash Disk 98 DriverWindows 98 KB891711 UpdateWindows 98 KB896358 UpdateWindows 98 KB908519 UpdateWindows 98 KB918547 UpdateWindows 98 Q823559 UpdateWindows 98 Q840315 UpdateWindows 98 Q888113 UpdateWindows 98 Q890175 UpdateWindows Media Player 7.1WinPatrolWinZipWise Disk Cleaner 2.6Wise Registry Cleaner 2.8.5XSInet DiallerYahoo! ToolbarZip backup to CD 3ZoneAlarm Quote Link to post Share on other sites
rmurphy Posted December 17, 2007 Report Share Posted December 17, 2007 Please uninstall NoAdware v5.0.Download CWShredder Here to its own folder.Update CWShredderOpen CWShredder and click I AGREEClick Check For UpdateClose CWShredderBoot into Safe Mode:Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.Now run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about. Reboot your computer into normal windows.After that, please update and scan with SUPERAntiSpyware. Please post the results of the scan along with a new hijack this log.-Ryan Quote Link to post Share on other sites
Gerry Posted December 19, 2007 Author Report Share Posted December 19, 2007 Hi RyanI have done the following:1. I could not gain direct access to the CWShredder.net website (did not respond) but downloaded the program from Filehippo. 2. Once downloaded I tried to update but this too did not respond3. I then had to scan without an update. This could not find any CoolWebSearch infections on my system4. A scan with SUPERAntispySpyware also could not detect anything.5. Please note that I could not start up in Safe Mode. The PC simply ignored my attempts, to open up and started up normally. I usually use Safe Mode for Scandisk and Defrag without problems but this time without luck (tried quite a few times. How can I fix that?)Ryan, please advise further.Thanks.Gerry Quote Link to post Share on other sites
rmurphy Posted December 20, 2007 Report Share Posted December 20, 2007 Please do an online scan with Kaspersky WebScanner You will need to use Internet Explorer to do thisClick on Kaspersky Online ScannerYou will be promted to install an ActiveX component from Kaspersky, Click Yes.The program will launch and then begin downloading the latest definition files:Once the files have been downloaded click on NEXTNow click on Scan SettingsIn the scan settings make that the following are selected:Scan using the following Anti-Virus database:Extended (if available otherwise Standard)Scan Options:Scan ArchivesScan Mail Bases[*]Click OK[*]Now under select a target to scan:Select My Computer[*]This will program will start and scan your system.[*]The scan will take a while so be patient and let it run.[*]Once the scan is complete it will display if your system has been infected.Now click on the Save as Text button:[*]Save the file to your desktop.Please post the report from the Kaspersky scan.-Ryan Quote Link to post Share on other sites
Gerry Posted December 23, 2007 Author Report Share Posted December 23, 2007 Please do an online scan with Kaspersky WebScanner You will need to use Internet Explorer to do thisClick on Kaspersky Online ScannerYou will be promted to install an ActiveX component from Kaspersky, Click Yes.The program will launch and then begin downloading the latest definition files:Once the files have been downloaded click on NEXTNow click on Scan SettingsIn the scan settings make that the following are selected:Scan using the following Anti-Virus database:Extended (if available otherwise Standard)Scan Options:Scan ArchivesScan Mail Bases[*]Click OK[*]Now under select a target to scan:Select My Computer[*]This will program will start and scan your system.[*]The scan will take a while so be patient and let it run.[*]Once the scan is complete it will display if your system has been infected.Now click on the Save as Text button:[*]Save the file to your desktop.Please post the report from the Kaspersky scan.-Ryan Quote Link to post Share on other sites
