Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

851.

Solve : logonui.exe in sd memory card.?

Answer»

hello is there anyone here tell me what is logonui.exe? Is it a virus? bcoz when i when i tried to open my sd card the only FILE i see is autorun.inf. but when i right click the sd card it has a used size of 93 mb.. so i go to command prompt to check if the file is only hidden but it show only two file the autorun and logonui.exe.. is anyone there HELP me how to fix this problem..  Thanks in advance..What brand is the SD card? Some SD cards come with a program that is SUPPOSED to be ran when you insert the SD card. If you dont need logonui.exe, deleting it shouldn't hurt anything. Also, a LITTLE bit of space is always used up, even when there are no files on the device.its kingstone 2gb.. is there any hope that i can view the pictures.. and what should i do.So you when you try to put pictures on the card, then you look on the card, the photos dont show up?
Or have you not tried yet? Oh, and do you have an anti virus?i used the card last saturday in a camera, then now i try to transfer the picture from sd card to my computer but all i can see is autorun.inf and  no other file inside it..yes i do have a anti virus on the other computer its mcaffee 8.7i.. but i did not make a scan yet coz i afraid to lose any picture..  have you already meet this kind of error mr.helper?Could you have accidently deleted the pictures from the SD card on camera? Try taking another picture on the camera and see if it shows up on your computer.no i did not DELETE any picture in the camera.. the logonui.exe is use application in sd card.. 93mb used space of my sd card is really the one that catches my attention.. and when i open it i can only see the autorun.inf and it has only okb size..Every drive, even when it has no files on it, uses SOME space. A 500 gigabyte hard drive shows SOME used space, even when no files are on it. And this applies to SD cards too.yah your right.. i tried it to my computer and format one of my partition. after i format it, even though you cant FIND file on it still it has a used space.. maybe its because of the system volume folder and  other protected operating system file that are hidden.. is there any chance that i can recover the lost file.?but i think its to strange for the sd card to have a 93mb used space because i a thumb drive can only have a 4 kb used space, and a hard disk partition is 67.9 mb.. i think there's really something wrong in here..dude thanks for the help.. i already fix my problem.. thanks you for the time.. godbless dude..Don't mention it.  I like helping people. Oh and, by the way, the amount of space that is always used depends on the capacity of the drive.

852.

Solve : Please check out my logs.?

Answer»

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:24:31 PM, on 9/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueSwitchAT&TYahoo\TrueWizard.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SBC SELF Support TOOL.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/activegs.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {5D2CF9D0-113A-476B-986F-288B54571614} - http://www.devalvr.com/instalacion/plugin/devalvrplugin.php
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1201728035968
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

--
End of file - 9106 bytes




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:24:31 PM, on 9/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueSwitchAT&TYahoo\TrueWizard.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/activegs.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {5D2CF9D0-113A-476B-986F-288B54571614} - http://www.devalvr.com/instalacion/plugin/devalvrplugin.php
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1201728035968
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

--
End of file - 9106 bytes


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/10/2009 at 00:52 AM

Application Version : 4.28.1010

Core Rules Database Version : 4024
Trace Rules Database Version: 1964

Scan type       : Complete Scan
Total Scan Time : 01:42:48

Memory items scanned      : 470
Memory threats detected   : 0
Registry items scanned    : 6018
Registry threats detected : 2
File items scanned        : 86052
File threats detected     : 0

Rogue.VirusTrigger
   HKU\S-1-5-21-2725332978-1741403521-1901879823-1003\Software\AnvTrgrsoft

Rogue.WebMediaViewer
   HKU\S-1-5-21-2725332978-1741403521-1901879823-1003\Software\WebMediaViewer

I followed all the steps the process tool asked me too do,btw.Did you run mbam after you ran the process tool?...please post an mbam log, and how is the pc running?Oh sorry thought I posted it. I don't remember if I ran it after  or before. Prolly both but I really can't remember. I have been running scans since Wednesday night when all of a sudden I couldn't access the internet. I was in a tab I am always in...my browser stopped responding. So I then I ended the browser process shut down the comp restarted...no internet...called ISP they said it wasn't them....went fishing around couldn't find any drivers...I was confused...so then I thought & thought and so I went to msconfig turned all start up items and stuff to on and Voila. I have been getting a few pop ups here and there...my browsers (I usually use Opera and FF) have been not responding a lot. Other than it works fine.  Heres the log. (Oh I am in the process of getting a firewall too,thought I had one hmm)

Malwarebytes' Anti-Malware 1.38
Database version: 2307
Windows 5.1.2600 Service Pack 3

6/19/2009 5:34:31 AM
mbam-log-2009-06-19 (05-34-31).txt

Scan type: Quick Scan
Objects scanned: 93605
Time elapsed: 4 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\My Documents\My Music\My Music.url (Trojan.Zlob) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\My Documents\My Videos\My Video.url (Trojan.Zlob) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Run Virus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\accessories\system tools\Run Virus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Online Spyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.
Tina , if you're still having problems try download...

http://majorgeeks.com/Dr.Web_CureIT_d4783.html

Run a scan and let us know how the computer responds.....It said viruses found. But I don't really know how to 'cure' them. Never used this program before.

Wait..I got it..I think.

Ok so apparently it moved some...deleted the incureable.

Is there a log to this u need to see? No , just reboot and see how the computer is running.Looks like I had got the same problem few weeks ago.
No logs, just reboot the computer.My comp has been rebooted.

My browsers seem to still shut down sometimes with a notice sometimes without. I use FF and Opera. Haven't used IE in awhile though.Whats this?

