Unsolved
This post is more than 5 years old
26 Posts
0
704
July 29th, 2005 21:00
Black Spyware background and Slow Boot Up
My computer has this really annoying black Background that keeps saying your computer has been infected with spyware clear here to remove and when i did that it keeps showing up to buy there stupid spyware program its getting on my nerves... its takes a long time just to load up to the window screen.. usually it only takes a few mins to load now i have to wait up to 7-8 mins
Logfile of HijackThis v1.99.1
Scan saved at 3:08:14 PM, on 7/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\INSTALL-ALL-GAMES-HERE !!!\aswUpdSv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
D:\INSTAL~1\FIREFOX.EXE
D:\Common Framework\FrameworkService.exe
D:\INSTALL-ALL-GAMES-HERE !!!\VsTskMgr.exe
D:\INSTALL-ALL-GAMES-HERE !!!\Mcshield.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
D:\Common Framework\UpdaterUI.exe
D:\INSTALL-ALL-GAMES-HERE !!!\shstat.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\Java\jre1.5.0_02\bin\javaw.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O4 - HKLM\..\Run: [ShStatEXE] "D:\INSTALL-ALL-GAMES-HERE !!!\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\INSTALL-ALL-GAMES-HERE !!!\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\INSTALL-ALL-GAMES-HERE !!!\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\INSTALL-ALL-GAMES-HERE !!!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\INSTALL-ALL-GAMES-HERE !!!\ashWebSv.exe" /service (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - D:\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - D:\INSTALL-ALL-GAMES-HERE !!!\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - D:\INSTALL-ALL-GAMES-HERE !!!\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Logfile of HijackThis v1.99.1
Scan saved at 3:08:14 PM, on 7/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\INSTALL-ALL-GAMES-HERE !!!\aswUpdSv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
D:\INSTAL~1\FIREFOX.EXE
D:\Common Framework\FrameworkService.exe
D:\INSTALL-ALL-GAMES-HERE !!!\VsTskMgr.exe
D:\INSTALL-ALL-GAMES-HERE !!!\Mcshield.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
D:\Common Framework\UpdaterUI.exe
D:\INSTALL-ALL-GAMES-HERE !!!\shstat.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\Java\jre1.5.0_02\bin\javaw.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O4 - HKLM\..\Run: [ShStatEXE] "D:\INSTALL-ALL-GAMES-HERE !!!\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\INSTALL-ALL-GAMES-HERE !!!\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\INSTALL-ALL-GAMES-HERE !!!\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\INSTALL-ALL-GAMES-HERE !!!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\INSTALL-ALL-GAMES-HERE !!!\ashWebSv.exe" /service (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - D:\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - D:\INSTALL-ALL-GAMES-HERE !!!\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - D:\INSTALL-ALL-GAMES-HERE !!!\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
No Events found!


NikkJ
94 Posts
0
July 30th, 2005 06:00
I'm Nick, and I will help you clear the problem. I'll post back here after I take a good look at your HJT log.
NikkJ
94 Posts
0
July 30th, 2005 13:00
There isn't much wrong in your log and we will clean it up now.
Please note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
The process is specific to your problem and setup. It should NOT be used anywhere else.
Ensure hidden files and folders are set to show
1 Click Start.
2 Open My Computer.
3 Select the Tools menu and click Folder Options.
4 Select the View Tab.
5 Under the Hidden files and folders heading select Show hidden files and folders.
6 Uncheck the Hide protected operating system files (recommended) option.
7 Click Yes to confirm.
8 Click OK.
Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE
Bring up task manager Ctrl-Alt-Del click on the Processes tab.
Highlight intell32 <<=============== Only this EXACT spelling
If it's there - click on End process.
Close any open windows and run Hijackthis and click the scan button, when it has finished scanning put a check against the following and click 'fix checked'
C:\WINDOWS\System32\intell32.exe
Now find and delete this file, if you can't find it don't worry.
C:\WINDOWS\System32\ intell32.exe
Empty recycle bin and temp. folders (Click Start, and then click Run. In the Open box, type cleanmgr, and then click OK.)
Reboot into normal mode. (Did the black screen Re-appear?)
Next, run an online antivirus scan using
Trend Micros Housecall
=>Select all available drives.
=>Check(tick) "Auto Clean".
=>Click "Scan".
Copy the list of anything that couldn't be fixed and save it for posting here.
Run HiJackthis, create a new log and post it here along with the Trend Micro list. I'll review them and let you know the next step.
NikkJ
94 Posts
0
August 15th, 2005 09:00
If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread.