PDA

View Full Version : hijack this. spyware identify



ninhsavestheday
08-27-2004, 12:00 PM
umm i got one of those ***.. underline (link) advertisments for "ntsearch.com

well im using hijack this to detect it to delete, but i dont know which one to remove. anybody got any ideas?

Logfile of HijackThis v1.98.2
Scan saved at 12:56:30 PM, on 8/27/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 9.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\sp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\BitTornado\btdownloadgui.exe
C:\Documents and Settings\Ninh\Desktop\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 9.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Steam] C:\Program Files\Steam\Steam.exe -silent
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll

pk-sd
08-27-2004, 12:56 PM
I mostly use spybot and adaware to detect and eliminate spyware. Try them as they are both freeware. Pretty easy to use also.

SanDiegoReefs
08-27-2004, 01:11 PM
Originally posted by pk-sd
I mostly use spybot and adaware to detect and eliminate spyware. Try them as they are both freeware. Pretty easy to use also.

HijackTHIS detects a lot of BS internetE stuff that Spybot doesn't pickup. i.e. search engine and 404 redirects, blah.

ninh: what do you mean by underline (link) advertisments for "ntsearch.com? An added toolbar/button on your IE window? Or what. I haven't gotten the ntsearch one...

Try removing:
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)


-moore

MrKrispy
08-27-2004, 01:23 PM
try downloading BHO demon, I had to use that to find stuff that kept getting by Spybot and AdAware.

brahm
08-27-2004, 01:27 PM
rofl! WRONG Message board!! There is a message board just for the purpose of people looking at your hi-jack this list! I have the link at home do a search on google groups and you'll find it!

ninhsavestheday
08-27-2004, 01:42 PM
haha im to lazy to register for another forum. i post here because i know theres a lot of computer gurus on this forum..


the spyware im getting is... when i visit a page.. random words in the text are linked.. to this site called "ntsearch.com".. where you can search up the word. its super annoying...

brahm
08-27-2004, 01:54 PM
Originally posted by ninhsavestheday
haha im to lazy to register for another forum. i post here because i know theres a lot of computer gurus on this forum..


the spyware im getting is... when i visit a page.. random words in the text are linked.. to this site called "ntsearch.com".. where you can search up the word. its super annoying...

rofl the other nite, I tried to go through and clean up, with hijack this.. LOL thank god for restore mode! hahaha, I Highly Jacked up my computer! I got it right on the third try though ;)
stupid ads234

ninhsavestheday
08-27-2004, 02:09 PM
lol yeah. sometimes i detechs files that you need!.. errr i think i got rid of it with adware. im not sure..

i dled hijack this, cwshredder, bhodemon, adware, spybot... and scanned like a dozen time

sdwrx
08-27-2004, 02:59 PM
I have found that the new Ad-Aware SE Personal (not 6.0) works very well.

Bickmade
08-27-2004, 03:04 PM
Spyware is so lame. I'm glad Macs dont have them ;)

GAD
08-27-2004, 03:29 PM
macs are ghey:p

brahm
08-27-2004, 03:40 PM
macs, are great.

"Have such good games..warcraft 3, break out, superbreakout, photoshop" - drunkgamers.

GAD
08-27-2004, 03:49 PM
Originally posted by brahm
macs, are great.

"Have such good games..warcraft 3, break out, superbreakout, photoshop" - drunkgamers.

hahahahaha

Bickmade
08-27-2004, 10:05 PM
Originally posted by GAD
macs are ghey:p

but still no spyware!

brahm
08-27-2004, 11:08 PM
Originally posted by Bickmade
but still no spyware!


don't worry, i'll be done writing some in a couple weeks ;)