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

Hi there Tina!!

                Malwarebyte 1.41 has just released.Please download it from the below link as you are using an outdated version of it.Update it and run a full scan.Check all drives except your CD/DVD drives.Save its log files to CONVENIENT location such as desktop.

http://www.malwarebytes.org/mbam-download.php

              Now scan your computer again with Hijack This and save its  logfile.Please include both the log files in your next reply.


Regarding your question about fixing the below entry
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

IT IS A LEGITIMATE ENTRY AND SHOULD NOT BE FIXED.It is a  Microsoft Client Service for Netware.Btw,When I rebooted this lat time,my comp changed to Military time. Its the right time just Military time. My comp has never done this before. I find it odd.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:56:23, on 9/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueSwitchAT&TYahoo\TrueWizard.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/activegs.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {5D2CF9D0-113A-476B-986F-288B54571614} - http://www.devalvr.com/instalacion/plugin/devalvrplugin.php
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1201728035968
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 8703 bytes


[attachment deleted by admin]Sorry Tina!!!I apologize for the delay.


Please fix the below entry.

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto

Your hjt and mbam logs appears to be clean.So now we will download  DDS and ROOTREPEAL.This will give me a better view to the files running, those that are hidden, and also those in the registry


1) Now download RootRepeal.rar from the below link and unzip it to your Desktop.

http://ad13.geekstogo.com/RootRepeal.rar (Direct Link)
http://rootrepeal.googlepages.com/

    * Close all programs and temporarily disable your anti-virus, Firewall and 
       any antimalware  real-time protection before performing a scan.Click the below 
       link if wish to  see how to disable your antivirus.

          http://www.techsupportforum.com/sectools/sUBs/dds

    * Double click RootRepeal.exe to start the program
    * Click on the Report tab at the bottom of the program window
    * Click the Scan button
    * In the Select Scan dialog, check:
          Drivers
          Files
          Processes
          SSDT
          Stealth Objects
          Hidden Services
    * Click the OK button
    * In the next dialog, select all drives showing
    * Click OK to start the scan

      The scan can take some time. DO NOT run any other programs while the scan is running
    * When the scan is complete, the Save Report button will become available
    * Click this and save the report to your Desktop as RootRepeal.txt
    * Go to File, then Exit to close the program
    * Post Rootrepeal.txt in your next reply.



2) Download DDS from the below link to your desktop.

http://download.bleepingcomputer.com/sUBs/dds.scr

    * Double click DDS.scr to run it and wait for the scan to finish
    * When finished DDS.txt will OPEN
    * A small while later, a prompt will open. Answer Yes
    * DDS will continue scanning
    * When done, Attach.txt will open

Post DDS.txt and attach Attach.txt


Quote

Btw,When I rebooted this lat time,my comp changed to Military time. Its the right time just Military time. My comp has never done this before. I find it odd.

Tina, I am not getting you.Can you be be more clear regarding the above issue.Also not to forget that you have to include the following logs in next reply.

*DDS.TXT
*ATTACH.TXT
*ROOTREPEAL.TXT
I do not know how to be more clear. I rebooted and my clock on the comp was in Military time ya know 13:01 14:01 15:01 instead of 1;01 2:01 ect ect.

I will get to the scans in a bit and ty for you for everyones help.

Sorry not meaning to be rude here...but like you only have 6 posts on this forum I do not recognize your name and well it doesn't say you are a malware specialist.  Whats up with that?Hello Tina!!


          I am currently seeking my malware removal training from one of the most reputated universities where we are given special training under the guidance of  most talented security professionals.My friend evilfantasy acquainted me with this forum few days ago.

               If you are doubting my instructions, you can ask any of the senior security analyst to double check my post.

Regards
Ankur
853.

Solve : HiJackThis log, something could be wrong here...?

Answer»

No it doesn't..

It SAYS

Quote

Platform: Windows Vista SP2 (WinNT 6.00.1906)

and even on the the first HJT log I POSTED, it says

Quote
Platform: Unknown Windows (WinNT 6.00.1906 SP2)

but WinNT 6.00 is Windows Vista.

I DID have Windows 7 RC INSTALLED inside a VirtualBox, but I uninstalled it a couple of months ago.

See my computer's Basic Information (See attachment):

[attachment DELETED by admin]
854.

Solve : Please help where can i download these softwares??

Answer»

Quote from: hannibal_lecter on August 26, 2009, 06:15:23 AM

i see. Thank you.

 about "file sharing" sites; I'll flesh it out some more  

a File sharing site would be something like fileplanet, rapidshare, etc, where any user can upload (share) files with others.

Filehippo, and many other sites (snapfiles, cnet download, etc) are managed by the editors (that is, moderated)

In many cases they wouldn't need to run a malware scan- they have a LOT of prerequisites- a company site, for example. And of course they look at said site and can recognize software that might be malicious/questionable (scam software company sites are INSTANTLY recognizable with a little practice)

the aforementioned "file sharing" type site (again, fileplanet, rapidshare, etc) may or may not perform scans of uploaded files- but it really doesn't matter- these are anonymous people posting anonymous content, and anonymity is a trait that one should only trust with extreme caution.
Quote from: Karnac on August 26, 2009, 07:17:15 AM
Hannibal,

A word of advice, download WOT (Web of trust), http://www.mywot.com/

This free program will allow you to determine if a website is safe to visit before you do so.
All searches will have an indicator to tell you whether the website is safe.
thank you very much, Karnac, for this really helpful advice! Quote from: Carbon Dudeoxide on August 26, 2009, 07:24:33 AM
If you guys want another opinion, I use Filehippo all the TIME. Perfectly safe. Perfectly legit.
i see that everyone is safe using filehippo. I'm much COMFORTED knowing that it's perfectly safe. Thank you very much for your opinion. Quote from: BC_Programmer on August 26, 2009, 07:31:16 AM
about "file sharing" sites; I'll flesh it out some more  

a File sharing site would be something like fileplanet, rapidshare, etc, where any user can upload (share) files with others.

Filehippo, and many other sites (snapfiles, cnet download, etc) are managed by the editors (that is, moderated)

In many cases they wouldn't need to run a malware scan- they have a LOT of prerequisites- a company site, for example. And of course they look at said site and can recognize software that might be malicious/questionable (scam software company sites are instantly recognizable with a little practice)

the aforementioned "file sharing" type site (again, fileplanet, rapidshare, etc) may or may not perform scans of uploaded files- but it really doesn't matter- these are anonymous people posting anonymous content, and anonymity is a trait that one should only trust with extreme caution.

it's totally helpful  explanation. Thank you very much. Thank you everyone who has replied my questions. Thank you very much for your time and advices. It's totally helpful. And i appreciate it.This >>FileHippo<< is not and has never been a file sharing site. They host only the best of the best freeware (some subscriptions). I even use them as a mirror for the downloads in my Malware Removal Guide

WOT scorecard - http://www.mywot.com/en/scorecard/filehippo.com <- All green.

It's been widely speculated but never actually confirmed that Piriform (CCleaner) also owns FileHippo. Or vice versa.

Just for fun, see the similarities.
Whois, FileHippo http://whois.domaintools.com/filehippo.com
Whois, Piriform http://whois.domaintools.com/piriform.com

But, the rule of thumb when downloading security software (or any for that matter) is to ALWAYS use the software developers website. That is unless you are unsure of what the website is because there are rouge websites set up to look like the official one and you will get ripped off not being VIGILANT. Never go to a site to download anything from an advertisement. I have a bunch of safe software and download websites listed on my blog if you ever need to find a software download. Trusted security tools & resources

When in doubt, these are the cleanest download sites I have found to date. Notice Download.com isn't listed.
http://filehippo.com/
http://www.majorgeeks.com/
http://fileforum.betanews.com/
i downloaded this firefox from filehippo and mcafee site advisior says it safe
and it havent seen any problems with iti use filehippo.com all the time it is a moderated site and have never had a problem with any of the files i have downloaded from that site Quote from: evilfantasy on August 26, 2009, 07:39:09 PM
This >>FileHippo<< is not and has never been a file sharing site. They host only the best of the best freeware (some subscriptions). I even use them as a mirror for the downloads in my Malware Removal Guide

WOT scorecard - http://www.mywot.com/en/scorecard/filehippo.com <- All green.

It's been widely speculated but never actually confirmed that Piriform (CCleaner) also owns FileHippo. Or vice versa.

Just for fun, see the similarities.
Whois, FileHippo http://whois.domaintools.com/filehippo.com
Whois, Piriform http://whois.domaintools.com/piriform.com

But, the rule of thumb when downloading security software (or any for that matter) is to ALWAYS use the software developers website. That is unless you are unsure of what the website is because there are rouge websites set up to look like the official one and you will get ripped off not being vigilant. Never go to a site to download anything from an advertisement. I have a bunch of safe software and download websites listed on my blog if you ever need to find a software download. Trusted security tools & resources

When in doubt, these are the cleanest download sites I have found to date. Notice Download.com isn't listed.
http://filehippo.com/
http://www.majorgeeks.com/
http://fileforum.betanews.com/

thank you so much evilfantasy for taking the time to gave some really helpful advices and the links. It's appreciated. It's comforting that filehippo is safe. You have a great blog. I'd like to download some softwares there for sure. Thanks! Quote from: evilfantasy on August 26, 2009, 07:39:09 PM
This >>FileHippo<< is not and has never been a file sharing site. They host only the best of the best freeware (some subscriptions). I even use them as a mirror for the downloads in my Malware Removal Guide

WOT scorecard - http://www.mywot.com/en/scorecard/filehippo.com <- All green.

It's been widely speculated but never actually confirmed that Piriform (CCleaner) also owns FileHippo. Or vice versa.

Just for fun, see the similarities.
Whois, FileHippo http://whois.domaintools.com/filehippo.com
Whois, Piriform http://whois.domaintools.com/piriform.com

But, the rule of thumb when downloading security software (or any for that matter) is to ALWAYS use the software developers website. That is unless you are unsure of what the website is because there are rouge websites set up to look like the official one and you will get ripped off not being vigilant. Never go to a site to download anything from an advertisement. I have a bunch of safe software and download websites listed on my blog if you ever need to find a software download. Trusted security tools & resources

When in doubt, these are the cleanest download sites I have found to date. Notice Download.com isn't listed.
http://filehippo.com/
http://www.majorgeeks.com/
http://fileforum.betanews.com/

thank you so much evilfantasy for taking the time to gave some really helpful advices and the links. It's appreciated. It's comforting that filehippo is safe. You have a great blog. I'd like to download some softwares there for sure. Thanks! Quote from: smeezekitty on August 27, 2009, 07:03:46 PM
i downloaded this firefox from filehippo and mcafee site advisior says it safe
and it havent seen any problems with it
thank you so much for taking the time to share smeezekitty. Quote from: talontromper on August 27, 2009, 07:55:26 PM
i use filehippo.com all the time it is a moderated site and have never had a problem with any of the files i have downloaded from that site
thank you so much for taking the time to share talontromper. Quote from: talontromper on August 27, 2009, 07:55:26 PM
i use filehippo.com all the time it is a moderated site and have never had a problem with any of the files i have downloaded from that site
I use cnet more most of my downloads besides the more popular programs like itunes firefox vlc java nortan avg i download all these programs at there sight Quote from: 876543219 on September 02, 2009, 10:16:29 PM
I use cnet more most of my downloads besides the more popular programs like itunes firefox vlc java nortan avg i download all these programs at there sight
thanks
855.

