some weeks ago my computer was infected by an annoying spyware that i cannot remove. Can anyone help me...the Logfile fo HijackThis is:
Logfile of HijackThis v1.99.1
Scan saved at 20:41:04, on 08.06.2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Programme\Java\jre1.5.0_03\bin\jusched.exe
C:\Programme\Winamp\winampa.exe
C:\Programme\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\WINDOWS\wupdmgr.exe
C:\WINDOWS\osaupd.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\srvany.exe
C:\WINDOWS\system32\resetservice.exe
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\wguserv.exe
C:\PROGRA~1\FRNDSL\FRNDSL.exe
C:\Programme\Winamp\Winamp.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Dokumente und Einstellungen\Mami\Lokale Einstellungen\Temporary Internet Files\Content.IE5\01MRGDEV\HijackThis[1].exe
You currently have Hijackthis in a temp folder. It needs to be moved to it's own folder such as C:\HJT.
The program creates backups that we may need, and don't want them lost as could happen in a Temp folder
Create a folder on the C: drive called C:\HJT. You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Logfile of HijackThis v1.99.1 Scan saved at 22:07:40, on 08.06.2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe C:\Programme\Java\jre1.5.0_03\bin\jusched.exe C:\Programme\Winamp\winampa.exe C:\Programme\QuickTime\qttask.exe C:\WINDOWS\System32\ctfmon.exe C:\Programme\Messenger\msmsgs.exe C:\WINDOWS\wupdmgr.exe C:\WINDOWS\osaupd.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\srvany.exe C:\WINDOWS\system32\resetservice.exe C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe C:\WINDOWS\system32\wguserv.exe C:\PROGRA~1\FRNDSL\FRNDSL.exe C:\Programme\Winamp\Winamp.exe C:\Programme\Internet Explorer\iexplore.exe C:\Programme\Adobe\Acrobat 7.0\Reader\AcroRd32.exe C:\HijackThis\HijackThis.exe
Logfile of HijackThis v1.99.1
Scan saved at 09:40:59, on 09.06.2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Programme\Java\jre1.5.0_03\bin\jusched.exe
C:\Programme\Winamp\winampa.exe
C:\Programme\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\WINDOWS\wupdmgr.exe
C:\WINDOWS\osaupd.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\srvany.exe
C:\WINDOWS\system32\resetservice.exe
C:\WINDOWS\system32\wguserv.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\PROGRA~1\FRNDSL\FRNDSL.exe
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
Follow the directions for
Express Installation under "
Installing SP1a on Your Computer".
IMPORTANT: DO NOT update to Service pack 2. Doing so before your computer is malware free can cause Windows to become unstable. We will update to SP2 when your system is clean.
okay, here is the brand new log file of HJT after updating windows service pack 1. Hope that is enough information because that spyware is really annoying :smileyindifferent:
Logfile of HijackThis v1.99.1
Scan saved at 22:41:18, on 11.06.2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Programme\Java\jre1.5.0_03\bin\jusched.exe
C:\Programme\Winamp\winampa.exe
C:\Programme\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\WINDOWS\wupdmgr.exe
C:\WINDOWS\osaupd.exe
C:\Programme\Yahoo!\Messenger\ymsgr_tray.exe
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\srvany.exe
C:\WINDOWS\system32\resetservice.exe
C:\Programme\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\wguserv.exe
C:\PROGRA~1\FRNDSL\FRNDSL.exe
C:\Programme\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
We will need some additional information before we begin your fix.
Please go
here (Microsoft website) using Internet Explorer (
not Firefox or any other browser as they won't work)
*Click on "Windows Validation Assistant"
*Click on the "Validate Now" button.
*Be patient while the ActiveX loads, do not click on any links.
*Read the instructions on this page while it's loading. You will be prompted to install - click YES.
*Enter your product key then click "continue"
(Product keys are 25-character alphanumeric strings that are formatted in groups of five characters, separated by dashes. If your computer came shipped with Windows pre-loaded, the product key is located on a genuine Microsoft license sticker somewhere on your computer.)
*When it says "Validation Complete" please click "Continue to return to your previous activity"
*Copy what it says and paste it here.
sorry, my windows xp version isn´t registered yet and i can not find the registering key so i couldn´t dowload the ActiveX compilation. I guess that´s it, there isn´t any other way to get rid of this spyware thing?
bamajim
10376 Posts
438
0
Posted June 8th, 2006 18:00
Kaktuuus
You currently have Hijackthis in a temp folder. It needs to be moved to it's own folder such as C:\HJT.
The program creates backups that we may need, and don't want them lost as could happen in a Temp folder
Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C:
then right click and select New then Folder and name it HJT.
Then Re run Hijackthis and post a new log
Thanks
bamajim
Training at Malware Removal University