Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Spywarestormer problems
   
BullGuard Antivirus Forum > General Security > Updates and Patches > Spywarestormer problems  
Forum Quick Jump
 
New Topic Post reply to : Spywarestormer problems Printable version of : Spywarestormer problems
[ << Previous Thread | Next Thread >> ]

dickster
New Member


Date Joined Jan 2005
Total Posts : 2
 
   Posted 1-28-2005 3:33 (GMT +1)    Quote: Spywarestormer problemsAlert an admin about: Spywarestormer problems
 Help
I can't get rid of spywarestormer,
Thankyou
Back to Top
 

Andrei M
Forum Moderator




Date Joined Jan 2005
Total Posts : 570
 
   Posted 1-29-2005 7:14 (GMT +1)    Quote: Spywarestormer problemsAlert an admin about: Spywarestormer problems
Hello,

i have installed spywarestormer just to see how it manifests at deinstallation. It did not create any problems, it uninstalled itself successfully. What trouble do you have with the uninstallation process? Does it give any error message?


"the doer alone learneth"
/friedrich nietzsche.

Back to Top
 

dickster
New Member


Date Joined Jan 2005
Total Posts : 2
 
   Posted 1-30-2005 2:12 (GMT +1)    Quote: Spywarestormer problemsAlert an admin about: Spywarestormer problems
Thankyou,
Here is the log.Logfile of HijackThis v1.99.0
Scan saved at 4:00:11 PM, on 1/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\system32\ssoftsrv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: HyperSearchHook - {4369FCC6-A672-499F-B1A7-750082CE4887} - C:\Program Files\Common Files\Hyperbar\HyperbarSS3.dll
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {607C88F9-0276-B0C7-D5C9-40ACB189C367} - C:\DOCUME~1\Owner\APPLIC~1\NEWWMA~1\OnceFace.exe
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
O4 - HKLM\..\Run: [wmagreatdupegpl] C:\Documents and Settings\All Users\Application Data\Jugsisowmagreat\Bolt open.exe
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [win creative] C:\DOCUME~1\Owner\APPLIC~1\BOLDFU~1\List Readme.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1106455185921
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service - Unknown - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Cryptainer service - Unknown - ssoftsrv.exe (file missing)
Back to Top
 

Bianc@
New Member




Date Joined Jan 2005
Total Posts : 25
 
   Posted 1-30-2005 4:01 (GMT +1)    Quote: Spywarestormer problemsAlert an admin about: Spywarestormer problems
 
 
Hi!
 
I checked the Hijack report you have posted.  Please close all your running applications, run HijackThis again and check the boxes for the following entries:
 
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {607C88F9-0276-B0C7-D5C9-40ACB189C367} - C:\DOCUME~1\Owner\APPLIC~1\NEWWMA~1\OnceFace.exe
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
After this please check 'Fix checked'.
 
You can post a new log to see if there is anything else wrong. Also, do you get any error messages when trying to uninstall SpywareStormer?
 
Regards,
 
Bianca Simion
BullGuard Support Team
Back to Top
 

Andrei M
Forum Moderator




Date Joined Jan 2005
Total Posts : 570
 
   Posted 1-30-2005 5:22 (GMT +1)    Quote: Spywarestormer problemsAlert an admin about: Spywarestormer problems
Bianc@,
i would not recommend dickster to fix the first and the last 02 BHO that you recommended, they are related to Microsoft Money, and his system might need them.

also, the 09 you recommended might be useful for dickster, as it is related to the Microsoft java virtual machine.

dickster, i will get back with recommendations for fixing in your hijackthis log.


"the doer alone learneth"
/friedrich nietzsche.

suspect any spyware/adware? download >hijackthis<
and post the log file it creates
also don't forget to test >the free Bullguard trial<

Back to Top
 

Bianc@
New Member




Date Joined Jan 2005
Total Posts : 25
 
   Posted 1-30-2005 8:31 (GMT +1)    Quote: Spywarestormer problemsAlert an admin about: Spywarestormer problems
 
 
 
Sorry Dickster and thank you CristofMarius!  I'm still learning things...rolleyes
Back to Top
 

Andrei M
Forum Moderator




Date Joined Jan 2005
Total Posts : 570
 
   Posted 2-1-2005 6:39 (GMT +1)    Quote: Spywarestormer problemsAlert an admin about: Spywarestormer problems
Hello dickster,

please run HIJACKTHIS again, scan and place a checkmark next to the following items:
1. all of the R1 items.
2. the R3 item.
3. O2 - BHO: (no name) - {607C88F9-0276-B0C7-D5C9-40ACB189C367} - C:\DOCUME~1\Owner\APPLIC~1\NEWWMA~1\OnceFace.exe check this one too
4. the O1 - Hosts: 64.91.255.87 www.dcsresearch.com must also be checked for fixing.
5. O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) check this one too.
6. O4 - HKLM\..\Run: [TkBellExe] = this could be the LOVGATE worm, so you should check it for fixing.
7. O4 - HKLM\..\Run: [New.net Startup] rundll32 this is a MUST fix.
8. O4 - HKLM\..\Run: [AdStatus Service] check this one too, this is adware
9. O4 - Startup: HP Organize.lnk = ? check for fixing
10. O10 - Hijacked Internet access by New.Net for this one, please download and run >SpyBot< also.
11. O23 - Service: Cryptainer service - Unknown - ssoftsrv.exe (file missing) check this too.

now fix everything by pressing the Fix checked button.

please download >ad-aware<, check for updates, and perform a full scan with it, fix everything it finds suspicious.
Then restart your computer, run HIJACKTHIS again and post a new log here.


Regards,
cristofMarius


suspect any spyware/adware? download >hijackthis< and post the log file it creates.
also don't forget to test >the free Bullguard trial<
--------
Cristof Marius Andrei | Bullguard Support Team

Post Edited (cristofMarius) : 2/1/2005 6:03:29 PM GMT

Back to Top
 
New Topic Post reply to : Spywarestormer problems Printable version of : Spywarestormer problems
 
Forum Information
Currently it is Thursday, November 20, 2008 12:18 PM (GMT +1)
There are a total of 63.926 posts in 15.821 threads.
In the last 3 days there were 34 new threads and 153 reply posts. View Active Threads
Who's Online
This forum has 27174 registered members. Please welcome our newest member, anthonymcg.
42 Guest(s), 1 Registered Member(s) are currently online.  Details
black.avanza
5 Latest Threads
Malware.Trace / Trojan.Vundo - PLEASE HELP CAN'T REMOVE!! (2)20-11-2008 11:00:04 (patel121)
What's wrong with my computer? (5)20-11-2008 10:59:30 (Touch)
Google and Yahoo redirect and associated malfunctions (11)20-11-2008 10:58:05 (Touch)
Generic.PWS.WoW.B7078E0 (11)20-11-2008 08:33:19 (Touch)
Performance dive (6)20-11-2008 06:40:36 (Touch)