1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Spyware Problems

Discussion in 'Malware and Virus Removal Archive' started by stevedoylenz, 2005/01/25.

Thread Status:
Not open for further replies.
  1. 2005/01/25
    stevedoylenz

    stevedoylenz Inactive Thread Starter

    Joined:
    2005/01/25
    Messages:
    5
    Likes Received:
    0
    Hi Folks,

    I've done the HijackThis thing, listed below, what next??

    Logfile of HijackThis v1.99.0
    Scan saved at 12:25:45 p.m., on 26/01/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    D:\WINNT\System32\smss.exe
    D:\WINNT\system32\winlogon.exe
    D:\WINNT\system32\services.exe
    D:\WINNT\system32\lsass.exe
    D:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
    D:\WINNT\system32\svchost.exe
    D:\WINNT\system32\spoolsv.exe
    D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    D:\WINNT\System32\svchost.exe
    D:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
    D:\WINNT\system32\regsvc.exe
    D:\WINNT\system32\MSTask.exe
    D:\WINNT\system32\ZoneLabs\vsmon.exe
    D:\WINNT\Explorer.EXE
    D:\WINNT\System32\WBEM\WinMgmt.exe
    D:\WINNT\system32\svchost.exe
    D:\WINNT\System32\SCardSvr.exe
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    D:\Program Files\GIANT Company Software\Spam Inspector\siService.exe
    D:\WINNT\system32\atiptaxx.exe
    D:\Program Files\Winamp\winampa.exe
    D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    D:\DOCUME~1\Stephen\LOCALS~1\Temp\bundle.exe
    D:\Program Files\GIANT Company Software\Spam Inspector\siMailProxyServer.exe
    D:\Program Files\GIANT Company Software\Spam Inspector\siSpamFilterEngine.exe
    D:\Program Files\AdStatus Service\AdStatServ.exe
    D:\Program Files\AdStatus Service\AdStatKeep.exe
    D:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
    D:\Program Files\Calenz\Calenz.exe
    D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    D:\Program Files\Microsoft Office\Office\WINWORD.EXE
    D:\Program Files\Internet Explorer\IEXPLORE.EXE
    D:\Program Files\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [siService.exe] "D:\Program Files\GIANT Company Software\Spam Inspector\siService.exe "
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINNT\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SAHBundle] D:\DOCUME~1\Stephen\LOCALS~1\Temp\bundle.exe
    O4 - HKLM\..\Run: [AdStatus Service] D:\Program Files\AdStatus Service\AdStatServ.exe
    O4 - Startup: Calenz Startup.lnk = D:\Program Files\Calenz\Calenz.exe
    O4 - Global Startup: NetScreen-Remote.lnk = D:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MusicUnlimited/ie/bridge-c8.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
    O23 - Service: SafeNet Monitor Service - SafeNet - D:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
    O23 - Service: SafeNet IKE Service - SafeNet - D:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
    O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - D:\WINNT\system32\ZoneLabs\vsmon.exe
     
  2. 2005/01/25
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0

  3. to hide this advert.

  4. 2005/01/25
    stevedoylenz

    stevedoylenz Inactive Thread Starter

    Joined:
    2005/01/25
    Messages:
    5
    Likes Received:
    0
    Sorry Jim, I should always read the rules first!!
    I run Spybot v1.3 latest detection update 2005-01-06
    After start-up it always detects AdTools and SAHAgent. Also I'm aware that Lssas.exe is also a trojan of some type. As I run a number of mailing lists I need to keep my machine as clean as possible.
     
  5. 2005/01/25
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    stevedoylenz--I am surprised that SpybotS&D (with updated reference files) does not detect and offer to remove the problems you mention, especially Adtools and SAHAgent.
    Have you also run AdAware?
    http://www.lavasoft.de/support/download/ (with latest updated reference files, of course)
    If no success--
    Concerning AdTools some info and ideas to remove here.
    http://www.cexx.org/msgmates.htm
    Concerning SAHAgent
    http://www.pestpatrol.com/PestInfo/s/sahagent.asp
    However, Lsass versus Isass has always been a problem to diagnose (because little L and capital i are so similar). Lsass in the Windows\System32 folder is not a virus or spyware. Elsewhere it is.
    http://www.google.com/search?hl=en&rls=GGLD,GGLD:2004-31,GGLD:en&q=Lsass.exe&spell=1
    However, having said all that, you still should consider posting per
    http://www.windowsbbs.com/showthread.php?t=37074
     
    Last edited: 2005/01/26
  6. 2005/01/25
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Run Hijackthis again, scan, and check the following for removal.
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    (note: not malware but not needed by you at startup so call it 'sludgeware')
    O4 - HKLM\..\Run: [SAHBundle] D:\DOCUME~1\Stephen\LOCALS~1\Temp\bundle.exe
    (note: after you remove the reg entry, check Here for detailed instructions to remove the underlying spyware infestation)
    O4 - HKLM\..\Run: [AdStatus Service] D:\Program Files\AdStatus Service\AdStatServ.exe
    (note: can't find any detail on this which is usually a bad sign. Unless you know what it is, kill this entry and then uninstall the app from add/remove and then delete the \program files\AdStatus Service folder if still present)
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/M...e/bridge-c8.cab

    Delete all items in the temp folders for all user accounts on the PC.
    From start, run, key in cleanmgr.exe and when it presents a list of things to delete, let it do so. May take a while.
    Turn off System Restore, reboot, and turn it back on.
    Run Hijackthis again and post a new log file.

    The lsass you see running from \system32 is almost certainly the legit process and needed for proper operation of your PC.
     
    Newt,
    #5
  7. 2005/01/25
    stevedoylenz

    stevedoylenz Inactive Thread Starter

    Joined:
    2005/01/25
    Messages:
    5
    Likes Received:
    0
    Spybot

    Jim,
    When I run Spybot it does offer to remove AdTools and SAHAgent, so I do. They are there again after a restart.
     
  8. 2005/01/26
    stevedoylenz

    stevedoylenz Inactive Thread Starter

    Joined:
    2005/01/25
    Messages:
    5
    Likes Received:
    0
    Latest

    I've followed Newt's instructions.
    This is the latest HijackThis Log

    Logfile of HijackThis v1.99.0
    Scan saved at 11:17:32 a.m., on 27/01/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    D:\WINNT\System32\smss.exe
    D:\WINNT\system32\winlogon.exe
    D:\WINNT\system32\services.exe
    D:\WINNT\system32\lsass.exe
    D:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
    D:\WINNT\system32\svchost.exe
    D:\WINNT\system32\spoolsv.exe
    D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    D:\WINNT\System32\svchost.exe
    D:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
    D:\WINNT\system32\regsvc.exe
    D:\WINNT\system32\MSTask.exe
    D:\WINNT\system32\ZoneLabs\vsmon.exe
    D:\WINNT\System32\WBEM\WinMgmt.exe
    D:\WINNT\system32\svchost.exe
    D:\WINNT\System32\SCardSvr.exe
    D:\WINNT\Explorer.EXE
    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    D:\Program Files\GIANT Company Software\Spam Inspector\siService.exe
    D:\WINNT\system32\atiptaxx.exe
    D:\Program Files\Winamp\winampa.exe
    D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    D:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
    D:\Program Files\Calenz\Calenz.exe
    D:\Program Files\GIANT Company Software\Spam Inspector\siMailProxyServer.exe
    D:\Program Files\GIANT Company Software\Spam Inspector\siSpamFilterEngine.exe
    D:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [siService.exe] "D:\Program Files\GIANT Company Software\Spam Inspector\siService.exe "
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINNT\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - Startup: Calenz Startup.lnk = D:\Program Files\Calenz\Calenz.exe
    O4 - Global Startup: NetScreen-Remote.lnk = D:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MusicUnlimited/ie/bridge-c8.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
    O23 - Service: SafeNet Monitor Service - SafeNet - D:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
    O23 - Service: SafeNet IKE Service - SafeNet - D:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
    O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - D:\WINNT\system32\ZoneLabs\vsmon.exe
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.