Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Is this a spyware/virus issue?  (Read 6361 times)

0 Members and 1 Guest are viewing this topic.

thammondwis

    Topic Starter


    Beginner

    Is this a spyware/virus issue?
    « on: October 25, 2009, 10:50:51 AM »
    Hello,

    I have had an unusual occurance happen on my computer that I'm not sure if I should be concerned about or not.  My wife and I both have accounts on ESPN for fantsy football.  One day a few weeks ago when bringing up the ESPN site, neither my wife's nor my ESPN account was defaulted to, but my daughters name was the "active account".  When looking into the account, her login and password were identical to her WebKin account which she uses on this computer.

    Neither my wife or I setup an account for her on ESPN and I think it is unlikely that she did/could setup an account accidently on ESPN.  Plus occasionally when opening ESPN her account is open.

    So can anyone suggest is this likely something done accidently or due to some type of virus/spyware, or other explantion.  And what if anything should I do about it?

    harry 48



      Egghead

    • lay back , relax and chill out
    • Thanked: 129
      • Yes
      • Yes
      • Yes
      • Dribbling Pensioner
    • Certifications: List
    • Experience: Familiar
    • OS: Windows 7
    Re: Is this a spyware/virus issue?
    « Reply #1 on: October 25, 2009, 12:02:46 PM »
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    go to above and complete , post 3 logs and an expert will look them

    thammondwis

      Topic Starter


      Beginner

      Re: Is this a spyware/virus issue?
      « Reply #2 on: December 02, 2009, 04:45:06 AM »
      Hello,

      It has been a while, but I am following up with the instructions given.  I have had another issue that has occured.  I found a charge from Apple's I Tunes on my checking account that my wife did not purchase.  When investigating, my wife discovered that her password to her I Tunes account did not work.  She has subsequently cancelled the debt card she was using for making purchases on I Tunes and has had her password restored.  Between the time the card was cancelled and the password restored, there was another attempted charge from I Tunes on her account.

      The first step I did was update my AVG virus software to version 9 and ran a system scan which found 2 viruses and a lot of spyware in the my music directory.

      I checked the add or remove programs, and found a few entries that I don't recall installing or not sure what they are.  They are; Banjor, Conexant AC-Link Audio, Galexy Video Poker Special Edition, Old West Video Poker Special Edition, US video Poker Special Edition

      I will continue with the instructions and post addition info as instructed.

      harry 48



        Egghead

      • lay back , relax and chill out
      • Thanked: 129
        • Yes
        • Yes
        • Yes
        • Dribbling Pensioner
      • Certifications: List
      • Experience: Familiar
      • OS: Windows 7
      Re: Is this a spyware/virus issue?
      « Reply #3 on: December 02, 2009, 12:09:42 PM »
      i would remove the 3 poker one's and see what comes out of the logs remove what ever comes up when you get to the end of the 3 runs
      « Last Edit: December 03, 2009, 02:14:22 PM by harry 48 »

      thammondwis

        Topic Starter


        Beginner

        Re: Is this a spyware/virus issue?
        « Reply #4 on: December 02, 2009, 07:58:57 PM »
        OK I ran the SuperAntiSpyware program and then uninstalled the 3 Poker programs.  Below is the log from the scan.

        SUPERAntiSpyware Scan Log
        http://www.superantispyware.com

        Generated 12/02/2009 at 08:38 PM

        Application Version : 4.31.1000

        Core Rules Database Version : 4327
        Trace Rules Database Version: 2182

        Scan type       : Complete Scan
        Total Scan Time : 02:28:35

        Memory items scanned      : 465
        Memory threats detected   : 0
        Registry items scanned    : 7004
        Registry threats detected : 0
        File items scanned        : 102746
        File threats detected     : 33

        Adware.Tracking Cookie
           C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt
           C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt
           C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt
           C:\Documents and Settings\Owner\Cookies\owner@realmedia[1].txt
           C:\Documents and Settings\Owner\Cookies\owner@specificclick[2].txt
           C:\Documents and Settings\Owner\Cookies\owner@apmebf[2].txt
           C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Owner\Cookies\owner@fastclick[2].txt
           C:\Documents and Settings\Owner\Cookies\owner@interclick[2].txt
           C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Owner\Cookies\owner@revsci[1].txt
           C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt
           C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Owner\Cookies\owner@specificmedia[2].txt
           C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt
           C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt
           C:\Documents and Settings\Owner\Cookies\owner@invitemedia[1].txt
           C:\Documents and Settings\Owner\Cookies\owner@revsci[2].txt
           C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
           C:\Documents and Settings\Owner\Cookies\[email protected][9].txt
           C:\Documents and Settings\Owner\Cookies\owner@tacoda[1].txt
           C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
           C:\Documents and Settings\Owner\Cookies\owner@invitemedia[2].txt
           C:\Documents and Settings\Owner\Cookies\owner@statcounter[2].txt
           C:\Documents and Settings\Owner\Cookies\owner@media6degrees[1].txt
           C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt
           C:\Documents and Settings\Owner\Cookies\[email protected][2].txt

        Trojan.Unclassified/Dropper
           C:\BACKUP\DESKTOP\BACKUP\TEMP\ALUP398.EXE

        Trojan.Agent/Gen-HackPatch
           C:\DOWNLOAD\DUP2\SKINS\VISTASKIN\VISTASKIN.EXE

        Adware.CouponBar
           C:\WINDOWS\SYSTEM32\CPNPRT2.CID

        thammondwis

          Topic Starter


          Beginner

          Re: Is this a spyware/virus issue?
          « Reply #5 on: December 02, 2009, 08:18:20 PM »
          Here is the log from the Maleware scan.

          Malwarebytes' Anti-Malware 1.41
          Database version: 3283
          Windows 5.1.2600 Service Pack 3

          12/2/2009 9:15:26 PM
          mbam-log-2009-12-02 (21-15-26).txt

          Scan type: Quick Scan
          Objects scanned: 106796
          Time elapsed: 8 minute(s), 46 second(s)

          Memory Processes Infected: 0
          Memory Modules Infected: 0
          Registry Keys Infected: 2
          Registry Values Infected: 1
          Registry Data Items Infected: 1
          Folders Infected: 0
          Files Infected: 0

          Memory Processes Infected:
          (No malicious items detected)

          Memory Modules Infected:
          (No malicious items detected)

          Registry Keys Infected:
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-

          bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ad7fafb0-16d6-40c3-

          af27-585d6e6453fd} (Trojan.BHO) -> Quarantined and deleted successfully.

          Registry Values Infected:
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\drive (Rogue.AntiVirus1) ->

          Quarantined and deleted successfully.

          Registry Data Items Infected:
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify

          (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

          Folders Infected:
          (No malicious items detected)

          Files Infected:
          (No malicious items detected)

          thammondwis

            Topic Starter


            Beginner

            Re: Is this a spyware/virus issue?
            « Reply #6 on: December 02, 2009, 08:53:25 PM »
            Here is the HJT log.

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 9:51:18 PM, on 12/2/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\AVG\AVG9\avgchsvx.exe
            C:\Program Files\AVG\AVG9\avgrsx.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\AVG\AVG9\avgwdsvc.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\AVG\AVG9\avgcsrvx.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\lxczcoms.exe
            C:\Program Files\Common Files\Motive\McciCMService.exe
            C:\Program Files\AVG\AVG9\avgnsx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Canon\CAL\CALMAIN.exe
            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\Program Files\Digital Media Reader\shwicon2k.exe
            C:\WINDOWS\system32\igfxtray.exe
            C:\WINDOWS\system32\hkcmd.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\PROGRA~1\AVG\AVG9\avgtray.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows Media Player\WMPNSCFG.exe
            C:\Program Files\BigFix\BigFix.exe
            C:\Program Files\Palm\Hotsync.exe
            C:\Program Files\Windows Desktop Search\WindowsSearch.exe
            C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\sniper.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

            http://www.fastdir.com/tsl/index.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

            http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

            http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

            http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

            http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer

            provided by Yahoo!
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =

            *.local
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

            Files\Yahoo!\Companion\Installs\cpn0\yt.dll
            R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} -

            C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
            O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
            O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
            O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
            O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
            O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
            O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
            O1 - Hosts: 217.20.175.74 www.reviews.download.com
            O1 - Hosts: 217.20.175.74 reviews.download.com
            O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
            O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
            O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
            O1 - Hosts: 217.20.175.74 reviews.pcmag.com
            O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
            O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
            O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
            O1 - Hosts: 217.20.175.74 reviews.reevoo.com
            O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
            O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
            O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
            O1 - Hosts: 217.20.175.74 reviews.techradar.com
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program

            Files\Yahoo!\Companion\Installs\cpn0\yt.dll
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program

            Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program

            Files\Windows Desktop Search\dsWebAllow.dll
            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -

            C:\Program Files\AVG\AVG9\avgssie.dll
            O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program

            Files\AVG\AVG9\Toolbar\IEToolbar.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

            files\google\googletoolbar2.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} -

            C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program

            Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

            files\google\googletoolbar2.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

            Files\Yahoo!\Companion\Installs\cpn0\yt.dll
            O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program

            Files\AVG\AVG9\Toolbar\IEToolbar.dll
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [SunKist] C:\Program Files\Digital Media Reader\shwicon2k.exe
            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
            O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
            O4 - HKLM\..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers
            O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device

            Support\bin\AppleSyncNotifier.exe
            O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0

            \Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
            O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti

            -Malware\mbam.exe" /runcleanupscript
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
            O4 - Global Startup: Free WebSite Tools.lnk = ?
            O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe
            O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

            Office\Office\OSA9.EXE
            O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop

            Search\WindowsSearch.exe
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2

            \OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2

            \OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32

            \Shdocvw.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

            Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

            C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

            Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

            C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) -

            http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program

            Files\Yahoo!\Common\Yinsthelper.dll
            O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -

            http://photo.walgreens.com/WalgreensActivia.cab
            O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -

            http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
            O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -

            http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
            O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) -

            http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
            O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) -

            http://web1.shutterfly.com/downloads/Uploader.cab
            O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) -

            http://support.gateway.com/support/serialharvest/gwCID.CAB
            O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} - http://offers.e-

            centives.com/cif/download/bin/actxcab.cab
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program

            Files\AVG\AVG9\avgpp.dll
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile

            Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program

            Files\AVG\AVG9\avgwdsvc.exe
            O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program

            Files\Canon\CAL\CALMAIN.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program

            Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program

            Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -

            C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: lxcz_device -   - C:\WINDOWS\system32\lxczcoms.exe
            O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common

            Files\Motive\McciCMService.exe
            O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New

            Boundary\PrismXL\PRISMXL.SYS
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program

            Files\Spyware Doctor\pctsAuxs.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program

            Files\Spyware Doctor\pctsSvc.exe
            O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common

            Files\SolidWorks Shared\Service\SolidWorksLicensing.exe

            --
            End of file - 11858 bytes

            thammondwis

              Topic Starter


              Beginner

              Re: Is this a spyware/virus issue?
              « Reply #7 on: December 02, 2009, 08:56:55 PM »
              Here are the logs as attachments.

              [Saving space, attachment deleted by admin]

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: Is this a spyware/virus issue?
              « Reply #8 on: December 05, 2009, 12:49:27 PM »
              Hello thammondwis and welcome to Computer Hope Forum. Sorry for the delay. My name is Superdave but you can just call me SD. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

              1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
              2. The fixes are specific to your problem and should only be used for this issue on this machine.
              3. If you don't know or understand something, please don't hesitate to ask.
              4. Please DO NOT run any other tools or scans while I am helping you.
              5. It is important that you reply to this thread. Do not start a new topic.
              6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
              7. Absence of symptoms does not mean that everything is clear.

              The first thing I will need you to do is to go to this link and  I will need the SuperAntiSpyware log.

              Open HijackThis and select Do a system scan only

              Place a check mark next to the following entries: (if there)

              O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
              O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
              O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
              O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
              O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
              O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
              O1 - Hosts: 217.20.175.74 www.reviews.download.com
              O1 - Hosts: 217.20.175.74 reviews.download.com
              O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
              O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
              O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
              O1 - Hosts: 217.20.175.74 reviews.pcmag.com
              O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
              O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
              O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
              O1 - Hosts: 217.20.175.74 reviews.reevoo.com
              O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
              O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
              O1 - Hosts: 217.20.175.74 www.reviews.techradar.com


              O1 - Hosts: 217.20.175.74 reviews.techradar.comO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
              (Description: Intel hotkey applet. Unnecessary. Removing this will free up a small amount of system resources.)

              O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
              (Description: Subscription reminder to unlock unkimited use for SoftThinks CD Creator CD/DVD rewriting software, usually supplied with HP PC's as a pre-installed package. Unnecessary. Removing this will free up a small amount of system resources. )

              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] \"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe\"
              (Description: Adobe reader startup - unnecessarily uses system resources.)

              O4 - HKLM\..\Run: [SunJavaUpdateSched] \"C:\Program Files\Java\jre6\bin\jusched.exe\"
              (Description: Sun Java update scheduler. Checks for updates. Not necessary. Removing this entry will free up a small amount of system resources.)

              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
              (Description: Microsoft Office Startup Assistant. This program loads some Microsoft Office components into memory, even if you're not currently using MS Office. Removing this unnecessary program will free up a considerable amount of system resources. )

              Important: Close all open windows except for HijackThis and then click Fix checked.

              Once completed, exit HijackThis.Download and save AVPFind.bat to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

              AVPFind.bat

              It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt
              Also attach the SAS log

              Windows 8 and Windows 10 dual boot with two SSD's

              thammondwis

                Topic Starter


                Beginner

                Re: Is this a spyware/virus issue?
                « Reply #9 on: December 05, 2009, 11:23:38 PM »
                Hi SD

                Thanks for the help.  I followed the instructions below and attached the logs requested.

                [Saving space, attachment deleted by admin]

                mroilfield



                  Mentor
                • Thanked: 42
                  • Yes
                  • Yes
                • Computer: Specs
                • Experience: Experienced
                • OS: Windows 11
                Re: Is this a spyware/virus issue?
                « Reply #10 on: December 05, 2009, 11:59:13 PM »
                Thammondwis,

                I would never use a debit card for anything online that stores your card info for later purchases. If someone gets your account info they can quickly use all the money in your account and it is harder to get the money replaced from the bank.

                A credit card is the best option as they are not actually taking money out of your account and you can dispute the charges with the credit card company with out actually being out any money. If you are worried about the interest charged on a credit card just keep a record of how much you put on it each month and leave that amount in your bank account and when the statement comes in pay if off.
                You can't fix Stupid!!!

                thammondwis

                  Topic Starter


                  Beginner

                  Re: Is this a spyware/virus issue?
                  « Reply #11 on: December 06, 2009, 07:00:01 AM »
                  Thanks for the tip.  I will do that in the future.  The bank did credit my account and the ITunes account password has been reset.

                  SuperDave

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Thanked: 1020
                  • Certifications: List
                  • Experience: Expert
                  • OS: Windows 10
                  Re: Is this a spyware/virus issue?
                  « Reply #12 on: December 09, 2009, 07:54:07 AM »
                  Hello thammondwis and I'm sorry for the delay. It seems as if everyone's computer is infected.

                  Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

                  link # 1
                  Link # 2

                  Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

                  Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

                  Vista users Right-click combofix.exe and select Run as Administrator and follow the prompts.
                  Double-click combofix.exe and follow the prompts.
                  When finished, ComboFix will produce a log for you.
                  Post the ComboFix log and a new HijackThis log in your next reply.

                  NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

                  Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
                  Windows 8 and Windows 10 dual boot with two SSD's