| Answer» I have followed the directions for Malware Removal. I am enclosing the 3 files that are required. Can any expert please analyze my files and let me know that I can do to make my computer faster. Thanks
 SuperAntispyware log:[/i]
 SUPERAntiSpyware SCAN Log
 http://www.superantispyware.com
 
 Generated 10/09/2008 at 06:22 PM
 
 Application Version : 4.21.1004
 
 Core Rules Database Version : 3593
 Trace Rules Database Version: 1580
 
 Scan type       : Complete Scan
 Total Scan Time : 00:14:19
 
 Memory items scanned      : 713
 Memory threats detected   : 0
 Registry items scanned    : 6855
 Registry threats detected : 0
 File items scanned        : 2411
 File threats detected     : 3
 
 Adware.Tracking Cookie
 C:\Users\Will\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
 C:\Users\Will\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
 C:\Users\Will\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
 
 
 Malwarebytes' Anti-Malware:
 Malwarebytes' Anti-Malware 1.28
 Database version: 1248
 Windows 6.0.6001 Service Pack 1
 
 10/9/2008 6:42:39 PM
 mbam-log-2008-10-09 (18-42-39).txt
 
 Scan type: Quick Scan
 Objects scanned: 50360
 Time elapsed: 6 minute(s), 5 second(s)
 
 Memory Processes Infected: 0
 Memory Modules Infected: 0
 Registry Keys Infected: 0
 Registry Values Infected: 0
 Registry Data Items Infected: 0
 Folders Infected: 0
 Files Infected: 1
 
 Memory Processes Infected:
 (No malicious items detected)
 
 Memory Modules Infected:
 (No malicious items detected)
 
 Registry Keys Infected:
 (No malicious items detected)
 
 Registry Values Infected:
 (No malicious items detected)
 
 Registry Data Items Infected:
 (No malicious items detected)
 
 Folders Infected:
 (No malicious items detected)
 
 Files Infected:
 C:\winlo.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 
 HJT file:
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 6:53:49 PM, on 10/9/2008
 Platform: Windows Vista SP1 (WinNT 6.00.1905)
 MSIE: Internet Explorer v7.00 (7.00.6001.18000)
 Boot mode: Normal
 
 Running processes:
 C:\Windows\system32\taskeng.exe
 C:\Windows\system32\Dwm.exe
 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
 C:\Windows\vVX3000.exe
 C:\Program Files\Windows Sidebar\sidebar.exe
 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
 C:\Program Files\Windows Media Player\wmpnscfg.exe
 C:\Users\Blak\AppData\Roaming\IMVUClient\IMVUClient.exe
 C:\Users\Blak\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe
 C:\Windows\Explorer.EXE
 C:\Windows\system32\SndVol.exe
 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 C:\Program Files\Internet Explorer\ieuser.exe
 C:\Windows\System32\notepad.exe
 C:\Windows\system32\NOTEPAD.EXE
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Windows\system32\SearchFilterHost.exe
 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
 O1 - Hosts: ::1 localhost
 O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
 O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
 O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
 O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
 O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
 O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
 O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
 O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
 O4 - HKLM\..\Run: [lifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
 O4 - HKLM\..\Run: [VX3000] C:\Windows\vVX3000.exe
 O4 - HKLM\..\RunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
 O4 - HKLM\..\RunOnce: [RegisterHPDeviceDetectionDll] regsvr32.exe /s "C:\Program Files\HP\Common\HPDeviceDetection.dll"
 O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
 O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
 O4 - HKCU\..\RunOnce: [Application Restart #0] C:\Program Files\Windows Sidebar\sidebar.exe
 O4 - HKCU\..\RunOnce: [Application Restart #1] C:\Program Files\Windows Sidebar\sidebar.exe
 O4 - HKCU\..\RunOnce: [Application Restart #2] C:\Program Files\Windows Media Player\wmpnscfg.exe
 O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
 O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
 O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
 O4 - HKUS\S-1-5-21-773588428-632993039-27872002-1002\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Blak')
 O4 - HKUS\S-1-5-21-773588428-632993039-27872002-1002\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'Blak')
 O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
 O4 - S-1-5-21-773588428-632993039-27872002-1002 Startup: IMVU.lnk = C:\Users\Blak\AppData\Roaming\IMVUClient\IMVUClient.exe (User 'Blak')
 O4 - S-1-5-21-773588428-632993039-27872002-1002 User Startup: IMVU.lnk = C:\Users\Blak\AppData\Roaming\IMVUClient\IMVUClient.exe (User 'Blak')
 O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
 O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
 O10 - UNKNOWN file in Winsock LSP: c:\windows\system32\wpclsp.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
 O13 - Gopher Prefix:
 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation SUPPORT) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
 O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
 O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
 O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
 O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
 O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
 O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
 O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\system32\rpcnet.exe
 O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
 
 --
 End of file - 9942 bytes
 
 I will be away for about 2 hours and will log back onto site tonight. Thanks in advance for any INPUTS, thoughts, and advice.There isn't a lot to do but maybe trim down a few startups which can be done with Startup Lite.
 
 StartupLite
 
 Thand you very much, evilfantasy. My computer is working like new! Thanks again.Your welcome.Download StartupLite by MalwareBytes to your Desktop.
Doubleclick StartupLite.exe to launch the program.
Ensure the Disable box is checked.
Click Continue.
A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.Re-start your computer.
 
 safe surfing....
 |