the_entwistles Posted April 2, 2008 Report Share Posted April 2, 2008 Hi,All this is new to me, the kids know more, our pc has been receiving the following message:You computer was infected by unknown trojan.It's dangerous for your system (critical files will be lost)!Click OK to download antispyware program to clean your system.Also on searching on google i seem to have a porn takeover that redirects searches.I have run various spyware programs which have not helped, so i have included a hijackthis report to see if it makes any sense to anybody?Thanks. Logfile of Trend Micro HijackThis v2.0.2Scan saved at 13:17:46, on 02/04/2008Platform: Windows 2000 SP3 (WinNT 5.00.2195)MSIE: Internet Explorer v5.00 SP3 (5.00.2920.0000)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\BUFFALO\Client Manager3\bwsvc\bwsvc.exeC:\WINDOWS\System32\DRIVERS\CDANTSRV.EXEC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeC:\WINDOWS\System32\svchost.exeC:\PROGRA~1\Navnt\npssvc.exeC:\WINDOWS\system32\regsvc.exeC:\WINDOWS\system32\MSTask.exeC:\Program Files\Spyware Terminator\sp_rsser.exeC:\WINDOWS\system32\stisvc.exeC:\WINDOWS\System32\UtilMan.exeC:\WINDOWS\System32\WBEM\WinMgmt.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\SCardSvr.exeC:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exeC:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\BUFFALO\Client Manager3\cm3_tray.exeC:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXEC:\WINDOWS\System32\wuauclt.exeC:\WINDOWS\system32\osk.exeC:\WINDOWS\system32\MSSWCHX.EXEC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Documents and Settings\gary\Desktop\HiJackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ask.co.ukR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.manx.netR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ask.co.ukR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.manx.netO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dllO2 - BHO: Media Player Codec - {54202673-BD70-423C-AE57-5B2354567629} - C:\WINDOWS\dsaip32b.dllO2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dllO4 - HKLM\..\Run: [systemTray] SysTray.ExeO4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [Norton eMail Protect] C:\Program Files\Navnt\POProxy.exeO4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exeO4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exeO4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytrayO4 - HKLM\..\Run: [sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptionsO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [spywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [] OSK.exe (User 'Default user')O4 - Global Startup: ClientManager3.lnk = C:\Program Files\BUFFALO\Client Manager3\cm3_tray.exeO8 - Extra context menu item: &eBay Search - res://D:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.htmlO10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dllO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cabO23 - Service: Bwsvc - BUFFALO INC. - C:\Program Files\BUFFALO\Client Manager3\bwsvc\bwsvc.exeO23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXEO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exeO23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exeO23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exeO23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exeO23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exeO23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exeO23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe--End of file - 5769 bytes Quote Link to comment Share on other sites More sharing options...
-pops- Posted April 2, 2008 Report Share Posted April 2, 2008 This is more than likely a come-on to entice you to buy rubbish software. Is there anything other than the message you quoted?Depending on your operating system, can you do a System Restore to a time before this made its presence known? (ME, XP and Vista will allow this).Do you have a full system backup? If not, I strongly recommend that you prepare one in case this happens again. Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted April 3, 2008 Report Share Posted April 3, 2008 We do no longer have the resource to analyze HijackThis logs.Click OK to download antispyware program to clean your system.Under no circumstances let this "antispyware" install on your computer; most likely this will lead to multiple infections.What I recommend is to run an online scan with http://housecall.trendmicro.com/ (make sure you select v6.6 if you are on vista). This will tell you if your computer is already infected, and you can select to take the appropriate steps to clean your system. Quote Link to comment Share on other sites More sharing options...
kimanne Posted October 31, 2008 Report Share Posted October 31, 2008 this spyware blocks trendmicro from downloading and/or running had to download malwarebytes to get rid of it..it takes over whole system and even locks you out of task manager and control panel. It's taken me 4 days to delete all the files it contaminated. Quote Link to comment Share on other sites More sharing options...
Vino Rosso Posted October 31, 2008 Report Share Posted October 31, 2008 If you are still having problems...1 - SmitfraudFixDelete any version of SmitfraudFix you may already have - this is important as SmitfraudFix is updated very frequentlyDownload SmitfraudFix (by S!Ri) to your Desktop from >here< or >here< Double-click smitfraudfix.exe Select option #1 - Search by typing 1 and press Enter This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply. IMPORTANT: Do NOT run any other options until you are asked to do so! Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. 2 - Uninstall ListRun HijackThis then click on Open the Misc Tools sectionIf HijackThis is still open, click on Config > Misc Tools Click on Open Uninstall Manager...Click on Save list...Leave the default filename as uninstall_list.txt and save the file, noting where it has been savedClose HijackThis.3 - Check on statusAfter you have completed the above, please reboot and post:the SmitfraudFix output file rapport.txtthe uninstall_list.txtThanksVino Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.