PDA

View Full Version : Misc Really good Spyware and Anti virus sodtware!



Brut
05-28-2006, 10:36 PM
Anyone have one? I'm using this XoftSpy 4.22 it get's rid of most things But it can't get rid of this file called command.exe I think. Also I'm using McAfee Virus scan shit and it sucks. I let it run for like 4 hours scanning my computer and it restarted it self. It says it can't remove some of the files either. I want some software that will get rid of this shit! anyone have any?

shortysm22
05-28-2006, 11:27 PM
try spybot, google it

Brut
05-28-2006, 11:30 PM
tryed it and used it..... still didnt help

Sky
05-29-2006, 07:55 AM
is that file a virus? have u tried manually delete it, meaning actually look for the file n delete it?

JennB
05-29-2006, 09:21 AM
I use Adaware and Spybot Search and Destroy

If you really know what you're doing, use Hijack This. If you aren't too sure, get Hijack This, run it, save your log in a worpad file and post it on a computer help forum like the Tech Support Guy Forum and nicely ask for some help with what to delete and they will tell you.

Brut
05-29-2006, 10:30 AM
I heard about Hijak thi. I guess I will have to try to use it. I can't get rid of the system fraud file and the command file thats on my computer. everytime my computer restars it takes longer for everything to start up and some fuckin thing alled freepodstuff keeps isntalling instelf everytime I restart.

Brut
05-29-2006, 10:31 AM
is that file a virus? have u tried manually delete it, meaning actually look for the file n delete it?

it says its in the C driver windows folder/ But then when I look for the weird file its in its not there.. also says when i try to delete some files it says i don't have permission to do that. :2up:

v3rd1g0
05-29-2006, 10:42 AM
restart in safemode and delete the fuck out of it. also google the files and see what comes up. that's how i found out how to get rid of that damn spyfalcon shit XD. good luck

Brut
05-29-2006, 10:50 AM
I did the Hijack this thing and posted my Log onto the Tech Support Guy forums to see if they can help me. Im CanadaFTW on there..... Also i dunno how to restart my computer in safe mode :)

Brut
05-29-2006, 10:51 AM
Logfile of HijackThis v1.99.1
Scan saved at 11:46:26 AM, on 5/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\outlook\outlook.exe
C:\defender23.exe
C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
C:\Program Files\ipwins\ipwins.exe
C:\WINDOWS\T3duZXI\command.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Plaxo\2.5.10.21\PlaxoHelper.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\WNSXS~1\alg.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Weather\Weather.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\ErrorSafe Free\lock.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Owner\Local Settings\Temp\wz5764\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://sidesearch.dropspam.com/sidesearch.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Drop Spam Toolbar - {2DEA8791-C2B7-48E1-8992-8E8E6A6FE789} - C:\Program Files\DropSpam\ewwie.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll
O3 - Toolbar: Drop Spam Toolbar - {2DEA8791-C2B7-48E1-8992-8E8E6A6FE789} - C:\Program Files\DropSpam\ewwie.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [defender] C:\\defender23.exe
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.21\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [Htss] "C:\WINDOWS\WNSXS~1\alg.exe" -vt yazb
O4 - Startup: Weather.lnk = C:\Program Files\Weather\Weather.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {B6E649FA-5461-40d7-AB4D-54FC3C8DB767} - C:\Program Files\DropSpam\ewwie.dll (file missing)
O9 - Extra 'Tools' menuitem: Looksitup Toolbar - {B6E649FA-5461-40d7-AB4D-54FC3C8DB767} - C:\Program Files\DropSpam\ewwie.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.0.84.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1143913477953
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CDA94496-ED6F-4C72-94C8-2C485DC63390} (VCDS Control) - http://vcds-client.nefficient.co.kr/vcds-client/vCDS.CAB
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\T3duZXI\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

JennB
05-29-2006, 11:13 AM
You're on XP so restart and while the screen is still black with text on it, during the startup process, press F8

ct9a gsr
05-29-2006, 11:27 AM
avast! = the best... and its free...

Honestly, the best safeguard from spyware and virii is between the computer and the chair... be smart. =]

Brut
05-29-2006, 03:08 PM
They made me run all these progams and all and do some logs and post on there. For safe mode they made me go to run type in msconfig and go and check run in safe mode and restart the computer and all. Hopefully these guys can get rid of the shit on my computer.

TURTLE
05-29-2006, 09:10 PM
john stop downloading porn wow. did you get your terabite hard drives LOL

TURTLE
05-29-2006, 09:19 PM
for spyware : Ad-Aware-SE-Personal-Edition
http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10045910.html

for anti virus : Nod32
http://www.download.com/NOD32-Standard-Version-Windows-NT-2000-XP-/3000-2239_4-10475647.html?tag=lst-0-1
- i know its a trail but it will get rid of whatever for the time being.

Brut
05-29-2006, 10:10 PM
john stop downloading porn wow. did you get your terabite hard drives LOL

Lol yea anthony that is one solution to it, and no i have gotten a terbyte yet. when i do ima download more porn lol. anyways i got rid of everything the following programs:

hijack this
SystemFraudfix
Killbox
and clean up

thanks to some of you guys and espically the peron with the mini in there sig for telling me to go to that one forum they helped my with everything and i donated money to the site and to the guy that helped me

EDIT: oh and i had 42,491 infected files.. mostly because of fuckin bearshare

ReCkLe5s
05-29-2006, 11:50 PM
avast! = the best... and its free...

Honestly, the best safeguard from spyware and virii is between the computer and the chair... be smart. =]

DID YOU READ THIS!!!!! TAKE THIS COMMENT TO HEART!! i do this for a living avast is the 2nd best anti virus program out, the best but slowest is kapersky or how ever you spell it but run it with spybot ad-aware and a program called x cleaner. they will keep every thing at bay

Stormhammer
05-30-2006, 12:51 AM
google AVG free - good antivirus software

Dark.GEAR
05-30-2006, 03:55 AM
i use Antivir...it works great...and itz free!

p81255
05-30-2006, 12:40 PM
im an A+ certified computer tech.
you need 3 programs
AVG antivirus
ad-aware se pro
cc cleaner