Home Forums Gamescan Chat42 About
* Login   * Register * FAQ    * Search
It is currently Tue 10-07-2025 4:14PM

All times are UTC - 6 hours




Post new topic Reply to topic  [ 7 posts ] 
Author Message
 Post subject: "atiupdate.exe", "ew0.exe"
PostPosted: Wed 12-22-2004 2:40PM 
Offline
Major General

Joined: Sat 03-09-2002 12:57PM
Posts: 2026

Source: Off Campus
zonealarm found these programs trying to access the internet, and they are spyware. as far as i know they are part of a program called "srchasst" or some sort of searchassistant. the only problem is, i can't find the executables anywhere. i found a directory called "srchasst" in c:\windows, but i can't delete it right now because it is "in use". and ew0 is still trying to access the internet. i removed all traces of srchasst from the harddrive and registry, but the exe is still somewhere on my harddisk.

if windows finder can't locate this file on my computer anywhere, then how does it exist? and how can i get rid of it?

google offered limited help


Top
 Profile  
    
 Post subject:
PostPosted: Wed 12-22-2004 2:56PM 
Offline
Spaceman Spiff
User avatar

Joined: Thu 05-03-2001 4:00PM
Posts: 906
Location: Kansas City

Source: VPN
I guess its too late to ask if you tried just removing it from ControlPanel->AddRemovePrograms. That works on a surprisingly large number of spyware things. If you remove that crap from the Run key of the registry its unlikely it will run anyways so finding it on your drive seems a bit moot.


Top
 Profile E-mail  
    
 Post subject:
PostPosted: Wed 12-22-2004 3:32PM 
Offline
Major General

Joined: Sat 03-09-2002 12:57PM
Posts: 2026

Source: Off Campus
i did not try that, but now that i looked it isn't listed. when i want to remove spyware i just usually go to my "program files" folder and look for anything suspicious and delete the folder.

one website had a link to "download removal software" all it did was download "spyhunter" or some thing, and then i had to install that. it didn't even find what it claimed it was going to find, and i couldn't remove anything without purchasing the software... i mean come on that is worse than what the spyware people do!

dammit this is starting to piss me off..........

the odd thing is that if i search for "srchasst" or "atiupdate.exe" on google or sarc.com i get hits, but the program trying to run on my computer (ew0.exe) doesn't get any hits on anything i've searched for....


Top
 Profile  
    
 Post subject:
PostPosted: Wed 12-22-2004 4:06PM 
Offline
Major General
User avatar

Joined: Sat 10-18-2003 10:26PM
Posts: 2955
Location: Stone's throw from Garden of the Gods, Colorado Springs

Source: Off Campus
Try these:

Ad-Aware

Spybot S&D

HiJackThis!

McAfee Viruscan

The four in combination, updated and used, will effectively take out anything bad in your system.

_________________
It's still UMR to me, dammit.


Top
 Profile  
    
 Post subject: Re: spyware
PostPosted: Wed 12-22-2004 7:18PM 
Offline
Major

Joined: Wed 08-18-2004 6:51PM
Posts: 246

Source: Off Campus
I can help you out if you want.

Get HijackThis from the previous post or from http://merijn.org/ (the author's website).

Use HJT to make a log (click Scan, then Save Log) and copy and paste it in a reply. I'll let you know which ones to checkmark for execution.

Yes I've done this before for other people. But if you don't trust me(some stuff will appear; like that child porno program you have running at startup), I can provide you with a list of websites' forums to go to for looking over your HJT log.


Top
 Profile  
    
 Post subject:
PostPosted: Wed 12-22-2004 8:39PM 
Offline
Major General

Joined: Sat 03-09-2002 12:57PM
Posts: 2026

Source: Off Campus
what? child porno?

here's the list

Quote:
Logfile of HijackThis v1.99.0
Scan saved at 8:36:41 PM, on 12/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer1.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\SETI@home\SETI@home.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\InterVideo\WinDVR\WinScheduler.exe
C:\Program Files\ZoneAlarm\zapro.exe
C:\Program Files\RemindMe\RemindMe.exE
C:\Documents and Settings\nsrbb5\Start Menu\Programs\Startup\ShareWatch.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\Nhksrv.exe
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\America Online\AIM95\aim.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\nsrbb5\Desktop\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer1.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {A78860C8-EE1A-46DF-A97F-E3E6D433E80B} - C:\WINDOWS\system32\ww67.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\AMERIC~1\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [Resume copy] copyfstq.exe /startup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [m09xf.exe] C:\WINDOWS\System32\m09xf.exe /k
O4 - HKCU\..\Run: [seticlient] C:\Program Files\SETI@home\SETI@home.exe -min
O4 - Startup: RemindMe.lnk = C:\Program Files\RemindMe\RemindMe.exE
O4 - Startup: ShareWatch.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: InterVideo WinScheduler.lnk = C:\Program Files\InterVideo\WinDVR\WinScheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\America Online\AIM95\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_04) - http://bbrd1.cc.umr.edu:8011/webapps/cl ... _1-win.exe
O23 - Service: MATLAB Server - Unknown - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server - Unknown - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



first of all, "Explorer1.exe" is explorer.exe. i have a modified start menu that says "slutbot" (don't ask) so this is not spyware

second, after i looked at the list i removed anything that had to do with "srchasst" and removed it.

after that the only suspicious program i see is this one

<b>O4 - HKLM\..\RunOnce: [m09xf.exe] C:\WINDOWS\System32\m09xf.exe /k</b>

so i "fixed it" with hijackthis and it disappeared. but then when you run the program again two seconds later it reappears. w t f


Top
 Profile  
    
 Post subject:
PostPosted: Thu 12-23-2004 7:39PM 
Offline
Major

Joined: Wed 08-18-2004 6:51PM
Posts: 246

Source: Off Campus
Yes the m09xf.exe needs to go, and
O2 - BHO: (no name) - {A78860C8-EE1A-46DF-A97F-E3E6D433E80B} - C:\WINDOWS\system32\ww67.dll
needs to be removed as well. Its from Adtomi spyware.

Try your best to delete m09xf.exef you can find it.

Also curious as to why in the heck there's Sun Java Console name for msjava.dll, so I'll look into if thats just a fluke or if its spyware too.


And just so the sanity is there: let me know if hijackthis crashed or anything while you were tring to use it, as its sign of something tring to mess with it.


If you haven't yet gotten ahold of spybot: search and destroy or ad-aware, check them out. Be sure to use their update checkers before you actually scan with them.


Top
 Profile  
    
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

All times are UTC - 6 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group