Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

spy ware, pop up (resolved)


  • This topic is locked This topic is locked

#1
carambaa

carambaa

    New Member

  • Member
  • Pip
  • 4 posts
Hi
Pop ups are taking the overhand again. Ad-aware, S&D dont find anything anymore. The most annoying one of all is called messenger service, cant seem to find and remove it

Could someone have a look at this log and see what needs to be removed. Much much appreciated
Rob

MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\hidserv.exe
D:\WINNT\System32\nvsvc32.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
C:\Tmntsrv.exe
D:\WINNT\Explorer.exe
C:\pccntupd.exe
C:\MndlSvr.exe
C:\Pop3trap.exe
C:\WebTrapNT.exe
D:\WINNT\System32\MMTrayLSI.exe
D:\WINNT\System32\MMTray2k.exe
D:\WINNT\System32\MMTray.exe
D:\WINNT\System32\internat.exe
D:\WINNT\system32\msiexec.exe
D:\Program Files\WinZip\WZQKPICK.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Documents and Settings\ Zwik Zwetsjanus\Desktop\Zwik\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.nl/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Internet Explorer Hot Fix - {A787CF4D-5AC9-4641-BF42-B72AAC45AF6B} - D:\WINNT\System32\dtzgd.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Goldensoft_MndlSvr] c:\\MndlSvr.exe
O4 - HKLM\..\Run: [C-Media Mixer] c:\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\WebTrapNT.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=061205 serial=DR12WTX-9999998-YSP lang=EN
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MNTP] forces_elite.exe
O4 - HKLM\..\Run: [SysEntry] SYSTRAV.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Real-time Monitor.lnk = C:\PNTIOMON.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Tmntsrv.exe
  • 0

Advertisements


#2
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Please repost your FULL HJT log, including the header.
  • 0

#3
carambaa

carambaa

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
ok here it is
Logfile of HijackThis v1.99.1
Scan saved at 14:17:50, on 3-6-2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\hidserv.exe
D:\WINNT\System32\nvsvc32.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
C:\Tmntsrv.exe
D:\WINNT\Explorer.exe
C:\pccntupd.exe
C:\MndlSvr.exe
C:\Pop3trap.exe
C:\WebTrapNT.exe
D:\WINNT\System32\MMTrayLSI.exe
D:\WINNT\System32\MMTray2k.exe
D:\WINNT\System32\MMTray.exe
D:\WINNT\System32\internat.exe
D:\WINNT\system32\msiexec.exe
D:\Program Files\WinZip\WZQKPICK.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Documents and Settings\ Zwik Zwetsjanus\Desktop\Zwik\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.nl/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Internet Explorer Hot Fix - {A787CF4D-5AC9-4641-BF42-B72AAC45AF6B} - D:\WINNT\System32\dtzgd.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Goldensoft_MndlSvr] c:\\MndlSvr.exe
O4 - HKLM\..\Run: [C-Media Mixer] c:\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\WebTrapNT.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=061205 serial=DR12WTX-9999998-YSP lang=EN
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MNTP] forces_elite.exe
O4 - HKLM\..\Run: [SysEntry] SYSTRAV.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Real-time Monitor.lnk = C:\PNTIOMON.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Tmntsrv.exe
  • 0

#4
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Hi Again,

Lets get this show on the road.

Firstly please create a new folder on your c drive (for example C:\HJT), install HJT into that folder and run it from there, that way it can create backups if required.

Please print out these instructions to make it easy to follow and to have access to them when you have to reboot your pc. Please read through them prior to commencing to do anything and if there is anything that you are unsure of, or do not understand, please contact me first for assistance.

I would like you to carry out the following free on-line virus scan and follow their instructions on removal of anything that it may find.

Panda Active Scan

Next please download the following two programs. Install them and update them both. Then run each one and have them fix anything that they may find.

Spybot Search and Destroy 1.4

Ad-aware S E 1.5

Download the following program.

Cleanup. Do NOT run it yet.

Set PC to show hidden files (Click link below if you do not know how

Show hidden files

Reboot into SAFE MODE by tapping the F8 key whilst PC starts up. Select SAFE MODE option

Open up HJT and rescan and Place a check against each of the following, making sure you get them all and not any others by mistake. Some of them might not be there as they will have been removed in previous stages of the sequence. This is normal so do not be alarmed

O2 - BHO: Internet Explorer Hot Fix - {A787CF4D-5AC9-4641-BF42-B72AAC45AF6B} - D:\WINNT\System32\dtzgd.dll
O4 - HKLM\..\Run: [MNTP] forces_elite.exe
O4 - HKLM\..\Run: [SysEntry] SYSTRAV.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


Ensure no windows are open apart from HJT and click FIX CHECKED.

Using Windows Explorer locate and delete the following files/folders.

D:\WINNT\System32\dtzgd.dll

Carry out a search for the following 2 files and delete them if found

forces_elite.exe
SYSTRAV.exe


Now use the Cleanup program to clear out temp files, junk etc.

Reboot normally and rescan with HJT and post the log in this thread
  • 0

#5
carambaa

carambaa

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Thanks,
Done as you discribed above,
Below is the new HiJackthis logfile
The messenger pop up seems to already be gone! anything else that looks like it should not be there?
Thanks
Again
Rob

Logfile of HijackThis v1.99.1
Scan saved at 12:48:16, on 4-6-2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\Explorer.exe
D:\Documents and Settings\ Zwik Zwetsjanus\Desktop\Zwik\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.nl/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Goldensoft_MndlSvr] c:\\MndlSvr.exe
O4 - HKLM\..\Run: [C-Media Mixer] c:\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\WebTrapNT.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=061205 serial=DR12WTX-9999998-YSP lang=EN
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Real-time Monitor.lnk = C:\PNTIOMON.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Tmntsrv.exe
  • 0

#6
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Hi Carambaa,

My only concern now is that you do not have any service packs installed. Pleas go to microsoft from the link below and update to service pack 4.

Click here


From your log, I see nothing in the ways of trojans, nor any evil entities attempting to possess your computer, except for Windows but it's too late for that one. :tazz:

Congratulations your log now appears to be clean. ;)

Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:

Detect and Remove Programs:
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
Prevention Programs:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
Other necessary Programs:
  • AntiVirus Program<= An AntiVirus program is a must! Whether it is a free version like AVG or Anti-Vir, or a shareware version like Norton or Kapersky, this is a must have.
  • Firewall<= A firewall is definatley a must have. Two good free versions are Sygate and ZoneLabs.
  • More Secure Browser<= Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox, however Opera and SlimBrowsers are good as well.
And also see TonyKlein's good advice
So how did I get infected in the first place? and AntiSpyware Net's spyware article: Spyware, Adware, Malware: What it is, how it got on my computer, how to get rid of it, and how to prevent it.
  • 0

#7
carambaa

carambaa

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Super many thanks for your help, service pack 4 is check.
excellent
Rob
  • 0

#8
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Topic resolved and closed
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP