Jump to content

Recommended Posts

Posted

I've got a nasty little app on my computer (came from downloading some "legit" add-ons for flight simulator (for the father-in=law honest!!))

 

Task Manager calls it "conceptual desktop" and the task is called gui.exe.

 

Non of the usual suspects gets rid of it (adAware, Spybot Killer, Panda et al)

 

If you're in google and you type in "mr & mrs smith" for example, google freezes, and this pop-up (well, more of a slide up really" try to sell you loads of Mr & Mrs Smith goods!

 

I'm not looking for a list of spyware apps that I havn't used; what I'm after is someone who's seen it and knows about it.

 

Yes I know I could just delete the gui.exe, but where is the fun in that? I want to nuke it once and for all!!

Posted

Try these:

 

- hijackthis - http://www.merijn.org/files/hijackthis.zip

[http://www.spywareinfo.com/~merijn/downloads.html]

 

Take care with that tho - dont remove anything you dont know is bad or you'll screw up IE [or more]

 

- CWShredder - http://www.trendmicro.com/ftp/products/online-tools/cwshredder.exe

[http://www.intermute.com/spysubtract/cwshredder_download.html]

 

Probably wont help but you never know.

 

- Spybot - Search & Destroy - http://www.spybot.info/en/mirrors/index.html

[http://www.spybot.info/en/home/index.html]

 

I dunno if you mean this was spybot killer [but remember some spyware removal programs actually contain spyware and "pretend" to remove stuff so be careful]

 

Also:

Use a program like Autoruns [http://www.sysinternals.com/Utilities/Autoruns.html] to see whats loading on the startup too - it might be something in that.

 

See how that goes and we'll carry on from there :)

 

I kick spyware in the rear most weekends for the past few years and there aint one that's beaten me yet :D :D

 

Cheers

Nath

Posted

It's funny but all the regular spyware apps (and by regular, I mean free) don't pick it up, but the ones that do a scan, then say $34 to remove it, picks it up (along with 122 others, that the freebies don't)

 

I got rid of the offending one in the end manually, but I'd prefer a remover that picked it up, as who knows what else could be lurking!!!

 

BTW what a pain it was too. Still alls quiet, but I know there are still 121 of these beasties on my system!!! :evil:

Posted

It's my opinion, thats there is more than 1 type of spyware. By that, I mean, there is some that slap you in the face evertime you're on t'internet, and then there is the hiding, doing nothing that you can see or feel stuff.

 

Everything Tarquel has suggested I'd done (and more). But I know that there is stuff lurking that I haven't removed.

 

Everything seems fine, but I know it aint!

 

Are you sure you've kicked spyware butt Tarquel, because you just never know!!!!!!!! 8O

Posted

Stewart - it was only a quick post... ;)

 

One time (wont say on who's laptop and no, it wasn't mine lol) I spent about 4 hrs removing spyware from a computer - I had to run the tools mentioned, along with some other ones like MS ASW, and lots of registry editing in every attempt.

 

Needless to say it was for free 'n' all [outside of work but close to home if you get my meaning lol].

 

I must have dealt with around 300 or more PC's in the past few years with some sort of spyware or another and they were all pretty 100% clean after - but i agree, there's no !00% definately way to know theres none left.

 

Any good man [or woman] worth their salt will tell you that presently, you *have* to use multiple known spyware removal tools, autorun/startup detection tools and various manual processes like registry editing and precise deletion of files, etc.. to be able to combat an infected machine, and to definately use multiple anti-spyware programs on your machines at all times.

 

@gecko - they are registry/system repairing and cleaning tools - they dont touch spyware [that I know of] but the latter is a good one for clearing the crap [no pun intended]. I do tend to use Norton Systemworks's WinDoctor [found on Norton Utiilities too i think] which is great for system repair and cleaning up - but thats another topic.

 

From what you said in your first post stewart, it would seem that either there is a background process running that is watching what you are doing, and/or, a BHO (Browser Hijacker) thats plugged in to IE and monitoring what you are typing and giving you results in a popup form.

 

Check for hidden toolbars too in IE.

 

...you should be able to identify what it is with hijackthis - you could always post a log of it here if ya like.

 

Cheers

Nath

Posted

@ tarquel - no no no and definatly NO at the posting logs here, you go to http://www.hijackthis.de

 

you can either copy and paste the log into the space provided on that page or save the log file to your desktop or some where you can find easily and upload the log file by clicking on the browse button on that page and analyse the log file and it will show you what to remove, obviously removing any things that come up as nasty.

 

As for those 2 suggestions I just wanted to add them to the list of things as I dont think they were mentioned.

 

MS's beta anti spyware is pretty good and I know a bunch of other good ones but generally when I get infections and I want to be sure of it getting removed ( and considering I have partitions set up so that my data is on my other partitions and not my system partition ie my C drive ) I just do a clean install and hence I have never really had many issues with trying to get rid of them by using any tools or registry edits etc. Just a case of a re format and re install :)

Posted

Just out of curiousty tarquel, what version of hijackthis is in that download ?

 

I only ask because 1.99 ( as far as I am aware is the latest version which obviously has updates / modifications which have obviously been made to it :)

Posted

One of the biggest problems I have with downloading mutliple anti-spyware platforms onto XPee is that it slows your system down. One of the reasons I switched to Macs at home was that I got fed up having to buy utilities and tools just to keep the system in some kind of stable working state.

 

The same with anti-virus tools too. However, needs must (I still have several Windows machines for testing server etc) so I use the M$ antispyware tool (currently free) and that's it. Of course I don't use windows to surf on and I generally don't use it for ordering stuff on, so it's probably not *as* vulnerable as some are.

 

My advice: buy a mac or use Linux to surf through- much harder to tamper with and more secure by default ("out of the box"). The good news is Vista might go some way towards improving this situation. Here's hoping!

 

Paul

Posted
Yep thats what I have at home. I use Linux on a vintage '97 machine to do my day to day web browsing/email/etc. I also have a WinXP PC for gaming. If that screws up or catches anything nasty I just reimage it because there's no important data on it. :)
Posted

Don't get me wrong Geoff, if I could use a linux box for the "day to day" I would. I have more than enough computers, but not enough room!

 

So I'm stuck with an XP machine that does "everthing" and a couple of laptops (Thank you "teachers for laptops" for 1 of them)

 

But I do a lot of other stuff too (video editing, music editing.. and stuff), but I wouldn't know where to start with linux (I'll have to cancel giving the conference lecture on Linux for this year)

 

That leaves me with a XP pc. At least I know what I'm doing on that!

So spyware is sooo anoying!

Posted

@gecko:

 

Yes Yes YES lol :p

 

Does that automated thing know about additional stuff that may be there due to tools you might not have normally on "home" computers?

 

I'd be doubtful - so its why I suggested he attaches the log. It doesnt do us any harm now does it? lol

 

The latest ver of hijackthis is 1.99.1

 

Cheers

Nath

Posted

If you do the analysis online it creates a url which shows you everything in the log, with nasty things, you save the analysis and you copy and paste the url into the forum, which saves space and is a lot neater. That way you can do it manually and automatic.

 

Give it a go and you will see what I mean ;)

Posted

Further to my post above, this is what the makers say:

 

"[below are the results of the scan]. Be careful what you delete, Hijackthis cannot determine what is bad and what is merely customised by you. The best thing to do is to save a log file and show it to knowledgable folks."

 

Kind of what Tarquel said. I quote:

 

"Does that automated thing know about additional stuff that may be there due to tools you might not have normally on "home" computers?

 

I'd be doubtful - so its why I suggested he attaches the log. It doesnt do us any harm now does it? lol"

 

I agree. And that's what the Hijack software team say- post the log so that people can help you. I hazard a guess there are quite a few people on here who could help.

 

Paul :-)

Posted

Just as an example, I ran hijack and just to show everyone the difference between what I said and what you are saying here it is :

 

The URL ( I was talking about doing , which not only shows you the log in the first place it also gives you a decent idea of what to delete and what not to delete and shows you unsure next to things it isnt sure about and that way you can still do the manual analysis of it !! ) :

 

http://hijackthis.de/logfiles/911778c556e954802b5a542f211d68e9.html

 

Now If I was to post the analysis you would get the following :

 


Logfile of HijackThis v1.99.1
Scan saved at 17:59:12, on 10/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\SBAudigy4\Entertainment Center\RcMan.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\SOMEUS~1\LOCALS~1\Temp\Rar$EX00.562\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://www.google.co.uk/[/url]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.embc.org.uk:80
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [CoolInfoXPMon] C:\PROGRA~1\COOLIN~1\cicmon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RemoteCenter] "C:\Program Files\Creative\SBAudigy4\Entertainment Center\RcMan.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Startup: Diskeeper 9 Professional Edition Registration.lnk = C:\Program Files\Executive Software\Diskeeper\ESIRegister.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [url]http://go.microsoft.com/fwlink/?linkid=39204[/url]
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - [url]http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab[/url]
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE0A09A-ABD8-4E0D-A082-F58AA30012B5}: NameServer = 194.168.8.100,194.168.4.100
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (Omega 1.6693) (Q) (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

 

I figured if you made the analysis and saved it all you would have to post is the url.

 

I was just trying to help out a little bit.

Posted

You could go here and find out:

 

http://www.tomcoyote.org/hjt/

 

You're moaning about nothing- it makes sense to me! You can see running processes (and therefore by implication processes that you perhaps think shouldn't be there) and you also have registry entries in the second section (which by further implication shows the registry entries for applications on your system). Don't think one should be there? Disable it.

 

I'm still finding it hard to understand why you wouldn't think posting the log file on here is that good an idea. In the time it took to discuss it and for you to try and prove your point, the log file could have been posted and discussed.

 

*sigh*

 

Paul

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...