+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Junior Member
    Join Date
    Jun 2006
    Posts
    3

    Default Suspect Virus or Spyware?

    For some time now I have suspected that I have either a Virus or Trojan in my System.
    Every 20-30 minutes an icon appears briefly (for one second) in my taskbar at the bottom of my screen. The icon is similar to any legit program but with only a white square on the left hand side. When this icon appears my CPU usage peaks at 100% causing my computor to crash if I am using extensive graphics. If I am not, then all that happens is the screen will flash burst for the one second the icon is present. I have spent hundreds of pounds on Adware, Spyware, Virus, and other programs to try to find a solution to my problem. Can anyone help, PLEASE?

    Petejcg

  2. #2
    Senior Member
    Join Date
    May 2005
    Posts
    1,017

    Default Re: Suspect Virus or Spyware?

    Hi,

    ok, can you download "hijackthis" software, (link is in right column on this page, under free tools) and follow these instructions carefully

    Install hijackthis on your pc, but change the install path to C:\hijack rather then the default one,

    Run the program and click on "Do a system scan a save a log file", this will open up your log file in notepad, cut and paste the contents of your log file and post it back to me.

    I wil take a look and see if i can spot any problems.

    thanks

  3. #3
    Junior Member
    Join Date
    Jun 2006
    Posts
    3

    Default Re: Suspect Virus or Spyware?

    Log as requested - thank you



    Logfile of HijackThis v1.99.1
    Scan saved at 20:51:52, on 25/06/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\crypserv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    C:\WINDOWS\system32\ZoneLabs\isafe.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
    C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\peter gaiger\Desktop\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
    O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
    O8 - Extra context menu item: Send To &Bluetooth - blank
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
    O9 - Extra button: Active Whois - {BAB9A4F4-C201-4fcf-A5D3-BA77BC9FBEB2} - C:\Program Files\Active Whois\ieshow.exe
    O9 - Extra 'Tools' menuitem: Active Whois - {BAB9A4F4-C201-4fcf-A5D3-BA77BC9FBEB2} - C:\Program Files\Active Whois\ieshow.exe
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - https://support.gateway.com/support/.../PCPitStop.CAB
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tech...a/LSSupCtl.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1122289843890
    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/pro...anner37300.cab
    O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} (OcarptMain Class) - https://oca.microsoft.com/en/secure/ocarpt.CAB
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...a/SymAData.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{062E52EB-7F67-483F-B2DE-F786C21296DF}: NameServer = 195.92.195.94 195.92.195.95
    O17 - HKLM\System\CS1\Services\Tcpip\..\{062E52EB-7F67-483F-B2DE-F786C21296DF}: NameServer = 195.92.195.94 195.92.195.95
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
    O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

  4. #4
    Senior Member
    Join Date
    May 2005
    Posts
    1,017

    Default Re: Suspect Virus or Spyware?

    Ok, i cant spot anything that would be causing the problem, it all looks pretty clean to me.

    What it does sound like is some process is obviously starting when you boot up and causing you problems.

    Download the trial verion of http://www.neuber.com/taskmanager/taskmanager.html , it monitors your system and tells you what processes are using up your cpu.

    lsee if you can spot which process is using up your cpu, and let me know.

    thanks

  5. #5
    Junior Member
    Join Date
    Jun 2006
    Posts
    3

    Unhappy Re: Suspect Virus or Spyware?

    Thanks, I have downloaded PCBooster so I shall see what program is causing the problem. What I did not tell you is that the log you got was after I shut down all of my start up programs with the exception of Zone Alarm and Spysweeper. Since then I have not had this problem! So it is a process of elimination to find the culprit. Did you want me to reactivate all start up programs and send you another log?

    Sorry to mess you about

    Regards

    Peter Gaiger

  6. #6
    Senior Member
    Join Date
    May 2005
    Posts
    1,017

    Default Re: Suspect Virus or Spyware?

    Hi,

    No thats fine, like i said your log file looks clean, i dont see any obvious problems there.

    It sounds like you are already doing what i was going to suggest as its definatly one of your processes on startup causing the problem.
    The link in my previous post may help you locate the problem quicker then the trial and error process.

    Either way, could you let me know which one it turns out to be, i would be interested to know, and also keep it for future reference

    thanks

  7. #7
    Junior Member
    Join Date
    Dec 2006
    Posts
    6

    Default Re: Suspect Virus or Spyware?

    This registy item looks really bad:

    BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    I can't help but wonder: About Spyware Doctor, Spy Sweeper and PC Pit Stop?

    Are these "free" programs, or the full professional / paid versions?

    Reason: SOME freeware have embedded viruses (albeit hard to prove). Some programs also like to "call home" with your usage statistics.

    You may wish to add/remove any of the above and see if that helps.

    A further OPINION is to use Lavasoft's Adaware instead.

Similar Threads

  1. spyware/hard drive update
    By redh0tdave in forum Spyware, Adware ,Viruses and HijackThis logs
    Replies: 6
    Last Post: 19-05-2008, 09:21 AM
  2. Recommended anit-spyware/anti-virus/anit-malware ect
    By fangabean in forum Spyware, Adware ,Viruses and HijackThis logs
    Replies: 5
    Last Post: 05-05-2008, 03:13 PM
  3. spybot S&D, ad aware and super anti spyware
    By pw29010 in forum Spyware, Adware ,Viruses and HijackThis logs
    Replies: 4
    Last Post: 06-01-2008, 08:08 PM
  4. spyware adds
    By mick in forum Spyware, Adware ,Viruses and HijackThis logs
    Replies: 1
    Last Post: 05-07-2007, 03:18 PM
  5. PC tools spyware doctor
    By pw29010 in forum Spyware, Adware ,Viruses and HijackThis logs
    Replies: 2
    Last Post: 27-04-2007, 11:48 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts