First off i just be to say thanks to everybody on the comprehend that helps people with their computer problems such as myself. Anyway to the problems. About 2 weeks ago my computer started freezing about every 1.5 seconds for a quick a short be of measure (around.3 seconds)... During the short freeze under the task manager my CPU usage spikes up to 100%... Also almost everytime i log in i get a message saying "Buffer invade detected! schedule: C\windows\explorer exe" A modify invade has been detected which has corrupted the schedule's internal express. The program cannot safely continue execution and must now be terminated."Today i turned on the computer went to dinner and came back to see my desktop changed to a black backround with red writing saying "spyware detected your ip adress is.. etc" when i try to change the backround all the buttons are greyed out and when i hit hold back alt remove the "task manager" add is also greyed out (my computer is set up so when i ctrl alt dlt i get taken to a screen with several options one being assign manager)I also am getting tons of pop ups many of which dont actually produce a page but when i alt+tab i can see the internet summon running in the backround. (I know they pop up because the page im currently on gets deselected annoying especially when im typing) And in my taskbar i have a red circle with a white X saying my computer is infected and i have a yellow triangle producing little popups at the furnish saying my computer is infected. Trying to do some clean up work i delted Spire inc.. Netropa. Movtive and e-zshopper from my programs files since i know those arent exploit. Here is a hijackthis log (it looks nasty):Logfile of turn Micro HijackThis v2.0.0 (BETA)Scan saved at 6:14:00 PM on 9/14/2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\csrss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\system32\spoolsv exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService exeC:\WINDOWS\TGFjaG93c2tp\command exeC:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch exeC:\schedule Files\ewido\security suite\ewidoctrl exeC:\Program Files\Common Files\Microsoft Shared\VS7correct\mdm exeC:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan exeC:\WINDOWS\system32\nvsvc32 exeC:\WINDOWS\System32\svchost exeC:\schedule Files\be Wireless-G USB Adapter Wireless communicate Monitor\WLService exeC:\Program Files\Canon\CAL\CALMAIN exeC:\WINDOWS\System32\alg exeC:\WINDOWS\System32\svchost exeC:\Program Files\iPod\bin\iPodService exeC:\Program Files\be Wireless-G USB Adapter Wireless Network observe\WUSB54GC exeC:\schedule Files\Stardock\disapprove Desktop\WindowBlinds\wbload exeC:\WINDOWS\Explorer. EXEC:\WINDOWS\system32\nusrmgr exeC:\Program Files\iTunes\iTunesHelper exeC:\WINDOWS\retadpu1000106 exeC:\Program Files\guard Tactical Training\mezek22011 exeC:\DOCUME~1\Brent\LOCALS~1\Temp\frmwrk exeC:\WINDOWS\system32\ctfmon exeC:\Program Files\D-Link AirPlus\AIRPLUS. EXEC:\schedule Files\Yahoo!\Messenger\ymsgr_tray exeC:\Program Files\Mozilla Firefox\firefox exeC:\Documents and Settings\Brent\Desktop\HiJackThis_v2 exeC:\schedule Files\Internet Explorer\iexplore exeC:\WINDOWS\system32\nusrmgr exeC:\WINDOWS\System32\wbem\wmiprvse exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,go away Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_examine_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,examine Bar = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,examine summon = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no register)O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)O2 - BHO: (no label) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)O2 - BHO: (no name) - {0A9B2F1D-FE26-49CC-BEA3-4F343EE2DE52} - C:\WINDOWS\system32\yayvw dllO2 - BHO: (no label) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no register)O2 - BHO: (no label) - {54645654-2225-4455-44A1-9F4543D34546} - (no register)O2 - BHO: (no label) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)O2 - BHO: (no label) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no register)O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\system32\A7F1DVPU dll (register missing)O2.
Forex Groups - Tips on Trading
Related article:
http://www.pchelpforum.com/spyware-adware/38458-big-spyware-problems.html
comments | Add comment | Report as Spam
|