Jump to content

OT Damned malware


bholder

Recommended Posts

  • Members

So I got fooled into trying to apply a new DivX codec, which seems to have loaded up this damned "SystemDefender" malware on my home laptop. Pain in the ass, keeps telling me I'm infected and hijacking me off to their site to try to get me to buy their "cleaner". I started up Symantec, it found it and quarantined it, but the damned thing's got itself wormed into Windows system restore.

 

Anyone know how to get rid of it? I imagine it left something in the registry, but how do I find it?

Link to comment
Share on other sites

  • Members

Crap,it looks like SystemDefender is gone, but there's something else left behind that Symantec isn't picking up so far.

 

If I ever get my hands on one of the little bastards that writes this crap, the results will not be pretty.

Link to comment
Share on other sites

  • Members

Grab this, run it, and post the logfile it will create:

 

http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

 

Then, get rid of Norton and install the trial version of NOD32 from ESET:

 

http://www.eset.com/download/index.php

 

and run it.

 

If you're going to be paying for an AV solution, NOD32 is probably the best there is, and it's not a resource hog like Norton.

Link to comment
Share on other sites

  • Members

Ok, here's the logfile:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:29:04 AM, on 10/6/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:Program FilesCommon FilesVirtual Tokenvtserver.exe

C:WINDOWSsystem32ibmpmsvc.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesIntelWirelessBinEvtEng.exe

C:Program FilesIntelWirelessBinS24EvMon.exe

C:Program FilesCommon FilesSymantec SharedccSetMgr.exe

C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe

C:Program FilesCommon FilesSymantec SharedccProxy.exe

C:Program FilesSymantec Client SecuritySymantec Client FirewallISSVC.exe

C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe

C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe

C:WINDOWSsystem32LEXBCES.EXE

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSsystem32LEXPPS.EXE

C:WINDOWSsystem32Drivers rcboot.exe

C:Program FilesIBMPersonal CommunicationsPCS_AGNT.EXE

C:Program FilesSymantec Client SecuritySymantec AntiVirusDefWatch.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesIBMIBM Rapid Restore Ultra

rpcsb.exe

c:sdworkissimsvc.exe

C:PROGRA~1AT&TNE~1NetCfgSv.EXE

C:WINDOWSSystem32QCONSVC.EXE

C:Program FilesIntelWirelessBinRegSrvc.exe

c:Program FilesSymantec Client SecuritySymantec AntiVirusSavRoam.exe

C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesSymantec Client SecuritySymantec AntiVirusRtvscan.exe

C:Program FilesSymantec Client SecuritySymantec Client FirewallSymSPort.exe

C:WINDOWSSystem32TPHDEXLG.EXE

C:WINDOWSsystem32TpKmpSVC.exe

C:Program FilesViewpointCommonViewpointService.exe

C:WINDOWSsystem32Driversldlcserv.exe

C:Program FilesViewpointViewpoint ManagerViewMgr.exe

C:Program FilesSynapticsSynTPSynTPLpr.exe

C:Program FilesSynapticsSynTPSynTPEnh.exe

C:WINDOWSsystem32igfxtray.exe

C:Program FilesThinkPadUltraNav WizardUNavTray.EXE

C:WINDOWSsystem32hkcmd.exe

C:WINDOWSsystem32TpShocks.exe

C:PROGRA~1ThinkPadPkgMgrHOTKEYTPHKMGR.exe

C:PROGRA~1ThinkPadUTILIT~1EzEjMnAp.Exe

C:Program FilesThinkPadPkgMgrHOTKEYTPONSCR.exe

C:Program FilesThinkPadPkgMgrHOTKEY_1TpScrex.exe

C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

C:WINDOWSsystem32dla fswctrl.exe

C:Program FilesIBMMessages By IBMibmmessages.exe

C:IBMTOOLSUTILSibmprc.exe

C:Program FilesThinkPadConnectUtilitiesQCTRAY.EXE

C:Program FilesThinkPadConnectUtilitiesQCWLICON.EXE

C:WINDOWSsystem32

undll32.exe

C:Program FilesJavajre1.5.0_06injusched.exe

C:Program FilesIBMPersonal Communications pam.exe

C:Program FilesLexmark X6100 Serieslxbfbmgr.exe

C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe

C:Program FilesCommon FilesSymantec SharedccApp.exe

C:PROGRA~1SYMANT~1SYMANT~2VPTray.exe

C:PROGRA~1ThinkPadUTILIT~1NPDTray.exe

C:Program FilesQuickTimeqttask.exe

C:Program FilesMegaSoundRecorderMega Sound Recorder.exe

C:Program FilesGoogleGoogle Desktop SearchGoogleDesktopIndex.exe

C:Program FilesLexmark X6100 Serieslxbfbmon.exe

C:Program FilesYahoo!MessengerYahooMessenger.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesCNN PipelineCNN.VideoNet.App.exe

