This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

SPYWAR

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I recently ran Browser hijack blaster and it tells me that I have SPYWAR on my computer, I've tried looking for it on the net, but can't find anything about it. any suggestions? I hope I am posting correctly. axis
axis999 :D

Welcome to Tom Coyote . Don't know what you have until you run Hijackthis and post the log into this thread.

Hijackthis 1.99.1
Its important that Hijackthis is installed in its own permanent folder for backup purposes.
  • Use the link above or the links in my signature to download HJT 1.99.1 setup to your desktop
  • Double Click on the Setup icon and by defaut it will unzip to C:\Program Files\Hijackthis
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure WordWrap is unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread.
  • Please use the [external image: Posted Image] Button and not the New Topic Button
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Hello,

I have added this from hijack this

axis


thanks


Logfile of HijackThis v1.99.1
Scan saved at 12:16:51 PM, on 10/30/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\CyberScrub AntiVirus\AvpM.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\CyberScrub AntiVirus\AvpM.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\CyberScrub AntiVirus\CAVSch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\gilbert valles\Local Settings\Temp\Temporary Directory 1 for hijackthis_199.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.intergate.com/startpage
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.intergate.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Intergate
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [Kaspersky Anti-Virus Lite] C:\Program Files\CyberScrub AntiVirus\AvpM.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [CyberScrub AutoUpdate] C:\Program Files\CyberScrub AntiVirus\CAVSch.exe s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1098578052176
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138952467463
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4518312A-823D-4743-865B-BE460D9991C3}: Domain = intergate.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{4518312A-823D-4743-865B-BE460D9991C3}: NameServer = 216.139.64.16 216.139.64.17
O17 - HKLM\System\CCS\Services\Tcpip\..\{76C65DC5-3CE7-401A-9FE4-0CBE723A1BC8}: Domain = intergate.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{76C65DC5-3CE7-401A-9FE4-0CBE723A1BC8}: NameServer = 216.139.64.16,216.139.64.17
O17 - HKLM\System\CS2\Services\Tcpip\..\{4518312A-823D-4743-865B-BE460D9991C3}: Domain = intergate.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{4518312A-823D-4743-865B-BE460D9991C3}: NameServer = 216.139.64.16 216.139.64.17
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: IS Service (ISSVC) - Unknown owner - C:\Program Files\Norton Internet Security\ISSVC.exe (file missing)
O23 - Service: KAV Monitor Service (KAVMonitorService) - Kaspersky Labs. - C:\Program Files\CyberScrub AntiVirus\AvpM.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
axis :D

I see no malware or viruses on your computer.

Browser hijack blaster <–What program are you actually referring to??


Your windows operating system is very outdated leaving you open to all sorts of infections. You need to open IE and go to tools> Windows updates and download every critical update thats available. Just don't download and install any driver files.
Okay I think I found it on line 02 under spybot and the third 09 I think you will see SPYWAR when I turn my computer on and run browser hijack blaster it reads new BHO SPYWAR. I don't if deleting this will end spywar on my computer. Yes i need to update. Any feedback will be appreciated. Thanks, Gilbert
Those 02 and 09 entries in HJT are legitimate.

browser hijack blaster <– I have never heard of this program, what program is this???? I am afraid I am not following what you are saying.
Hello,

doing a serach on the net I found

http://www.pcworld.com/downloads/file/fid,…escription.html

There was a name change.

It is suppose to stop web sites from hijacking from changing you home page.

I also did a ip look up at arin.net and found that line the 2, 3, 4 line 017 to be an ISP by the name of trip.net

I don't know if it's an old IP I use to use. So I am trying to look into that.

Question? Should I click "fix" on all entries that have ste "file missing"

Thanks

Gilbert
Gilbert,

This is where those 017 entries are pointing to United States - Texas - Houston - Trip.net

Now, you did not follow my instructions for installing HJT in its own folder, whenever we fix something with HJT, it makes backups, if its not in its own folder, those backups are going to be lost.

Easy to fix.
  • just go to My Computer > YOUR C:\ DRIVE > Program Files and create a new folder and name it Hijackthis .
  • Now scroll to where you have HJT currently, right click on the HJT icon and select CUT .
  • Now open the new folder you just created and right click within that folder and select PASTE .
  • Now HJT should reside in C:\Program Files\Hijackthis\Hijackthis.exe

Now, Spyware Blaster is a great program :thumbup:


No, I would not fix anything in HJT, it all looks fine :thumbup: The only thing you may consider fixing is the 017 entries if you do not use that ISP to log onto the internet, if you do use trip.net and fix those entries, you won't be able to access the internet.

If you need this..

To restore the backups:
  • Open HiJackThis
  • Click on "View the list of Backups"
  • Place a check mark next to everything in that window
  • Click Restore
  • Click Yes
  • Reboot your computer

Why dont you run the free online virus scanner from Panda and save and post the report.
Panda ActiveScan <<
Hello, I emailed my ISP and they tell me it's the same name, so it's okay ran panda, got this: Incident Status Location Dialer:dialer.xd Not disinfected c:\windows\switchagreement.txt Dialer:Dialer.ABR Not disinfected C:\WINDOWS\Downloaded Program Files\start7.inf Potentially unwanted tool:Application/QuickKeylog Not disinfected C:\WINDOWS\system32:dvaa.dll It looks like it's going to get ugly. Oh and when I click on the link from my email from tomcoyote. spyware doctor doesen't won't allow me access. So I have to come in through the website. axis
Lets get rid of these.


Download Pocket Killbox to your desktop, unzip it to a folder that you can find

C:\WINDOWS\Downloaded Program Files\start7.inf
c:\windows\switchagreement.txt
C:\WINDOWS\system32\dvaa.dll


Highlight all the files with the complete path in the quote and press Ctrl C on your keyboard.
  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure ALL Files is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes
The rest of your log looks fine :thumbup:

How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.

System Restore <– Do this first to prevent reinfecting yourself.
TonyKlein CastleCops
Grinler BleepingComputer
Geeks To Go
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI