Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Spyware Guard 2008


  • This topic is locked This topic is locked
4 replies to this topic

#1 Smidy

Smidy

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:43 AM

Posted 26 December 2008 - 03:10 PM

I downloaded torrents of various programs a few days ago and recently my computer has been running extremely slowly and a program called Spyware Guard 2008 has appeared on my computer. I've tried to delete this program using the remove/change programs function, uninstall it and remove this program by running Malwarebytes' Anti-Malware program. I'm running this computer on Windows XP and I have no idea how to get rid of this spyware. Any suggestions?





DDS (Version 1.1.0) - NTFSx86
Run by paul at 19:47:51.12 on 26/12/2008
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.124 [GMT 0:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\winscenter.exe
C:\Program Files\Spyware Guard 2008\spywareguard.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\paul\Desktop\dds.scr
C:\Documents and Settings\paul\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.0.0.125\IPSBHO.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [spywareguard] c:\program files\spyware guard 2008\spywareguard.exe
mRunServices: [Windows Service Processor] shdocvw.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: mss.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: ieModule - {7FAF6024-5506-479A-8B27-833AA8DA5EDE} - c:\documents and settings\all users\application data\microsoft\internet explorer\dlls\ieModule.dll
SSODL: InternetConnection - {6ADEAFDE-3739-4E8B-8579-976EE576DDC1} - c:\documents and settings\all users\application data\microsoft\internet explorer\dlls\aaikdrxfjt.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\paul\applic~1\mozilla\firefox\profiles\wadz40cx.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.co.uk
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - HiddenExtension: XUL Cache: {9BEC74A9-A666-49E8-BCAF-304541DDC72F} - c:\documents and settings\paul\local settings\application data\{9BEC74A9-A666-49E8-BCAF-304541DDC72F}

ATTENTION: FIREFOX POLICES IS IN FORCE
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R0 symefa;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1000000.07d\SYMEFA.SYS [2008-12-26 309296]
R1 bhdrvx86;Symantec Heuristics Driver;\??\c:\windows\system32\drivers\nav\1000000.07d\BHDrvx86.sys [2008-12-26 254512]
R1 cchp;Symantec Hash Provider;\??\c:\windows\system32\drivers\nav\1000000.07d\ccHPx86.sys [2008-12-26 362544]
R1 idsxpx86;IDSxpx86;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20080826.006\IDSxpx86.sys [2008-12-26 274808]
R2 norton antivirus;Norton AntiVirus;"c:\program files\norton antivirus\engine\16.0.0.125\ccsvchst.exe" /s "norton antivirus" /m "c:\program files\norton antivirus\engine\16.0.0.125\diMaster.dll" /prefetch:1 []
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-12-26 99376]
R3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys [2008-12-26 38496]
R3 naveng;NAVENG;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\NAVENG.SYS [2008-12-26 89104]
R3 navex15;NAVEX15;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\NAVEX15.SYS [2008-12-26 873552]

=============== Created Last 30 ================

2008-12-26 19:45 1,003,957 a------- c:\windows\sysexplorer.exe
2008-12-26 19:45 134,149 a------- c:\windows\reged.exe
2008-12-26 19:45 51,197 a------- c:\windows\spoolsystem.exe
2008-12-26 19:45 50,620 a------- c:\windows\sys.com
2008-12-26 19:45 47,872 a------- c:\windows\syscert.exe
2008-12-26 19:45 18,941 a------- c:\windows\vmreg.dll
2008-12-26 19:45 <DIR> --d----- c:\program files\Spyware Guard 2008
2008-12-26 18:55 <DIR> --d----- c:\docume~1\paul\applic~1\Malwarebytes
2008-12-26 18:55 15,504 a------- c:\windows\system32\drivers\mbam.sys
2008-12-26 18:55 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-26 18:55 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2008-12-26 18:55 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2008-12-26 15:24 <DIR> --d--r-- c:\program files\Norton Support
2008-12-26 15:22 35,888 a----r-- c:\windows\system32\drivers\SymIM.sys
2008-12-26 15:22 124,464 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2008-12-26 15:22 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2008-12-26 15:22 10,635 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2008-12-26 15:22 806 a------- c:\windows\system32\drivers\SYMEVENT.INF
2008-12-26 15:22 <DIR> --d----- c:\program files\Symantec
2008-12-26 15:22 <DIR> --d----- c:\program files\common files\Symantec Shared
2008-12-26 15:21 <DIR> --d----- c:\windows\system32\drivers\NAV
2008-12-26 15:21 <DIR> --d----- c:\program files\Norton AntiVirus
2008-12-26 15:21 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Norton
2008-12-26 15:18 <DIR> --d----- c:\program files\NortonInstaller
2008-12-26 15:18 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller
2008-12-26 15:01 25,600 a--sh--- c:\windows\system32\mss.dll
2008-12-26 03:33 384,000 a------- c:\windows\system32\winscenter.exe
2008-12-26 03:31 15,000 a------- c:\windows\system32\tyshb36rfjdf.dll
2008-12-26 03:30 <DIR> --d----- c:\docume~1\alluse~1\applic~1\CrucialSoft Ltd
2008-12-26 03:30 163,840 a------- c:\windows\system32\Updater.exe
2008-12-26 03:30 112,364 a------- c:\windows\system32\drivers\48e6fd8.sys
2008-12-26 03:30 29,701 a------- c:\docume~1\alluse~1\applic~1\svhost.exe
2008-12-26 03:30 108,336 a------- c:\windows\system32\mswinsck.ocx
2008-12-26 03:30 81,931 a------- C:\wcal.exe
2008-12-26 03:30 29,701 a------- C:\iuuksh.exe
2008-12-26 03:29 2 a------- C:\2096569539
2008-12-26 03:29 8,192 a------- C:\iqovtd.exe
2008-12-26 03:29 44,032 a------- c:\windows\Qcejalu.dll
2008-12-26 03:29 255 ---shr-- C:\autorun.inf
2008-12-26 03:29 15,000 a------- c:\windows\system32\jkse73hedfdgf.dll
2008-12-26 03:29 44,032 a------- C:\imfhh.exe
2008-12-26 03:22 <DIR> --d----- c:\windows\WinRAR
2008-11-29 19:25 3,727,720 a------- c:\windows\system32\d3dx9_35.dll
2008-11-29 19:25 2,414,360 a------- c:\windows\system32\d3dx9_31.dll
2008-11-29 19:25 <DIR> --d----- c:\program files\Virtools
2008-11-27 18:40 <DIR> --d----- c:\program files\iPod
2008-11-27 18:40 <DIR> --d----- c:\program files\iTunes
2008-11-27 18:40 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-27 15:43 <DIR> --d----- c:\program files\Audacity

==================== Find3M ====================

2008-11-26 16:28 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-11-26 16:28 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-11-10 05:43 410,984 a------- c:\windows\system32\deploytk.dll
2008-10-28 22:36 823,296 a------- c:\windows\system32\divx_xx0c.dll
2008-10-28 22:36 823,296 a------- c:\windows\system32\divx_xx07.dll
2008-10-28 22:35 815,104 a------- c:\windows\system32\divx_xx0a.dll
2008-10-28 22:35 802,816 a------- c:\windows\system32\divx_xx11.dll
2008-10-28 22:35 684,032 a------- c:\windows\system32\DivX.dll
2008-10-23 12:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 a------- c:\windows\system32\wininet.dll
2008-10-16 14:06 268,648 a------- c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 a------- c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 a------- c:\windows\system32\strmdll.dll
2008-02-12 18:59 63,494 ---shr-- c:\windows\system32\shdocvw.exe

============= FINISH: 19:48:29.54 ===============

Attached Files


Edited by Smidy, 26 December 2008 - 03:10 PM.


BC AdBot (Login to Remove)

 


#2 Smidy

Smidy
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:43 AM

Posted 26 December 2008 - 06:21 PM

Bump

#3 Smidy

Smidy
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:43 AM

Posted 27 December 2008 - 12:36 PM

Bumpy bump bump

#4 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:06:43 PM

Posted 05 January 2009 - 02:46 AM

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix.. Please visit HERE if you don't know how.. Please re-enable them back after performing all steps given..

Please download ComboFix by sUBs from one of the locations below, and save it to your Desktop.

Link 1
Link 2
Link 3

Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.

If ComboFix asked you to install Recovery Console, please do so.. It will be your best interest..

When finished, it shall produce a log for you. Post that log and a fresh HijackThis log in your next reply..

Note: DO NOT mouseclick combofix's window while its running. That may cause it to stall

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#5 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:06:43 PM

Posted 12 January 2009 - 02:57 AM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users