Help - Search - Members - Calendar
Full Version: Very Tough Spyware Infected my Computer: Need Help
Asia Finest Discussion Forum > AF Entertainment > Technology Chat
Suijen
All right comrades, here's what's up.

I downloaded a few...things and now I've got a malicious program in my computer. It's not only malicious though...the hacker was really smart.

It changed my desktop and kept bringing up popups. I googled and remedied that, but, lo and behold, whenever I use google, it redirects me to a spam site. Alta vista, nothing, but it affects ALL web browsers, even the Opera that I recently installed. And, I can't find solutions to sites because all links that I click on in google redirect me to a spam site. I get around it using google cache. Pretty clever eh? Block off the means of finding a solution. I can actually see on firefox when I use google the ip address change to some other predefined spam one on some godforsaken list somewhere in my computer.

Here's another fun part. My system restore is gone. It keeps telling me to restart before I can create a restore point, and all my past restore points are gone. Double clever.

Spybot/AVG turns up nothing (as expected), even in safemode. In fact, it's actually still active when in safemode/networking. I can't find anything on the google cache pages on this fiendish spyware. CW shredder and Ewido turn up nothing.
I think it's disguised as one of my svchosts.exe but I can't find it. It's not in msconfig/startup either.

This is what shows up on Hijack This:
QUOTE
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:48:34 PM, on 9/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\program files\steam\steam.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

--
End of file - 5425 bytes


Comrades, I'm afraid to say it but I'm even considering reformatting my computer. This son of a cocksucking whore has got the most @$$ ramming program I have ever seen.
utarah
some questions:

1. can you ctrl+alt+del or access your task manager ?

2. in your windows explorer --> Folder, can you see the Folder Options ?

3. can you access your registry by typing the regedit in the run ?

if those above questions are answered by no then I suggest that you download and run these following antimalwares.

1. a-squared free [this is a good anti-malware with enormous database even bigger than avg antispyware ] --> http://www.emsisoft.com/en/software/free/

2. malwarebytes' antimalware [it is capable of finding Hijacked Folder Options and Hijacked Task Manager ] --> http://www.download.com/Malwarebytes-Anti-...4-10804572.html

3. Spyware Terminator [A free anitipsyawre that offers a real-time protection. I suggest that you replace your S&D with it ]--> http://www.spywareterminator.com/ Scan your computer and after sacnning, check the Unknown SW in the Last Scan Report Window. Spyware Terminator will give you a list of unknown softwares when you click the Unknow SW tab.


4. use a registry cleaner. run a registry clean-up after your computer is purged by the suggested antimalwares.
Suijen
Utarah, if you're ever in Berkeley, I'm treating you to a drink. Thank you.
Metropolitan
This is me a couple months ago with the exact same problem as you have. Read through my posts and the help I got. http://www.asksomeone.net/forums/index.php...ic=8131&hl=
planxty
Is it fixed?
If not, might be worth checking your hosts file for rogue entries.
Chinese DesertFox
QUOTE(Suijen @ Sep 15 2008, 09:16 PM) [snapback]3924136[/snapback]
Utarah, if you're ever in Berkeley, I'm treating you to a drink. Thank you.

Just one drink?
Suzuka00
Install AVG Antivirus.
Suijen
QUOTE(planxty @ Sep 16 2008, 01:13 PM) [snapback]3925179[/snapback]
Is it fixed?
If not, might be worth checking your hosts file for rogue entries.


It was completely fixed.

QUOTE(Chinese DesertFox @ Sep 16 2008, 03:49 PM) [snapback]3925263[/snapback]
Just one drink?


Or two

QUOTE(Suzuka00 @ Sep 16 2008, 06:07 PM) [snapback]3925428[/snapback]
Install AVG Antivirus.


I did. I mentioned how it couldn't find anything.
GentleWind
i have one trojan too right now in limewire
Ralf
If folks can afford it, I always recommend having two computers.
One which is used for safe work and storage and it never (or very rarely) goes online.
And another one which is used for online communications, testing software, playing games, etc....
babyshanker
just had one of these rogue malware problems the other day. i just downloaded some anti malware crap and it worked out fine.
BrooklynCarter
what kind of "things"? lol
Hi Tone
Check your windows temp, spyware usually kept there first. Open the dlls with notepad and see which files it's connected to.
Hafiz
QUOTE(Ralf @ Sep 17 2008, 11:37 PM) [snapback]3927338[/snapback]
If folks can afford it, I always recommend having two computers.
One which is used for safe work and storage and it never (or very rarely) goes online.
And another one which is used for online communications, testing software, playing games, etc....


.
hoyky
I can assure that if you have Kaspersky you won't like you need 2 computers, cause kaspersky it will protect your Pc not only against viruses but also spyware, trojans and others. I use it and I recommend it to everyone. http://www.trustdownload.com/Antivirus-and...curity-7.0.html
martin_nuke
You can use Ubuntu it does not get spywares or viruses.

Why not try Combofix.exe it is the last option of Windows users for removing viruses and spywares.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2013 Invision Power Services, Inc.