| Answer» I was on a fan forum for my favorite online game when I clicked on an outside link that supposedly had humour on it. When the site started to load a popup window came up that said something like: Your internet has been running slower than usual install Microsoft Vista Anti-Virus to scan for problems. There were two BUTTONS "OK" and "Cancel". (more or less the message, wish I written it down) I panicked because my father said he got something similar and had (I think) chosen "Cancel" but still ended up with a huge virus that Microsoft had to help him quarantine (but couldn't remove completely). Instead of hitting any of the buttons I touched nothing and powered down my computer completely using the on/off button waited a bit, powered it back on and immediately ran my CCleaner, AVG Free, and Ad-Aware. It found nothing, but worried, I still found your site and followed your instructions down to and including installing and running HijackThis, SuperAntiSpyware, and Malwarebytes. SuperAntiSpyware and Malwarebytes found no problems either but Hijackthis came up with the following log:
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 12:29:47 AM, on 7/12/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Dell Support Center\bin\sprtsvc.exe
 C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
 C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
 C:\PROGRA~1\AVG\AVG8\avgrsx.exe
 C:\PROGRA~1\AVG\AVG8\avgemc.exe
 C:\WINDOWS\system32\RUNDLL32.EXE
 C:\WINDOWS\RTHDCPL.EXE
 C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
 C:\PROGRA~1\AVG\AVG8\avgtray.exe
 C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\AVG\AVG8\avgui.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\Program Files\Opera\opera.exe
 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 C:\Program Files\Trend Micro\HijackThis\sniper.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0080423
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0080423
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0080423
 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
 O2 - BHO: ADOBE PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
 O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
 O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
 O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
 O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
 O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
 O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
 O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
 O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
 O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
 O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
 O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
 O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll
 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
 O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
 O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
 O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
 O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
 
 --
 End of file - 7239 bytes
 
 
 Am I infected with anything? My computer is less than 2 months old and I am worried. I have not been experiencing any symptoms but it has only been about 4 hours since I got the popup window.
 
 If it helps to know, I run Windows XP. My web browser is Opera, but I was previously using Mozilla Firefox. I have never used Internet Explorer on this computer because I heard it is more likely to get viruses than many other browsers.Welcome to CH.
 
 I don't see any malware but there are a few things to fix.
 
 Open Hijackthis and select Do a system scan only.
 
 Place a check mark next to the following entries: (if there)
 
 O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
 O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
 
 Important: Close all windows except for Hijackthis and then click Fix checked.
 
 Exit Hijackthis and run CCleaner.
 
 ----------
 
 Your Java is out of date.
 
 Older versions have vulnerabilities that malicious sites can use to infect your system.
 
 First install the new Sun Java Runtime Environment
 
 Remove the old version(s)
 
 
 .Go to add/remove programs and uninstall all old versions.Be sure not to remove the new version that was just installed.
Download JavaRa and unzip the file to your Desktop.
Open JavaRA.exe and CHOOSE Remove Older Versions
Once complete exit JavaRA and delete the program.Run CCleaner.
 ----------
 
 Use the  Secunia Software Inspector to check for out of date software.
 
 .Click Start Now
Check the box next to Enable thorough system inspection.
Click Start
Allow the scan to finish and scroll down to see if any updates are needed.Update anything listed.
 ----------
 
 Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.
 
 If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.
 
 ----------
 
 Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.
 
 Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.
 
 To prevent unknown applications from being installed on your computer install WinPatrol 2008
 *  Using Winpatrol to protect your computer from malicious software
 
 Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.
 
 SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
 * Using SpywareBlaster to protect your computer from Spyware and Malware
 * If you don't know what ActiveX controls are, see here
 
 Check out  Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.
 
 Also see  Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Done, thank you!! Just as a side note, when I run CCleaner, is it necessary to check any of the subheadings under Advanced (where it says Old Prefetch Date and such)? I clicked them all when I first installed it over a year ago on my old computer and, when I got this computer 2 months ago and installed CCleaner on it, I just did the same and left them clicked. I really don't know whether that is overkill or something I should have even touched. (Oh to the ignorant who click things when they do not know what they do, lol)
 I usually leave the Advanced settings alone just to be on the safe side.Thank you. Your site was recommended by another player on the online game fan forum I use. You all HELPED him with some Malware he'd picked up browsing the internet. I'll have to let him know it worked for me too. I'll have to recommend you to my father as well. Maybe it will save him a call to Microsoft if something happens again.
 
 Now that my worry over my new computer is over, I'm going to bed as it's after 1:30 am here .Glad we could help.
 
 We're much cheaper then MS help is...
 
 Safe surfing.....
 |