First off, i must confess to some bad browsing habits which is how i ended up with this problem i am sure. Here is the problem My computer is sending viagara/cialis spam to addresses not in my addres book. The only way i know this is because my norton e-mail/antivirus software/whateverit does informs me when the delivery is rejected (coz it is spam of course) by other servers. I have run ad-aware/spybot/cc cleaner and hijack this thpugh i must say i am not competent enough with directories to properly analyze my hijack this log files. Any suggestions?
Well post the hijackthis log (if thats allowed im a "newbie" so I am not sure, I dont know how much I can gleam from it but its a start. I clean machines with spyware on a regular basis, the first thing I recommend doing is downloading a program called Security Task Manager (download link) The program will analyze all running processes and all dll's associated with it and do a threat assessment on them. Usually the spyware goes to the top (somewhere in the top 10) and you can then quarantine it out of the system. Use common sense when deciding if "high security threats" are actually viruses.. usually they will come in the flavor executables and dll's with random filenames .. Tgtasf.dll or GOOOOGGG.exe or something like that. Look at other properties of the files like the date created (was it close to the time you got the virus), the creator (if its microsoft your probably safe) ... is it a hidden file (usually viruses are designated as hidden and system files so it makes them harder to find and delete) Many time the viruses are unable to be deleted out of memory because they are associated with a core process of windows. In this case you'll have to use a linux live cd that can access ntfs filesystems but we can cross that bridge when we come to it.
Ran it and everything seems legit in terms of it all has recognized publishers or is part of software that makes sense. There is only one dll file and it is a symantec one. Upon further thought, i think what ever i have basically creates a connection when i am online and uses me as a proxy and sends stuff using my bandwith as final delivery and my e-mail(maybe) as final sender. does that help coz i think that measn that it isnt spyware coz it isnt their to spy? Also, it takes several minutes for it to start working after i go on line and it is not an issue if i am offline.
It looks like you have a CWS (Cool Web Search) infection. I am going to point you to CWS Shredder. Run that then repost your hijackthis log.
Also in HijackThis, check the following entries and then select fix. These should be removed.... O4 - HKLM\..\Run: [mstsdsc.exe] c:\windows\system32\mstsdsc.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll The two following entries are not malicious but serve no purpose so may as well get rid of them.... O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
Thanks for that here is logfile. I could not get rid of the .dll file. I think you have to get them in safe mode because they start up at start up and you cannot delete a file while it is being used. I have not dealt with the other tow peripheral issues you mentioned yet. LSPFix is a wonderful tool, but in the off chance it doesn't work, post back asap and I'll post a link to a tool I believe may help. But heres hoping LSPFix does the job
Thanks guys. That deletion of the .dll file seems to have solved the problem. thank you for your time and assistence.