Spyware/Trojan?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by goldfish, Jun 5, 2004.

  1. goldfish

    goldfish Lt. Sushi.DC

    Ok, so I go on my parents PC to give it a quick tune-up, and I get "Click YES to install the software" out of the blue. Not even with IE apparently open. So i go through the task manager, end likley looking tasks (obviously IE processes first) and come across which called itself TCPService.exe, which made the box dissapear. Hmm, i thought. So, I suspect this machine has a trojan. So I downloaded The Cleaner and its still scanning as I type.
    Here is an excert from my HijackThis log, and attached is the full log.

    Logfile of HijackThis v1.97.7
    Scan saved at 22:11:47, on 05/06/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE


    They all seem pretty normal to me! I got a few hits on Pestscan.com, but mostly because spybot had immunised against a load of dodgey websites already.. which is what set it off. This machine is fully patched with updates .. antivirus is up to date, as is adaware and spybot, and scanned with all. I'm also still scanning with The Cleaner. I have Panda AV by the way... hopefully to change to avast! after testing it on my machine.

    Hmmmm....

    EDIT : The Cleaner comes up with no hits :/
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Log looks clean to me too GoldFish. I had a similar problem a couple weeks ago on a Win2K PC. Even when not running any browsers at all, I would periodically start getting popups. The PC was on a LAN at work and is always physically connected to the network but I was not doing anything on the PC at all an popups would appear. I tried all the typically adware scanners and ran a full virusscan. I found nothing. So for the heck of it I ran an application like CrapCleaner and removed all the cookies, temp folder contents....etc. The problem went away. I'm still not sure what the problem was but it never came back.
     
  3. goldfish

    goldfish Lt. Sushi.DC

    Hmm, interesting, I ran crap cleaner just now as well.. and I'm going to leave the machine on for a while and see if the problem comes back after a restart and a few hours idle (when i go to sleep).
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! Let us know whether this works for you too.
     
  5. goldfish

    goldfish Lt. Sushi.DC

    Well, the problem seems to have gone away, but I didnt have the chance to test it overnight as my parents turned the machine off :mad: grr.

    But yeah, Ive got Crap Cleaner on there and did a sweep with it. Maybe it was some errant temp file or somthing :/ hmm ...
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds