Database of Spyware Project Forum
Welcome, Guest. Please login or register.
August 20, 2008, 07:25:54 am

Login with username, password and session length
Search:     Advanced search
Posting over 7,000 new Spyware, Malware, and Adware infections today!
4675 Posts in 4646 Topics by 14130 Members
Latest Member: ivfujdtnmr
* Home Help Search Login Register
+  Database of Spyware Project Forum
|-+  General Category
| |-+  Spyware Removal Help
| | |-+  Pop ups in System Tray
« previous next »
Pages: [1] Print
Author Topic: Pop ups in System Tray  (Read 1158 times)
fireboy
Newbie
*

Karma: 0
Posts: 12

I fight Spyware!


View Profile
Pop ups in System Tray
« on: June 08, 2006, 04:35:57 pm »

I am getting these pop ups in my system tray that say "you are infected."  If I click on them, it opens a SpywareQuake 2.1 window.  I tried to use Add/Remove programs to delete this, but didn't have any luck.  Any suggestions?
Logged
tschrock
The AntiSpyware King
Administrator
Newbie
*****

Karma: 0
Posts: 39


The King Fights on!


View Profile WWW
Re: Pop ups in System Tray
« Reply #1 on: June 09, 2006, 12:41:39 pm »

Fireboy, please download and install HijackThis and post a log here.  We will look it over and let you know what we see.
Logged

fireboy
Newbie
*

Karma: 0
Posts: 12

I fight Spyware!


View Profile
Re: Pop ups in System Tray
« Reply #2 on: June 09, 2006, 12:45:31 pm »

Logfile of HijackThis v1.99.1
Scan saved at 1:28:21 PM, on 5/27/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\Userinit.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atmclk.exe
C:\WINDOWS\System32\dcomcfg.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cisvc.exe
C:\Documents and Settings\Elizabeth Salsedo\Desktop\Cleaning Comp\October 1\security suite\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Elizabeth Salsedo\Desktop\HijackThis.exe

O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\System32\hp100.tmp
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab
O16 - DPF: {EBC1356E-7D5E-44EC-831D-847882F06FE5} (Gateway Client for MetaFrame) - https://www.waterfordfocus.com/waterford%20...en/CSGProxy.cab
O23 - Service: ewido security suite control - ewido networks - C:\Documents and Settings\Elizabeth Salsedo\Desktop\Cleaning Comp\October 1\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
Logged
tschrock
The AntiSpyware King
Administrator
Newbie
*****

Karma: 0
Posts: 39


The King Fights on!


View Profile WWW
Re: Pop ups in System Tray
« Reply #3 on: June 09, 2006, 12:48:57 pm »

Thanks for the post.  You are definately infected with SpywareQuake.  Please take a look at the removal instructions located at http://www.removespyfalcon.com.

They will have you download a couple tools, but the whole fix takes about 5 minutes.  Its pretty concise.  Let us know how it works!
Logged

fireboy
Newbie
*

Karma: 0
Posts: 12

I fight Spyware!


View Profile
Re: Pop ups in System Tray
« Reply #4 on: June 09, 2006, 12:50:01 pm »

Wow, much better now. Thank You!

Logfile of HijackThis v1.99.1
Scan saved at 7:09:51 PM, on 6/4/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\Userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Documents and Settings\Elizabeth Salsedo\Desktop\HijackThis.exe

O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\System32\hp100.tmp (file missing)
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [a9e26658.exe] C:\WINDOWS\System32\a9e26658.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [a9e26658.exe] C:\Documents and Settings\Elizabeth Salsedo\Local Settings\Application Data\a9e26658.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab
O16 - DPF: {EBC1356E-7D5E-44EC-831D-847882F06FE5} (Gateway Client for MetaFrame) - https://www.waterfordfocus.com/waterford%20...en/CSGProxy.cab
O23 - Service: ewido security suite control - ewido networks - C:\Documents and Settings\Elizabeth Salsedo\Desktop\Cleaning Comp\October 1\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe


-----------------------------------------------------------------------------------------------------------------------------
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 7:09:25 PM, 6/4/2006
+ Report-Checksum: C41510F4

+ Scan result:

No infected objects found.


::Report End
Logged
fireboy
Newbie
*

Karma: 0
Posts: 12

I fight Spyware!


View Profile
Re: Pop ups in System Tray
« Reply #5 on: June 09, 2006, 12:51:00 pm »

I thought maybe I was all set, but...a pop-up has already appeared. It is offering to have "Ultimate Windows Defender" perform a free scan.

Please advise...thanks!
Logged
tschrock
The AntiSpyware King
Administrator
Newbie
*****

Karma: 0
Posts: 39


The King Fights on!


View Profile WWW
Re: Pop ups in System Tray
« Reply #6 on: June 09, 2006, 12:51:49 pm »

Looks like there is still some of Smitfraud present, so lets run the fix again, as follows.

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
If the computer is running, shut down Windows, and then turn off the power.
Wait 30 seconds, and then turn the computer on.
Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
Ensure that the Safe Mode option is selected.
Press Enter. The computer then begins to start in Safe mode.
Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
Quit Internet Explorer and quit any instances of Windows Explorer.
Click Start, click Control Panel, and then double-click Internet Options.
On the General tab, click Delete Files under Temporary Internet Files.
In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
Click on Scanner
Click on Settings
Under How to scan all boxes should be checked
Under Unwanted Software all boxes should be checked
Under What to scan select Scan every file
Click on Ok
Click on Complete System Scan to start the scan process.
Let the program scan the machine.
If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections and put a checkmark in the box next to Create encrypted backup, then choose clean and click Ok.

Once the scan has completed, there will be a button located on the bottom of the screen named Save Report.
Click Save Report button
Save the report to your Desktop
Close Ewido and Reboot in Normal Mode.

Please post:
c:\rapport.txt
Ewido log
A new HijackThis log, into this topic.
Your may need several replies to post the requested logs, otherwise they might get cut off.
Logged

Pages: [1] Print 
« previous next »
Jump to: