Your forum username:
Do you already have an account?
Forgot your password?
  • Log in or Sign up


    Welcome to Sky User - The Unofficial Support Forum for everything Sky! - Proudly helping over 65k members.


    Advertisement

    Results 1 to 6 of 6

    Do i have spyware on my pc??

    This is a discussion on Do i have spyware on my pc?? within the Sky Broadband help forums, part of the Sky Broadband help and support category; Hijackthis log: Logfile of HijackThis v1.99.1 Scan saved at 09:34:56, on 18/08/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet ...

    1. #1
      jdsimp1234's Avatar
      jdsimp1234 is offline Sky User Member
      Exchange: SWBNP - Bridgend .South Wales
      Broadband ISP: Sky Fibre Unlimited Pro
      Router: Sagem F@ST 2504n
      Sky TV: Sky+ HD
      Join Date
      Aug 2007
      Location
      Bridgend South Wales area
      Posts
      795
      Thanks
      5
      Thanked 5 Times in 5 Posts

      Do i have spyware on my pc??

      Hijackthis log:

      Logfile of HijackThis v1.99.1
      Scan saved at 09:34:56, on 18/08/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 SP3 (7.00.6000.16674)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\Program Files\Belkin\F5D7051\WLService.exe
      C:\Program Files\Belkin\F5D7051\WLanCfgG.exe
      C:\Program Files\Kontiki\KService.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\UPHClean\uphclean.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\WINDOWS\Mixer.exe
      C:\WINDOWS\Twain_32\SlimU2\HotKey.exe
      C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
      C:\Program Files\SamsungODD\Magic Speed\MagicSL.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\POP Peeper\POPPeeper.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
      C:\Program Files\Kontiki\KHost.exe
      C:\Program Files\PeerGuardian2\pg2.exe
      C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
      C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      C:\Program Files\Free Download Manager\fdm.exe
      C:\Program Files\Software Informer\softinfo.exe
      C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\KeirNet\K9\K9.exe
      C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
      C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
      C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\HijackThis\imabunny.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
      O2 - BHO: (no name) - {14370F76-7676-44A2-AD11-93A31C5FC9FC} - (no file)
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: (no name) - {8C57CB69-EC1F-4FF3-916F-52151AABC187} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
      O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
      O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\SlimU2\HotKey.exe
      O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
      O4 - HKLM\..\Run: [MagicSpeed] C:\Program Files\SamsungODD\Magic Speed\MagicSL.exe /autorun
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [POP Peeper] "C:\Program Files\POP Peeper\POPPeeper.exe" -min
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
      O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
      O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
      O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
      O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
      O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
      O4 - HKCU\..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe -autorun
      O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
      O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - Startup: Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe
      O4 - Startup: MailWasherPro.lnk = C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
      O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
      O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
      O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
      O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
      O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
      O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - Sky.com - Home (file missing)
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O15 - Trusted Zone: CDcovers.to - cd and dvd covers search
      O15 - Trusted Zone: Download latest movies, games, applications and porn from fast direct downloads | Warez Downloads
      O15 - Trusted Zone: eBay - The UK's Online Marketplace
      O15 - Trusted Zone: Welcome to Facebook! | Facebook
      O15 - Trusted Zone: http://*.filehippo.com
      O15 - Trusted Zone: FrostWire.com - Official Website - Free BitTorrent/Gnutella Client - No subscriptions, Just download and install
      O15 - Trusted Zone: GoMusic.Ru
      O15 - Trusted Zone: Google
      O15 - Trusted Zone: ILoveIM.com Web Messenger
      O15 - Trusted Zone: Sign In
      O15 - Trusted Zone: MegaSearch, the premier cd covers search engine for audio cd covers, pc cd covers and dvd cd covers
      O15 - Trusted Zone: DG834GT
      O15 - Trusted Zone: http://*.mp3mediaworld.com
      O15 - Trusted Zone: News, Sport, Music, Movies, Money, Cars, Shopping and more from the MSN UK
      O15 - Trusted Zone: Plentyoffish.com Free Online Dating Service & Dating Site
      O15 - Trusted Zone: Sky News - First for breaking news - Latest news and video from the UK and around the world.
      O15 - Trusted Zone: Sky Showbiz Home
      O15 - Trusted Zone: Sky.com - Home
      O15 - Trusted Zone: skymovies.com
      O15 - Trusted Zone: Sky Sports | Home | Skysports
      O15 - Trusted Zone: Sky User - Unofficial Help and Support for Sky Broadband and everything Sky!
      O15 - Trusted Zone: Speedtest.net - The Global Broadband Speed Test
      O15 - Trusted Zone: http://axxotorrents2.spruz.net
      O15 - Trusted Zone: Home - WindowsMedia.com Media Guide
      O15 - Trusted IP range: http://192.168.0.1
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab
      O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/tech...bs/tgctlsr.cab
      O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/soft...ch/alaunch.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{7C3BD378-5823-4D10-B44F-47F8E2967668}: NameServer = 208.67.222.222,208.67.220.220
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
      O20 - Winlogon Notify: geBSKaBt - geBSKaBt.dll (file missing)
      O20 - Winlogon Notify: vtUkHxWp - vtUkHxWp.dll (file missing)
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      O23 - Service: Belkin High-Speed Mode Wireless G USB Driver (Belkin High-Speed Mode Wireless G USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\F5D7051\WLService.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
      O23 - Service: DU Meter Service (DUMeterSvc) - Unknown owner - C:\Program Files\DU Meter\DUMeterSvc.exe (file missing)
      O23 - Service: Google Update Service (gupdate1c8e1bb74d2aa1a) (gupdate1c8e1bb74d2aa1a) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe" /svc (file missing)
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
      O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
      O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

      wondering if i have any spyware on my machine?

      explorer.exe keeps crashing & restarting after I close a windows explorer window.


    2. Advertisement
    3. #2
      googleme's Avatar
      googleme is offline Sky User Beta tester
      Exchange:
      Broadband ISP: Connect
      Router: Sagem F@ST 2504
      Sky TV: Sky+ HD
      Join Date
      May 2008
      Posts
      896
      Thanks
      0
      Thanked 0 Times in 0 Posts

      Re: Do i have spyware on my pc??

      By the looks of things you have had some form of virtumode hit your machine at some point and has been partially cleaned.

    4. #3
      jdsimp1234's Avatar
      jdsimp1234 is offline Sky User Member
      Exchange: SWBNP - Bridgend .South Wales
      Broadband ISP: Sky Fibre Unlimited Pro
      Router: Sagem F@ST 2504n
      Sky TV: Sky+ HD
      Join Date
      Aug 2007
      Location
      Bridgend South Wales area
      Posts
      795
      Thanks
      5
      Thanked 5 Times in 5 Posts

      Re: Do i have spyware on my pc??

      whish ones should I get rid of, googleme?

    5. #4
      googleme's Avatar
      googleme is offline Sky User Beta tester
      Exchange:
      Broadband ISP: Connect
      Router: Sagem F@ST 2504
      Sky TV: Sky+ HD
      Join Date
      May 2008
      Posts
      896
      Thanks
      0
      Thanked 0 Times in 0 Posts

      Re: Do i have spyware on my pc??

      Just google virtumonde removeale tool. You should be able to find something. Also just thinking a full blow virtumonde would not let your browse. So could be something else

    6. #5
      x LAGER LOUT x's Avatar
      x LAGER LOUT x is offline Sky User Member
      Exchange: Aldershot:THAD
      Broadband ISP: Max
      Router: Netgear V1 DG834GT
      Sky TV: Sky+ HD
      Join Date
      Sep 2007
      Location
      Aldershot
      Posts
      301
      Thanks
      0
      Thanked 0 Times in 0 Posts

      Re: Do i have spyware on my pc??

      If you haven't already, download and scan with Superantispyware. Probably one of the best available and it's FREE!!!

    7. #6
      Isitme's Avatar
      Isitme is online now Sky User Moderator
      Exchange: Bannockburn
      Broadband ISP: Sky Fibre Unlimited
      Router: Sky Hub SR102
      Sky TV: Sky+ HD
      Join Date
      Dec 2006
      Location
      Central Scotland
      Posts
      34,131
      Thanks
      64
      Thanked 1,641 Times in 1,602 Posts

      Re: Do i have spyware on my pc??

      I endorse the previous cpmment about Superantispyware, at the moment it is the best.

      You could also copy and paste your log into THIS it will analyse it and make recommendations.

      TomD


      Please note the views and recommendations in my posts are my own and in no way reflect the views of SkyUser.


      Useful Utilites

      http://www.nirsoft.net/utils/wifi_information_view.html/ TCPOptimiser /Test Socket

      Note - When downloading always select the Custom install or you will end up with stuff you don't want.





     

     

    Tags for this Thread

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •  
    SkyUser - Copyright © 2006-2017. SatDish and NewsreadeR | SkyUser is in no way affiliated with Sky Broadband / BSkyB
    RIPA NOTICE: NO CONSENT IS GIVEN FOR INTERCEPTION OF PAGE TRANSMISSION