Gerry Posted December 23, 2007 Author Report Share Posted December 23, 2007 RyanI am having no luck with the Kaspersky Online Scanner with Explorer. I can access the website but when I click on 'Kaspersky Online Scanner' the hourglass comes up with the cursor but then disappears after a while and it just hangs. No firefox browser is open at the time, only Explorer.When I try the scan on Firefox I have no problems but because I have to use Explorer for this I did not proceed.Please advise me further, or suggest an alternative Online Scanner that I could use on Firefox.My PC is getting worse by the day. On some days I can not access websites and just give up.Thanks, Ryan!Gerry Quote Link to post Share on other sites
rmurphy Posted December 23, 2007 Report Share Posted December 23, 2007 Try this scanner:Please go HERE to run Panda's ActiveScan. You will need to use Internet Explorer to run it.Once you are on the Panda site click the Scan your PC buttonA new window will open...click the Check Now buttonEnter your CountryEnter your State/ProvinceEnter your e-mail address and click sendSelect either Home User or CompanyClick the big Scan Now buttonIf it wants to install an ActiveX component allow itIt will start downloading the files it requires for the scan (Note: It may take a couple of minutes)When download is complete, click on My Computer to start the scanWhen the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.Post the contents of the ActiveScan report.-Ryan Quote Link to post Share on other sites
Gerry Posted December 29, 2007 Author Report Share Posted December 29, 2007 Try this scanner:Please go HERE to run Panda's ActiveScan. You will need to use Internet Explorer to run it.Once you are on the Panda site click the Scan your PC buttonA new window will open...click the Check Now buttonEnter your CountryEnter your State/ProvinceEnter your e-mail address and click sendSelect either Home User or CompanyClick the big Scan Now buttonIf it wants to install an ActiveX component allow itIt will start downloading the files it requires for the scan (Note: It may take a couple of minutes)When download is complete, click on My Computer to start the scanWhen the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.Post the contents of the ActiveScan report.-Ryan Quote Link to post Share on other sites
Gerry Posted December 29, 2007 Author Report Share Posted December 29, 2007 Try this scanner:Please go HERE to run Panda's ActiveScan. You will need to use Internet Explorer to run it.Once you are on the Panda site click the Scan your PC buttonA new window will open...click the Check Now buttonEnter your CountryEnter your State/ProvinceEnter your e-mail address and click sendSelect either Home User or CompanyClick the big Scan Now buttonIf it wants to install an ActiveX component allow itIt will start downloading the files it requires for the scan (Note: It may take a couple of minutes)When download is complete, click on My Computer to start the scanWhen the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.Post the contents of the ActiveScan report.-Ryan Quote Link to post Share on other sites
Gerry Posted December 29, 2007 Author Report Share Posted December 29, 2007 Hi RyanOnce again I have been unable to do a scan with Panda, same problem as with Kaspersky. I have aacessed the websites with Internet Explorer but the scans simply would not respond. (I havenot opened a Firefox browser). What do you think the reason for this could be?I have, as an alternative, done a Full System Scan with a-sqaured. I realise that this is probably not the real McCoy but it is the only working alternative that I could think of. However, no serious infections were found and I have deleted all, except one which refused to be deleted (medium threat). I have copied the scan log below for your info.I think my problems could be the cause of something else and I will submit a new post for further assistance.Thanks for your help, Ryan------------------------------------------------------------------------------------------------------a-squared Free - Version 3.0Last update: 07/12/25 05:47:57 AMScan settings:Objects: Memory, Traces, Cookies, C:\, D:\Scan archives: OnHeuristics: OnADS Scan: OffScan start: 07/12/26 07:20:20 AMc:\casino detected: Trace.Directory.CarnivalCasinoValue: HKEY_CURRENT_USER\Software\SearchHTML --> UrlSupport detected: Trace.Registry.AdwareFilterValue: HKEY_LOCAL_MACHINE\SOFTWARE\AdwareFilter --> POST_INST_1_CHOICE detected: Trace.Registry.AdwareFilterc:\program files\softwaredoctor\errordoctor detected: Trace.Directory.ErrorDoctorValue: HKEY_CURRENT_USER\Software\Casino DelRio --> options_dealervoices detected: Trace.Registry.Casino Del RioValue: HKEY_CURRENT_USER\Software\Casino DelRio --> options_music detected: Trace.Registry.Casino Del RioValue: HKEY_CURRENT_USER\Software\Casino DelRio --> options_sounds detected: Trace.Registry.Casino Del RioValue: HKEY_CURRENT_USER\Software\Casino DelRio --> options_xlslots detected: Trace.Registry.Casino Del RioValue: HKEY_CURRENT_USER\Software\Casino DelRio --> options-fullscreen detected: Trace.Registry.Casino Del RioValue: HKEY_CURRENT_USER\Software\Casino DelRio --> options-volume detected: Trace.Registry.Casino Del RioValue: HKEY_LOCAL_MACHINE\SOFTWARE\Casino DelRio --> advertisercode detected: Trace.Registry.Casino Del RioValue: HKEY_LOCAL_MACHINE\SOFTWARE\Casino DelRio --> banner detected: Trace.Registry.Casino Del RioValue: HKEY_LOCAL_MACHINE\SOFTWARE\Casino DelRio --> creferer detected: Trace.Registry.Casino Del RioValue: HKEY_LOCAL_MACHINE\SOFTWARE\Casino DelRio --> profile detected: Trace.Registry.Casino Del RioValue: HKEY_LOCAL_MACHINE\SOFTWARE\Casino DelRio --> referer detected: Trace.Registry.Casino Del RioValue: HKEY_LOCAL_MACHINE\SOFTWARE\Casino DelRio --> safemode detected: Trace.Registry.Casino Del RioValue: HKEY_LOCAL_MACHINE\SOFTWARE\Casino DelRio --> uninstall_lang detected: Trace.Registry.Casino Del RioValue: HKEY_CURRENT_USER\Software\MicroGaming\Thumper\Detect --> BD detected: Trace.Registry.Phoenician CasinoValue: HKEY_CURRENT_USER\Software\MicroGaming\Thumper\Detect --> DXVerN detected: Trace.Registry.Phoenician CasinoValue: HKEY_CURRENT_USER\Software\MicroGaming\Thumper\Detect --> FlashVerN detected: Trace.Registry.Phoenician CasinoValue: HKEY_CURRENT_USER\Software\MicroGaming\Thumper\Detect --> IEVerN detected: Trace.Registry.Phoenician CasinoValue: HKEY_CURRENT_USER\Software\MicroGaming\Thumper\Detect --> ScreenX detected: Trace.Registry.Phoenician CasinoValue: HKEY_CURRENT_USER\Software\MicroGaming\Thumper\Detect --> ScreenY detected: Trace.Registry.Phoenician CasinoValue: HKEY_CURRENT_USER\Software\CasinonetInstaller --> INSTALLER_GUID detected: Trace.Registry.CasinoOnNetValue: HKEY_CURRENT_USER\Software\CasinonetInstaller --> URL_CASINO_2 detected: Trace.Registry.CasinoOnNetValue: HKEY_CURRENT_USER\Software\casinoonnet\casino\init --> serial detected: Trace.Registry.CasinoOnNetValue: HKEY_CURRENT_USER\Software\casinoonnet\casino\init --> test_data detected: Trace.Registry.CasinoOnNetValue: HKEY_CURRENT_USER\Software\casinoonnet\casino\SDL --> Upd_Flag detected: Trace.Registry.CasinoOnNetValue: HKEY_CURRENT_USER\Software\casinoonnet\casino\SDL --> Upg_Date detected: Trace.Registry.CasinoOnNetC:\WINDOWS\Cookies\anyuser@statcounter[1].txt detected: Trace.TrackingCookieC:\WINDOWS\TEMP\is-0TN84.tmp\askBarSetup.exe detected: Riskware.AdTool.Win32.MyWebSearch.bnC:\WINDOWS\Sterling House Casino setup.exe detected: Adware.Win32.Casino.wScannedFiles: 122255Traces: 153132Cookies: 15Processes: 18FoundFiles: 2Traces: 29Cookies: 1Processes: 0Registry keys: 0Scan end: 07/12/26 04:32:27 PMScan time: 9:12:07 Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.