C:Program FilesWindows Media PlayerWMPNSCFG.exe

C:WINDOWSsystem32 askmgr.exe

C:Program FilesClipomaticClipomatic.exe

C:Program FilesDigital Line DetectDLG.exe

C:Program FilesYahoo!Yahoo! Music Jukeboxymetray.exe

C:Program FilesyProxyyProxy.exe

C:Program FilesGoogleGoogle Desktop SearchGoogleDesktopCrawl.exe

C:Program FilesSymantec Client SecuritySymantec AntiVirusVPC32.exe

C:Program FilesJavajre1.5.0_06injucheck.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:WINDOWSExplorer.exe

C:Program FilesTrend MicroHijackThisHijackThis.exe

 

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.yahoo.com

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com

R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: MSVPS System - {3ADCBC16-19FA-4C59-9C22-E17C71B5FD7A} - C:WINDOWSndsronw.dll

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:Program FilesYahoo!Commonyiesrvc.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:WINDOWSsystem32dla fswshx.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_06inssv.dll

O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:Program FilesViewpointViewpoint Toolbar3.8.0ViewBarBHO.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll

O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:Program FilesCommon FilesViewpointToolbar Runtime3.8.0IEViewBar.dll

O3 - Toolbar: The netadv - {ABF529BE-6245-465A-BBD4-238C4EAB0F0A} - C:WINDOWS

etadv.dll

O4 - HKLM..Run: [synTPLpr] C:Program FilesSynapticsSynTPSynTPLpr.exe

O4 - HKLM..Run: [synTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe

O4 - HKLM..Run: [igfxTray] C:WINDOWSsystem32igfxtray.exe

O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe

O4 - HKLM..Run: [TPKMAPHELPER] C:Program FilesThinkPadUtilitiesTpKmapAp.exe -helper

O4 - HKLM..Run: [TpShocks] TpShocks.exe

O4 - HKLM..Run: [TPHOTKEY] C:PROGRA~1ThinkPadPkgMgrHOTKEYTPHKMGR.exe

O4 - HKLM..Run: [ControlCenter] "C:Program FilesIBM fingerprint softwarectlcntr.exe" /startup

O4 - HKLM..Run: [TP4EX] tp4ex.exe

O4 - HKLM..Run: [EZEJMNAP] C:PROGRA~1ThinkPadUTILIT~1EzEjMnAp.Exe

O4 - HKLM..Run: [soundMAXPnP] C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

O4 - HKLM..Run: [soundMAX] C:Program FilesAnalog DevicesSoundMAXSmax4.exe /tray

O4 - HKLM..Run: [updateManager] "C:Program FilesCommon FilesSonicUpdate Managersgtray.exe" /r

O4 - HKLM..Run: [dla] C:WINDOWSsystem32dla fswctrl.exe

O4 - HKLM..Run: [ibmmessages] C:Program FilesIBMMessages By IBM\ibmmessages.exe

O4 - HKLM..Run: [iBMPRC] C:IBMTOOLSUTILSibmprc.exe

O4 - HKLM..Run: [QCTRAY] C:Program FilesThinkPadConnectUtilitiesQCTRAY.EXE

O4 - HKLM..Run: [QCWLICON] C:Program

Link to comment
Share on other sites

  • Members

FilesThinkPadConnectUtilitiesQCWLICON.EXE

O4 - HKLM..Run: [PWRMGRTR] rundll32 C:PROGRA~1ThinkPadUTILIT~1PWRMGRTR.DLL,PwrMgrBkGndMonitor

O4 - HKLM..Run: [bLOG] rundll32 C:PROGRA~1ThinkPadUTILIT~1BatLogEx.DLL,StartBattLog

O4 - HKLM..Run: [sunJavaUpdateSched] C:Program FilesJavajre1.5.0_06injusched.exe

O4 - HKLM..Run: [Tpam.exe] "C:Program FilesIBMPersonal Communications pam.exe"

O4 - HKLM..Run: [iSSI EZUpdate Service] "c:sdworkissimsvc.exe"

O4 - HKLM..Run: [C4EBReg] "C:Program FilesC4ebregc4ebreg.exe" /q

O4 - HKLM..Run: [stgclean] c:sdworkw32main2.exe /cleanup

O4 - HKLM..Run: [Lexmark X6100 Series] "C:Program FilesLexmark X6100 Serieslxbfbmgr.exe"

O4 - HKLM..Run: [Google Desktop Search] "C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe" /startup

O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"

O4 - HKLM..Run: [vptray] C:PROGRA~1SYMANT~1SYMANT~2VPTray.exe

O4 - HKLM..Run: [symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe /Enterprise

O4 - HKLM..Run: [NPDTRAY] C:PROGRA~1ThinkPadUTILIT~1NPDTray.exe

O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime

O4 - HKLM..Run: [PATHPILOT] C:Program FilesMegaSoundRecorderMega Sound Recorder.exe

O4 - HKCU..Run: [ibmmessages] C:Program FilesIBMMessages By IBMibmmessages.exe

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [Yahoo! Pager] "C:Program FilesYahoo!MessengerYahooMessenger.exe" -quiet

O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [CNN.Pipeline.Alerter] "C:Program FilesCNN PipelineCNN.VideoNet.App.exe" /cnndriver:startapp alerter

O4 - HKCU..Run: [Mega Sound Recorder] C:Program FilesMegaSoundRecorderMega Sound Recorder.exe

O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe

O4 - Startup: Mozilla Firefox.lnk = C:Program FilesMozilla Firefoxfirefox.exe

O4 - Startup: Mozilla Thunderbird.lnk = C:Program FilesMozilla Thunderbird hunderbird.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Reader

eader_sl.exe

O4 - Global Startup: Clipomatic.lnk = C:Program FilesClipomaticClipomatic.exe

O4 - Global Startup: Digital Line Detect.lnk = ?

O4 - Global Startup: ymetray.lnk = C:Program FilesYahoo!Yahoo! Music Jukeboxymetray.exe

O4 - Global Startup: yProxy.lnk = C:Program FilesyProxyyProxy.exe

O8 - Extra context menu item: &Yahoo! Search - file:///C:Program FilesYahoo!Common/ycsrch.htm

O8 - Extra context menu item: Open Link Target in Firefox - file://C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfilesom89zjw7.defaultextensions{5D558C43-550F-4b12-84AB-0D8ABDA9F975}firefoxviewlink.html

O8 - Extra context menu item: View This Page in Firefox - file://C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfilesom89zjw7.defaultextensions{5D558C43-550F-4b12-84AB-0D8ABDA9F975}firefoxviewpage.html

O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:Program FilesYahoo!Common/ycdict.htm

O8 - Extra context menu item: Yahoo! &Maps - file:///C:Program FilesYahoo!Common/ycmap.htm

O8 - Extra context menu item: Yahoo! &SMS - file:///C:Program FilesYahoo!Common/ycsms.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06inssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06inssv.dll

O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:Program FilesYahoo!Commonyiesrvc.dll

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:PROGRA~1AIMaim.exe

O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:Program FilesLenovoPkgMgr\PkgMgr.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:Program FilesYahoo!MessengerYahooMessenger.exe

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:Program FilesYahoo!MessengerYahooMessenger.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O10 - Broken Internet access because of LSP provider 'c:program files

ewdotnet

ewdotnet6_38.dll' missing

O11 - Options group: [JAVA_IBM] Java (IBM)

O17 - HKLMSystemCS1ServicesTcpipParameters: SearchList = ibm.com

O17 - HKLMSystemCCSServicesTcpipParameters: SearchList = ibm.com

O20 - AppInit_DLLs: C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL

O21 - SSODL: msvb - {0837F1F8-E35A-4A4A-8AA6-8881992FC6B6} - C:WINDOWSmsvb.dll

O21 - SSODL: sysdx - {F6F6727C-04D8-4AED-A928-A7CF73503F5D} - C:WINDOWSsysdx.dll

O23 - Service: AppnNode - IBM Corporation - C:WINDOWSsystem32Driversappnnode.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe

O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccProxy.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:Program FilesSymantec Client SecuritySymantec AntiVirusDefWatch.exe

O23 - Service: EvtEng - Intel Corporation - C:Program FilesIntelWirelessBinEvtEng.exe

O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:Program FilesIBMIBM Rapid Restore Ultra

rpcsb.exe

O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:WINDOWSsystem32ibmpmsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1050Intel 32IDriverT.exe

O23 - Service: ISSI EZUpdate (ISSIMon) - IBM Global Services - c:sdworkissimsvc.exe

O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:Program FilesSymantec Client SecuritySymantec Client FirewallISSVC.exe

O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:WINDOWSsystem32Driversldlcserv.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE

O23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE

O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:PROGRA~1AT&TNE~1NetCfgSv.EXE

O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:WINDOWSsystem32PsaSrv.exe (file missing)

O23 - Service: QCONSVC - IBM Corp. - C:WINDOWSSystem32QCONSVC.EXE

O23 - Service: RegSrvc - Intel Corporation - C:Program FilesIntelWirelessBinRegSrvc.exe

O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:Program FilesIntelWirelessBinS24EvMon.exe

O23 - Service: SAVRoam (SavRoam) - symantec - c:Program FilesSymantec Client SecuritySymantec AntiVirusSavRoam.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:Program FilesSymantec Client SecuritySymantec AntiVirusRtvscan.exe

O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:Program FilesSymantec Client SecuritySymantec Client FirewallSymSPort.exe

O23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:WINDOWSSystem32TPHDEXLG.EXE

O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:WINDOWSsystem32TpKmpSVC.exe

O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:WINDOWSsystem32Drivers rcboot.exe

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:Program FilesViewpointCommonViewpointService.exe

O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:Program FilesCommon FilesVirtual Tokenvtserver.exe

 

--

End of file - 16889 bytes

Link to comment
Share on other sites

  • Members

I have no idea where I picked this crap up from. The logfile was generated by that HijackThis program, as you suggested.

 

I ran the free version of SpyHunter, which claims to be able to find and remove this crap, and sure found lots of suspicious stuff, but of course, they want you to pay for the version that'll actually do the removal. For all I know, they could be scammers too.

 

I'll have some choice feedback to Symantec for not finding and handling this better. They're getting paid big bucks to make sure this doesn't happen.

Link to comment
Share on other sites

  • Members

I have no idea where I picked this crap up from. The logfile was generated by that HijackThis program, as you suggested.


I ran the free version of SpyHunter, which claims to be able to find and remove this crap, and sure found lots of suspicious stuff, but of course, they want you to pay for the version that'll actually do the removal. For all I know, they could be scammers too.


I'll have some choice feedback to Symantec for not finding and handling this better. They're getting paid big bucks to make sure this doesn't happen.

 

They won't give a {censored}. :D You can try, though.

 

Another free, good spyware scanner that you won't have to pay to use is Lavasoft's Ad-Aware. Run that and see if it's of any help. SpyHunter appears to be an absolutely terrible piece of software, and I wouldn't give them a cent.

Link to comment
Share on other sites

  • Members

You've got a bunch of crap installed, nasty crap too, adaware and spybot can't remove these (yet).

O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:Program FilesViewpointViewpoint Toolbar3.8.0ViewBarBHO.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:Program FilesCommon FilesViewpointToolbar Runtime3.8.0IEViewBar.dll
O3 - Toolbar: The netadv - {ABF529BE-6245-465A-BBD4-238C4EAB0F0A} - C:WINDOWSetadv.dll

Viewpoint is spyware and netadv.dll is probably causing the mediadefender popups.
Removing these completely is gonna take some work.

Viewpoint:
1) Kill the C:Program FilesViewpointViewpoint ManagerViewMgr.exe process with the taskmanager

2) Unregister these DLL's with regsvr32.exe
ViewBar.dll
ViewBarBHO.dll
SWFView.dll
AxMetaStream.dll

Then reboot.

3) Now the fun part, start regedit.exe and search for any of these items
ViewpointSearchBar
Viewpoint
Viewpoint Manager
ViewpointSearchBar
Viewpoint
Viewpoint
ViewBarBHO.BHO
ViewBarBHO.BHO.1
ViewBar.ViewBar
ViewBar.ViewBar.1
AxMetaStream.MetaStreamCtl
AxMetaStream.MetaStreamCtl.1
AxMetaStream.MetaStreamCtlSecondary
AxMetaStream.MetaStreamCtlSecondary.1
Viewpoint
ViewBarBHO.BHO
ViewBarBHO.BHO.1
ViewBar.ViewBar
ViewBar.ViewBar.1
AxMetaStream.MetaStreamCtl
AxMetaStream.MetaStreamCtl.1
AxMetaStream.MetaStreamCtlSecondary
AxMetaStream.MetaStreamCtlSecondary.1
@viewpoint.com/VMP
ViewpointPermissionChecker2
&Viewpoint Search
ViewpointSearchBar
Viewpoint Manager
ViewpointMediaPlayer
{A7327C09-B521-4EDB-8509-7D2660C9EC98}
MetaStream3
MetaStream
{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
{A7327C09-B521-4EDB-8509-7D2660C9EC98}
{F8AD5AA5-D966-4667-9DAF-2561D68B2012}
{03F998B2-0E00-11D3-A498-00104B6EB52E}
{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
{F0ED1949-59F9-447D-A8B9-FBDCEBC85198}
{E060D9D9-E979-4C2F-A840-BE5150F84AC5}
{9DBB28C1-1925-11D3-A498-00104B6EB52E}
{A7327C09-B521-4EDB-8509-7D2660C9EC98}
{F8AD5AA5-D966-4667-9DAF-2561D68B2012}
{03F998B2-0E00-11D3-A498-00104B6EB52E}
{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
{F0ED1949-59F9-447D-A8B9-FBDCEBC85198}
{E060D9D9-E979-4C2F-A840-BE5150F84AC5}
{9DBB28C1-1925-11D3-A498-00104B6EB52E}

If you find any of them, delete.

4)Delete C:Program FilesViewpoint and C:Program FilesCommon FilesViewpoint directories

It might be a good idea to search your harddrive for other AxMetastream and Viewpoint files and directories and delete them. (just uses the windows file search)

Link to comment
Share on other sites

  • Members

Another free,
good
spyware scanner that you won't have to pay to use is Lavasoft's
Ad-Aware.
Run that and see if it's of any help. SpyHunter appears to be an absolutely terrible piece of software, and I wouldn't give them a cent.

 

Spybot search and destroy is good as well, AVG has an anti-spyware, and surprisingly, Microsoft's antispyware is solid.

 

I run all four. Go for the scattergun approach :D

Link to comment
Share on other sites

  • Members

You might want to copy this to a txt file or print it, because you can't use your internetconnection in Safe Mode.

Netadv.dll:

1) Download SmitFraudFix

2) Reboot into Safe Mode

3) Run Hijackthis and check:
O3 - Toolbar: The netadv - {ABF529BE-6245-465A-BBD4-238C4EAB0F0A} - C:WINDOWSetadv.dll

Then click Fix checked.

4) Delete the file C:WINDOWSetadv.dll

5) Run SmitFraudFix, select option 2, this will probably replace wininet.dll.

6) Reboot into normal mode if SmitFraudFix doesn't do it for you.

7) Go to Control Panel > Display properties > Desktop > Customize Desktop > Web tab
Select "Privacy Protection" if you it find in there and delete it.

8) Start SmitFraudFix again, select the 3rd option and let it restore the trusted zone by pressing y after that.

It should be fixed now, but just to make sure, post a new Hijackthis log here and also the SmitFraudFix log (c:apport.txt).

Link to comment
Share on other sites

  • Members

bholder I use Spybot search and destroy. It finds things the Symantec misses. It was a free download, too, at the recomendation of an AT&T Yahoo tech. It works. Supposedly now the spies can act like viruses and the viruses can act like spies, something which happened in the last year. Spybot gets rid of them.

Link to comment
Share on other sites

  • Members

Things are looking better, thanks. I thought I had AdAware installed already, but I guess not. Not sure which one of the above did the trick, but the popups have stopped for now.

 

FWIW, Spybot search and destroy and Spywarebot search and destroy are two very different things - if you do a google for the former, the latter shows up at the top of the list, but beware, the latter is just another one of these malware programs that takes you to their site to get a paid license for their product. {censored}ing scammers need to die painfully.

Link to comment
Share on other sites

  • Members

After a reboot, all seems happy and normal again (and a bit faster than even before this latest round). Thanks for the help, guys.

 

KK, is Microsoft's antispyware something built-in I just have to turn on, or is that a separate download (and fee?)??

Link to comment
Share on other sites

  • Members

 

After a reboot, all seems happy and normal again (and a bit faster than even before this latest round). Thanks for the help, guys.


KK, is Microsoft's antispyware something built-in I just have to turn on, or is that a separate download (and fee?)??

 

 

Free, separate download (though depending on your windows update settings it may automatically install).

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...