|
FAQ | Members List | Calendar | Today's Posts | Search |
![]() |
Oct 24th, 2004 12:49 PM | |
Ninjavenom |
Holy crap, you have a lot of stuff running. Compare that to this: Code:
Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\System32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\wuauclt.exe C:\Program Files\Soulseek\slsk.exe C:\Program Files\Winamp\winamp.exe C:\Program Files\AIM\aim.exe C:\Program Files\Mozilla Firefox\firefox.exe D:\Torrents\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.suprnova.org/ O2 - BHO: (no name) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O9 - Extra button: AIM (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) The things that stand out to me are the following: Code:
E:\PROGRA~1\Toolbar\TBPSSvc.exe E:\PROGRA~1\Toolbar\TBPS.exe E:\PROGRA~1\Toolbar\PIB.exe E:\PROGRA~1\Yahoo!\browser\ycommon.exe E:\Program Files\Yahoo!\browser\ybrwicon.exe E:\Program Files\Yahoo!\browser\ybrowser.exe Is that yahoo stuff like a browser, or a toolbar accessory? Toolbars are the bane of the web browser's existence. |
Oct 21st, 2004 09:54 PM | |
FartinMowler |
Running processes: E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() E ![]() R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.seekerbar.com/ie.aspx?tb_id=50154 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.red.clientapps.yahoo.com/c.../www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rogers.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ca.red.clientapps.yahoo.com/c.../www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ca.red.clientapps.yahoo.com/c...search/ie.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.red.clientapps.yahoo.com/c.../www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://E ![]() R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.red.clientapps.yahoo.com/c.../www.yahoo.com R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - E ![]() O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E ![]() O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E ![]() O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file) O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - E ![]() O2 - BHO: IYBookmarkHO Class - {8B11A219-80C8-4B42-B558-B8C14D1AA8C4} - E ![]() O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - E ![]() O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - E ![]() O3 - Toolbar: RHSI Toolbar - {4DF5B116-4FD9-4039-B377-1130953A980F} - E ![]() O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - E ![]() O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E ![]() O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E ![]() O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E ![]() O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [ATIPTA] E ![]() O4 - HKLM\..\Run: [NeroCheck] E ![]() O4 - HKLM\..\Run: [TkBellExe] "E ![]() O4 - HKLM\..\Run: [QuickTime Task] "E ![]() O4 - HKLM\..\Run: [WebSavingsFromEbates0] "E ![]() O4 - HKLM\..\Run: [TBPS] E ![]() O4 - HKLM\..\Run: [ccApp] "E ![]() O4 - HKLM\..\Run: [ccRegVfy] "E ![]() O4 - HKLM\..\Run: [Outpost Firewall] E ![]() O4 - HKLM\..\Run: [cdexv] E ![]() O4 - HKCU\..\Run: [RHSI SHS] "E ![]() O4 - HKCU\..\Run: [Update Manager] "E ![]() O4 - HKCU\..\Run: [Yahoo! Pager] E ![]() O4 - HKCU\..\Run: [SpybotSD TeaTimer] E ![]() O4 - HKCU\..\Run: [Mozilla Quick Launch] "E ![]() O4 - HKCU\..\Run: [Morpheus] "E ![]() O4 - Global Startup: Harmony Monitor.lnk = E ![]() O4 - Global Startup: Image Transfer.lnk = E ![]() O4 - Global Startup: WinZip Quick Pick.lnk = E ![]() O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - E ![]() O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - E ![]() O9 - Extra button: Rogers Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - E ![]() O9 - Extra 'Tools' menuitem: Rogers &Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - E ![]() O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E ![]() O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E ![]() O12 - Plugin for .pdf: E ![]() O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - E ![]() O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/c...on=4,3,2,20802 O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - E ![]() |
Oct 21st, 2004 08:10 PM | |
Raize | Look for anything out of the ordinary in your task list. Not just .exe files, but other ones as well. Or get HijackThis, download and run it and post your logs here. |
Oct 18th, 2004 07:04 PM | |
eggyolk |
the daily zing keep em coming! ![]() |
Oct 18th, 2004 04:42 PM | |
Emu | It's not spyware, it's your wife trying to tell you something. |
Oct 18th, 2004 03:59 PM | |
FartinMowler | Yes, again you are most likely correct. It would be nice to figure out which one. |
Oct 18th, 2004 03:49 PM | |
MetalMilitia | Mabey it comes with a program you have installed such as a download accelerator or some such crap. |
Oct 18th, 2004 03:39 PM | |
FartinMowler |
tHE pOp-UP THAT jUST WONT gO away!!!! One stupid viagra pop-up...that I'm possitive that is in my system because I can get rid of everything but this one...I have Ad-aware...Spybot...Spyware blaster and anti-pop up programs ![]() |