UNSOLVED

gary routh

updated

22 years ago

GR

gary routh

10 Posts

0

4210

November 2nd, 2004 21:00

AdwareSAHAgent

Can anyone enlighten me on this matter. I ran a scan with Norton 2004 Anti-Virus and it tells me that i have AdwareSAHAgent on my computer and i go to the page to see how to get rid of it and it tells me to delete some registry keys and when i go to the registry editor, it does not have those keys in there, and i also cant find the file anywhere. Is there something i am doing wrong, as i have not been a computer user very long and i am lost. I will post what keys to delete if i need to....thanks...gary
  • Midnight Star

    4791 Posts

    401

    0

    Posted November 2nd, 2004 22:00

    gary routh,

    You might also consider downloading, installing and running these free programs:

    AdAware SE Personal; version 1.05 from [ www.lavasoft.de ].
    Spybot S&D; version 1.3 from [ http://www.safer-networking.org/en/download/ ].

    Maybe they can help 'sniff' some problems out on your system, including the one you mentioned.

    Mike.
  • gary routh

    10 Posts

    401

    0

    Posted November 2nd, 2004 22:00

    Thanks Mike, i failed to mention that i already have Ad-Aware and Spybot, and neither one even detected my problem. I also failed to mention that i have Windows XP if that makes a difference. I appreciate any advice you can spare.........thanks
  • Midnight Star

    4791 Posts

    402

    0

    Posted November 2nd, 2004 23:00

    gary,

    Ok, we need you to post us up a HiJackThis log to review. Download HiJackThis ver 1.98.2, and place it in it's own folder; like "C:\HJT". Run it, click "Scan" then "Save log", next copy/paste the text that comes up and post it back here. Don't try and fix anything just yet; most of what it reports is good.

    You can select a download site from here: http://www.majorgeeks.com/download3155.html

    Mike.
  • gary routh

    10 Posts

    402

    0

    Posted November 3rd, 2004 14:00

    Hi Mike, thanks for the help, but i have 1 question....its on my computer now, but how do i copy and paste it so that it gets onto this site. Sorry that im not all that computer smart, but in time i will learn, i hope. Anything you help me with is very appreciated, believe me....................Gary
  • Midnight Star

    4791 Posts

    402

    0

    Posted November 3rd, 2004 15:00

    Gary,
     
    Question? Fire away...
     

     
    Click on " Reply" for this thread, and when the " Reply to Message" comes back...
     
    From within Notepad:
     
    " Edit | Select All" or CTRL-A
    " Edit | Copy" or CTRL-C
     
    Then right-click within the " Message Body", and select " Paste".
     

     
    It's alwasy a good idea to go back to the top and add any additional information before the log that you think we might need to know when researching your log.
     
    Mike.
     
  • gary routh

    10 Posts

    402

    0

    Posted November 4th, 2004 23:00

    HijackThis v1.98.2
    Scan saved at 8:34:02 AM, on 11/3/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\kdx\KHost.exe
    C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Yahoo!\Messenger\YPager.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Free Download Manager\fdm.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
    R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [Spyware Stormer] C:\Program Files\Spyware Stormer\SpywareStormer.Exe
    O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
    O4 - HKLM\..\Run: [Microsoft Update] vpc32.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] vpc32.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
     
  • Midnight Star

    4791 Posts

    402

    0

    Posted November 5th, 2004 15:00

    gary,

    The problem reported by Norton's; can you give us the full path. Also is the item quarantined?

    Mike.

     

    Message Edited by Midnight Star on 11-05-2004 12:08 PM

  • Midnight Star

    4791 Posts

    402

    0

    Posted November 5th, 2004 16:00

    gary,
     
    This entry: [Microsoft Update] vpc32.exe looks like the AGOBOT.XM worm; also see this article.
     
    Be sure to read the article since it might involve making sure your have NETBUI and NETBIOS over TCP/IP, and file sharing disabled, if your not using it, as well as applying some possible 'hot' fixes and critical updates.
     
    Go to www.trendmicro.com, then click on " Free Online Scan". It'll take a few minutes to download and install. When it's done, select all availabe drives and click " Scan".
    See if that can flush out any problems lurking on your pc.
     
    Mike.
     
  • gary routh

    10 Posts

    402

    0

    Posted November 5th, 2004 19:00

    Thanks Mike for all your help, i will see what happens and hope for the best. I think this computer is going to be the death of me....lol...................................Gary
  • Midnight Star

    4791 Posts

    105

    0

    Posted November 5th, 2004 22:00

    Gary,
     
    Thanks for the vote! Just glad I can help.
     
    Spybot will incorrectly (falsely) report DSO exploits; that's a bug in Spybot. So you can safely ignore them for now.
     
    Mike.