Solve : my three logs?

Answer»

here are the three logs. however the hijack log may be incomplete due to "modmain_startscan error #6

hijack log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:15 AM, on 9/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\bejak.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\kequoul.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070416
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Adobe PDF READER Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [gacaryv] C:\WINDOWS\system32\kequoul.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Mxaqokofata] rundll32.exe "C:\WINDOWS\otihoqus.dll",Startup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_9 -reboot 1
O4 - HKUS\S-1-5-21-2853403350-2063308389-319719190-1006\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'QBDataServiceUser17')
O4 - HKUS\S-1-5-18\..\Run: [gacaryv] C:\Documents and Settings\LocalService\Application Data\Microsoft\kequoul.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [gacaryv] C:\Documents and Settings\LocalService\Application Data\Microsoft\kequoul.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Convert link TARGET to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1177417349343
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://chat2.j2.com/Media/VisitorchatEnu/TLIEFlash.CAB
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp.coupons.com/r3302/Nestle/Coupons.cab
O16 - DPF: {D6E0B119-DCF2-4CD6-8DFB-7CFF1B70F7FF} (TeamOn Import Object) - https://bis.na.blackberry.com/html/web/client_tools/TOImport.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2007\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

--
End of file - 13341 bytes

superspywarelog:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/23/2009 at 01:09 AM

Application Version : 4.29.1002

Core Rules Database Version : 4117
Trace Rules Database Version: 2057

Scan type       : Complete Scan
Total Scan Time : 01:30:20

Memory items scanned      : 727
Memory threats detected   : 0
Registry items scanned    : 7315
Registry threats detected : 1
File items scanned        : 108293
File threats detected     : 0

Trojan.Agent/Gen-Waledac
   HKLM\Software\Microsoft\Windows\CurrentVersion\Run#PromoReg [ C:\WINDOWS\Temp\_ex-08.exe ]

Malaware log:
Malwarebytes' Anti-Malware 1.41
Database version: 2849
Windows 5.1.2600 Service Pack 3

9/23/2009 7:20:16 AM
mbam-log-2009-09-23 (07-20-16).txt

Scan type: Quick Scan
Objects scanned: 117677
Time elapsed: 6 minute(s), 47 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
C:\WINDOWS\9129837.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{edf444b4-301d-f4df-64bc-d6c7a06bd6d2} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{edf444b4-301d-f4df-64bc-d6c7a06bd6d2} (Trojan.BHO.H) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ttool (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RList (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification PACKAGES (Trojan.Vundo.H) -> Data: imscear.dll  -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\imscear.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\otihoqus.dll (Trojan.BHO.H) -> Delete on reboot.
C:\Documents and Settings\Laura Hamlett\Start Menu\Programs\Startup\ikowin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cpnprt2.cid (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Laura Hamlett\Application Data\wiaserva.log (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\9129837.exe (Trojan.Agent) -> Quarantined and deleted successfully.


thank you.jimyou have viewpoint in your pc , it's not HARMFUL but should not be there , try below and wait for an expert to look at the logs

Go to Start > Run and copy/paste or type: taskmgr
•Under the Processes tab find the following tasks or processes:
ViewpointService.exe
ViewMgr.exe
•Highlight and click "End Process".
•Exit Task Manager.

Click on Start > Run and type: services.msc
•Press "OK".
•Click the "Extended tab".
•Scroll down the list and find the service called "Viewpoint Manager Service"
•When you find the service, double-click on it.
•In the Properties Window > General Tab that opens, click the "Stop" button.
•From the drop-down menu next to "Startup Type", click on "Disabled".
•Now click "APPLY", then "OK" and close any open windows.

Click on Start > Control Panel > Add/Remove Programs > highlight and remove all references to Viewpoint - i.e. Viewpoint, Viewpoint Manager, Viewpoint Media Player.

Finally, delete the following folders if they still exist:
C:\Program Files\ViewManager\ <-- and delete this folder
C:\Program Files\Viewpoint\ <-- and delete this folder

856.

Solve : My Desktop is blank (no icons no startbar) Please Help!!!!!?

Answer»

i am in safe mode nowif you are using vista this wont work:
try running
RUNDLL32.EXE SHELL32.DLL,Control_RunDLL nusrmgr.cpl,,0
it might work on vista if you use:
RUNDLL32.EXE SHELL32.DLL,Control_RunDLL C:\i386\nusrmgr.cpl,,0i was able to do that and create a new USER logged on and hijackthis opened started and quit just like on the other accountsRan a PROGRAM called Dr. Web Cureit this morning it actually went all the way through with the scan only detected one bad file tho?? anyways after the scan tried to go back and RUN some of the other programs but still same result as before Evilfantasy will have to assist you, it's pretty obvious that something has a hold of your pc that the regular tools can't fix.Evilfantasy can you help me???forum memberdo what?C-Good , GIVE this a try...

http://evilfantasy.wordpress.com/2009/05/06/rescue-cds/
the same thing is happening to me i havnt tryed to run those SCANS but i just reformatted computer and downlaoded 1 thing from Microsoft and then i restarted and when i restarted this problem occured. Should i try to run those scans?

857.

Solve : Here is my malwarebyts ant-malware and hijackthis log files?

Answer»

I would suggest using Malwarebytes' Anti-Malware and SUPERAntiSpyware in addition to McAfee because they have some of the best detection rates.  The only way I can know if you are still infected is if you post some logs here (McAfee and HijackThis).  It's possible that the files being picked up by McAfee are just cookies or something else equally harmless.  If they are still being detected, then feel free to post your logs on here and I will be glad to take a look for you.  It's possible that you are still infected, but hopefully these are just harmless files.I was not sure that all the infections on my computer were gone so I did a scan with bitdefender online scanner and the results were horrible. The scanner seemed to pick out normal files that were infected by the virus or trojan. I have no clue what to do next. Here is the results of the scanner. Here is my hijack log.

[attachment deleted by admin]If it is any consolation, many of those files are actually harmless.  They are still infections, but a large majority of them are backups that are currently dormant.  However, if you use System Restore, they COULD be placed back onto your computer, so please don't use System Restore unless I tell you to.

Okay...first, scan with HijackThis and place checkmarks next to these entries:
O4 - Global Startup: $McRebootA5E6DEAA56$.lnk = C:\WINDOWS\system32\cmd.exe
O23 - Service: Net Login (NetLogin) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

Close all other windows and click on Fix Checked.


Okay...now, do you still have SAS and MBAM on your computer?  If not, go ahead and download them.  You should then enter Safe Mode and scan with each program.  First scan with SAS and then when it is complete, scan with MBAM.  Post both of those logs here when you are done.  They are both very thorough and should be able to get rid of things that BitDefender wasn't able to.  Remember to do this in Safe Mode!


You've been dealing with quite a bad infection and there's no guarantee that this will be 100% cleared up.  I personally think a complete reformat (which will erase everything and set the computer back to factory settings) would be the best solution, but if you want to avoid that, I will stick with you.  I just thought it was something I should mention. Quote from: CBMatt on September 28, 2009, 10:44:50 PM

You've been dealing with quite a bad infection and there's no guarantee that this will be 100% cleared up.  I personally think a complete reformat (which will erase everything and set the computer back to factory settings) would be the best solution, but if you want to avoid that, I will stick with you.  I just thought it was something I should mention.

Cbmatt there is no doubt that I want to FORMAT my computer both the c and d drives but I do not have a windows xp os cd. I really want to buy the xp os but there is no one selling it in stores.You don't have the CD's the came with your computer?  A computer will usually come with System Recovery CD's that you can use to reformat and reinstall Windows without having to buy it in stores.  If you don't have this, you can usually get a replacement from the manufacturer of your computer.  If you contact the company or fill out a form on their site, you can usually get these CD's as long as you pay for shipping (about US$6).  What brand is your computer?


And of course, if you would rather continue trying to fight the infection, you can follow the steps in my previous post. Quote from: CBMatt on September 29, 2009, 04:22:33 PM
You don't have the CD's the came with your computer?  A computer will usually come with System Recovery CD's that you can use to reformat and reinstall Windows without having to buy it in stores.  If you don't have this, you can usually get a replacement from the manufacturer of your computer.  If you contact the company or fill out a form on their site, you can usually get these CD's as long as you pay for shipping (about US$6).  What brand is your computer?


And of course, if you would rather continue trying to fight the infection, you can follow the steps in my previous post.


I have those cd's but I had to call hp up so they would ship them to me. I need to format both the c and d drives because I want to make sure that the computer is not still infected. What good is it to format the c drive and do a system recovery and find out that the d drive which has the operating system is still infected. Youare telling me that the recovery cds ALSO have the operating system on them is that correct. Then I can format the c and d drive and use the system recovery cd's rather than buying windows xp home from online and then use the product key on the side of the computer to register the copy of windows. I am using an hp a810n model computer. Here are my SAS and Malwarevyte log files.


[attachment deleted by admin]Some recovery discs will let you reformat more than one drive at a time.  However, I can't say if your particular discs allow that or not.  If not, then you will have to reformat them separately.  To do that, you would want to remove Drive D, reformat Drive C, remove Drive C, hook up Drive D, and then reformat it.  Basically, you have to go through the reformatting process twice.  A simpler way would be to simply reformat your main hard drive and then hook up the secondary hard drive.  Then when you boot up the computer, go to Administrative Tools in the Control Panel.  Once there, open Computer Management.  On the left side of the new window, near the bottom, click on Disk Management.  From here, you can right-click on your secondary hard drive and select Format.  That will wipe everything off of it.  Once the format is complete, the status should say Healthy.

As for your other question...as long as HP sent you the proper disc that goes along with your model of computer, then it should install Windows XP for you.  According to this page, HP should've sent you the XP Home SP2 51NAheBLU1/3_51 NAheBLA2 Recovery Kit, which will install Windows XP Home Edition for you (it is only SP2, so you will have to download SP3 from Microsoft's site for free).  HP's instructions for system recovery are here:
http://h10025.www1.hp.com/ewfrf/wc/document?lc=en&dlc=en&cc=us&product=443069&os=228&lang=en&docname=bph07145#bph07145_disc

On Step 7, I suggest pressing F to perform the destructive recovery.  I know you said you had tried the destructive recovery and you were still infected, but it either wasn't done correctly or the virus re-entered your computer immediately.  If it's the latter, then it may have come from one of the programs you installed.  Are these all legitimate legal programs?  Or are any of them cracked?  If you have obtained software illegally through P2P clients (Limewire, uTorrent, etc.), then there is a good chance that it is infecting your system as soon as you install it.  If that is not the case, then it may be hopping onto your computer from the secondary hard drive.  If so, then my suggestion of swapping the drives and using the recovery disc on each one would be a good idea.

I hate the thought of you having to go to such measures, but it may be your best solution.  Of course, you are always welcome to try ComboFix again.  If it will successfully run on your computer without any problems like before, then I'm certain it will be able to make a significant dent in the infection.  It's your call...
Quote from: CBMatt on September 22, 2009, 06:30:05 PM
Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click combofix.exe and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
858.

Solve : Computer Conundrum, Please help?

Answer»

So, presently there are two problems on my XP laptop that reinforce eachother so neither can be fixed. I'll present them as they've shown up.

1) First, I'm unable to run setup programs. This has been a problem for a while now, and I don't know why it has happened. It could possibly be spyware or malware, but I honestly haven't a clue. The warning tells me I don't have access to perform the operation, but it's the administrative as well as singular account on the computer, so this makes no sense. I'd check to see what exactly this is, but...

2) As of yesterday, I cannot connect to the internet. It will only go so far as to say that the connection is limited (with the triangular yellow symbol atop the familiar wireless network icon). The same will occur plugging it directly into the router, or even the modem. I know the network is fine because I tested it using my friend's laptop. The only NOTABLE actions I took that could be worth mentioning are upgrading the version of itunes on it and also, and more importantly, changing the startup programs on my computer using ms-config (go to 'run' and type in ms-config). I thought this might have been the root of the problem, but I've tried changing between normal startup, diagnostic, and the previous selective startup I'd been using previously, with various programs selected and unselected.

The problem this creates is that I can't effectively use a scanner to detect or delete whatever could be causing this. Why? Because I was unintelligent ENOUGH to not think to UPGRADE avg until this all started, and while I got as far as upgrading the core software, the virus scanner and malware/spyware scanner functions need to be updated, and require internet access to obtain said update. I, of course, can't do that because the internet won't work.

That said, if anybody out there is familiar with either/both problems, and help would be greatly appreciated. One idea I was thinking of would be to install the newest avg ONTO another person's computer, copy the program files and transfer them onto my computer. I don't know if that will even be useful, so I'll wait for some feedback. Please write soon.1) Download and run an AV at boot time (AVAST or AVIRA will work for you)
2) Download and run  MalwareBytes and/or SuperAntiSpyware
I put all the setup programs on a thumbdrive, but I can't install any of them onto the laptop because I can't connect to the internet on it. How do I get around that?Create a bootable cd for AVAST or AVIRA on a different PC, boot to it on your pc and run the scan.

As for the anti malware programs, can you get into safe mode?I've tried running the programs, and while some mal/adware was found and deleted, the problems still persist. what should I try now? and yes, I can get into safe mode.

859.

Solve : Hidden in BookMarks?

Answer»

Win XP HE SP.3+

A routine Spybot scan came up with:


The cure seems to be to find/delete them in Bookmarks, is there a way to Search bookmarks for the entries, the only suggestion so far is to hover over each bookmark, an onerous job when hundreds of bookmarks are involved.

ThanksYou need to update your bookmarks. The original owner of spywareinfo.com disappeared. The bill wasn't paid and in turn the URL was sold by GoDaddy to the highest bidder and is now an attack site. Let Spybot fix those entries.

The new URL is www.spywareinfoforum.comThank you EvilF.  I already have that info from various web searches but SpyBot will NOT fix the entries.  The latest info I have is from the POSTS by SpybotSandra on the Spybot forum here.. and from tbone here.

AFAIK I have never bookmarked Spywareinfo.com and it seems the only way to remove the entries is manually.  Being lazy all I need is a method of searching F'Fox bookmarks for the relevant entries.

Download Registry Search by Bobbi Flekman
(see the link titled RegSearch Download Link)

* Extract the files from Regsearch.zip into a folder.
* Doubleclick regsearch.exe to start the program.
* Enter Spywareinfo in the top area of the form and then click OK
* Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
* Add the contents of the Notepad file to your next reply.Thanks again.  Here's the result of the Reg Search.

Quote

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0

; Results at 29-09-2009 16:19:11 for strings:
;  'spywareinfo'
; Strings excluded from search:
;  (NONE)
; Search in:
; Registry Keys  Registry VALUES  Registry Data 
; HKEY_LOCAL_MACHINE  HKEY_USERS 


[HKEY_USERS\S-1-5-21-1123561945-1592454029-682003330-1004\Software\Update\Locate32\Dialogs]
"Name/Name"="spywareinfo.com"
"Advanced/ContainData"="spywareinfo"

[HKEY_USERS\S-1-5-21-1123561945-1592454029-682003330-1004\Software\Update\Locate32\Recent Strings]
"Name0"="spywareinfo.com"

; End Of The Log...

There was no opportunity to enter this to the "next reply" as Regsearch went into Not Responding on two runs and had to be aborted on both occasions.

The Reg entries obviously exist, should I delete them using Regedit?

I exported FFox bookmarks and used the Search feature in Edit.com to locate all 7 occurrences of Spywareinfo and manually deleted the entries from bookmarks.  A rerun of Spybot shows all clear.



Yes but just delete the spywareinfo entries on the right side of the window in regedit.

Now empty the recycle BIN, restart the computer and see if Spybot is still finding anything.

Done.   Also ran Reg Search again with the result:
Quote
Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0

; Results at 30-09-2009 12:59:16 for strings:
;  'spywareinfo'
; Strings excluded from search:
;  (None)
; Search in:
; Registry Keys  Registry Values  Registry Data 
; HKEY_LOCAL_MACHINE  HKEY_USERS 


; End Of The Log...

SpyBot found no threats.

Earlier I posted Quote
AFAIK I have never bookmarked Spywareinfo.com
but I must have done at some time.  Sorry about the confusion.

Thank you for your guidance EvilF.

T.C.

Glad you got them removed.
860.

Solve : No virus scans will open and my desktop just shows up as the background picture?

Answer»

I have a big problem, can't run any kind of scans. Even HijackThis, nor can I do it safe mode either. My desk TOP just has the background PICTURE. When I open anything that deals with a virus scanner or such, I get I am not allowed to open this. AVG does open, but won't start a virus scan. The only way I can even run something is going through the task manger. HELP!!

This started after I got home from a camping trip. I went to my daily sites, tried some new one's. But I had the same problem, only I couldn't run jack and I got my computer fixed. I don't know what to do.You're on a support forum where everyone POSTS looking for help. NEXT time a more descriptive title might be useful

Download, burn and run a free boot time AV (Avast, Avira, etc).Does that help more? Where do I find that?Sorry, you apparently have one of those SYSTEMS that shipped without Google.
http://www.google.com/search?hl=en&rlz=1T4GGLL_enUS326US326&q=download+boot+antivirus&aq=0&oq=download+boot+anti&aqi=g1

861.

Solve : how to remove recycler??

Answer»

someone tell me how to remove recycler in pen drives and drives?1. Scan it with your antivirus.

2. Run this.

PANDA USB and AutoRun VACCINE

Insert your flash drive before we begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

Download Panda USB and AutoRun Vaccine and save it to your desktop. - Alternate download link

* Extract (unzip) the file to your desktop and a FOLDER named USBVaccine will be created.
* Open that folder and double-click on USBVaccine.exe to START the program.
* Click Run
* Click the button to Vaccinate computer.
* Insert your USB flash drive.
* When the name of the drive appears in the dialog box, click the button to Vaccinate USB drive(s).
* Exit Panda USB and AutoRun Vaccine when done.

Note: Computer AutoRun Vaccination will prevent any AutoRun file from running, regardless of whether the removable device is infected or not. USB Vaccination disables the autorun file so it cannot be read, modified or replaced by malicious code. The Panda Resarch Blog advises that once USB drives have been vaccinated, they cannot be reversed except with a format. If you do this, be sure to back up your data files first or they will be lost during the FORMATTING process.

3. Update Windows with Windows Update. http://update.microsoft.com

Evil, that Windowsupdate link doesn't work for me.Thanks. Fixed.

862.

Solve : Sniper Log?

Answer» YES you should be GOOD to GO now.

Safe SURFING..
863.

Solve : Windows Antivirus Pro manual removal in safe mode?

Answer»

If you don't plan on buying the full version I would suggest going ahead and uninstalling it then download/install the free version and also a free firewall. No need paying for something that you can get for free...

Avira is the top of the list as far as reliability and performance.

Remember to only install one antivirus!
 
1) Avast! Home Free Edition
2) AVG Free Edition
3) Avira AntiVir Personal

I suggest the free version of Online Armour but these are all good.

Remember only install ONE firewall

1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any Ask.com options if you choose this one)
2) Online Armor
3) Sunbelt/Kerio
4) Agnitum
5) PC Tools Firewall Plus

OK well I have time left on a subscription to McAfee Security Centre but it got screwed up with the virus and I decided to use AVG in meantime since I couldn't find the offline installation download on their website at the time.  Anyhow, I'll have another go with the McAfee site or failing that, try your suggestions.  THANK you.

Regards,

GraddfonRun this and then you should be able to reinstall McAfee.

Download the McAfee Consumer Product Removal Tool to your Desktop.
Using McAfee Consumer Product Removal tool:

  • Double click the MCPR.exe
  • A Command Line window will be displayed, and then close automatically.
  • Wait for a second Command Line window to be displayed.
    • Note: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear.
  • After the second window appears, the program will begin the cleanup.
  • Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n]
  • Press Y on the keyboard.
  • Wait for the computer to restart.
  • All McAfee products are now removed from your computer.
OK thanks for that, I've done that. Still can't seem to find an offline install version of McAfee so will try the products you've suggested now. Thanks again.

Regards,
 garddfonAre you on dial-up?Hi evilfantasy,

OK I've successfully installed Avira and Online Armor and have now run the KASPERSKY Scan.  Results pasted below.

No I'm not dial-up, but didn't want to connect until sure that Firewall and Antivirus functioning properly.

Thanks,

Garddfon
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
 Wednesday, September 23, 2009
 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
 Kaspersky Online Scanner version: 7.0.26.13
 Last database update: Wednesday, September 23, 2009 13:25:40
 Records in database: 2871703
--------------------------------------------------------------------------------

Scan settings:
   scan using the following database: extended
   Scan archives: yes
   Scan e-mail databases: yes

Scan area - My Computer:
   C:\
   D:\
   E:\

Scan statistics:
   Objects scanned: 92651
   Threats found: 1
   Infected objects found: 1
   Suspicious objects found: 0
   Scan duration: 02:12:07


File name / Threat / Threats count
C:\Documents and Settings\simonp\Local Settings\Application Data\Identities\{31391EF3-B3AC-4F12-94D8-DC2DA45E9526}\Microsoft\Outlook Express\Inbox.dbx   Infected: Trojan.Win32.Agent2.bl   1

Selected area has been scanned.
How is the computer running now?
Hi again,

No obvious signs of anything DODGY thankfully. Any thoughts on the 1 infected item from the Kaspersky scan?

Regards,

GarddfonI'm thinking it's a false positive but I'm not sure. It's an email in your Outlook Inbox. Check it to see if there is any spam there and delete it.

Final suggestions.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you SAFE from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop CERTAIN cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
864.

Solve : Virus is too big to be removed! HELP?

Answer»

I got the virus - "System Security".  I ran my AVG Internet Security and it shows 2 files infected.  however, when I TELL it to remove them it says, "Moved object is bigger than the archive size limit."  So now what do I do? Hmmm. A nasty trick. Increase the size of your archive, MOVE it there, then remove them. In the Virus Vault SECTION of Advanced AVG Settings, EITHER change the percentage of disk space used for the virus vault, or uncheck "limit virus vault size".

865.

Solve : my logs, please take a peek?

Answer»

ok, so i followed the guidelines and ran all the programs needed........here are my logs......
the problem is that my system started lagging real bad, and internet pages were taking forever to open.......after running the programs it is definitely better but not as it should be, pages still a bit slow.....



[attachment deleted by admin]anyone?first 2 logs are fine , hjt there are 3 items you will need help with , wait for a malware  expert will do...thanksThe logs look fine but there is ONE optional entry I suggest removing with HJT.

Quote

Realtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor one's actions. It is not a SINISTER one, like remote control programs, but it is being used by Realtek to gather data about customers

Open HijackThis and select Do a system scan only

Place a check mark next to the FOLLOWING entries: (if there)

- O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

For the slow browser speed you might want to do some maintenance.

You can use the built in Windows Defrag by clicking Start > Run and then type in dfrg.msc then click OK. Or use a faster FREE program. Defraggler is very effective and easy to use.

Note: Be sure to clean out temp files and restart the computer just before beginning a defrag.great....im doing that now but have a question......what is the best way to clean out temp files?
i always go to c: then docs and settings then temp and try to delete all, but only some delete and i get a message saying some files cannot be deleted they are being used by another person or program......so some files i never can delete.....is there anything else i can do?Use a more powerful cleaner.

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and CHOOSE Run As Administrator

TFC will close all programs when run, so MAKE sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
866.

Solve : A few suspicious items?

Answer» ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. INCLUDE the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan Loghi. That didn't work, because when I was installing i got the error "Can not update. Is proxy configured?".

Been trying to search this board for the other online scanner (by kaspersky i believe), but was fruitless, so i'll have to bother you with giving me the link and all.

Thanks SD Please go to Kaspersky website and perform an online antivirus scan.

1. Read through the requirements and privacy statement and click on Accept button.
2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
3. When the downloads have finished, click on Settings.
4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
Spyware, Adware, Dialers, and other potentially dangerous programs
Archives


5. Click on My Computer under Scan.
6. Once the scan is complete, it will DISPLAY the results. Click on VIEW Scan Report.
7. You will see a list of infected items there. Click on Save Report As....
8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
9. Please post this log in your next reply along with a fresh HijackThis log.

hi 
the kaspersky scan is stopping at random moments

so I decided to post the HJT log.  I saw the VVSN entry again 

Quote
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:03:46, on 30/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Steven\Desktop\utilities\ProcessExplorer\procexp.exe
C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Ansys Inc\Shared Files\Licensing\intel\ansyslmd.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Steven\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\[email protected]\[email protected]\[email protected]
C:\Documents and Settings\Steven\Application Data\[email protected]\FahCore_78.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to procexp.exe.lnk = C:\Documents and Settings\Steven\Desktop\utilities\ProcessExplorer\procexp.exe
O4 - Startup: todo.txt
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} (TSCCInstall Class) - http://www.techsmith.com/codec/tsccinst.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} (Java Plug-in 1.6.0_15) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - https://secure.storegate.com/User/Files/Cabs/ImageUploader4.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\WINDOWS\
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager (NILM License manager) - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\SYSTEM32\OpcEnum.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

--
End of file - 10520 bytes

Hello two-eyes. I'm at a loss as to where this VVSN program is coming from. I will have to check it with my mentor but he's away for the holidays. Is your computer running well enough to wait a bit?SD, VVSN is SaveNow adware.Thanks Karnac
Two-eyes, let's try this to see if we can find that program.

•Start HijackThis
•Click on the Misc Tools button
•Click on the Open Uninstall Manager button.
•Click on the Save list... button and specify where you would like to save this file. When you press Save button a Notepad will open with the contents of that file. Save the file to your desktop.
Copy and paste this file in your next reply. Quote
Is your computer running well enough to wait a bit?
It is, don't worry. It's just the fact that there is something on my computer that shouldn't be there.  Don't worry too much about it.

Here is the uninstall list:
Quote
32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.5 LANGUAGE Support
Adobe Reader 7.1.0
Adobe Shockwave Player 11.5
Age of Empires III
Alcatel SpeedTouch USB Software
ANSYS 10.0
Ares 3.1
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Control Panel
ATI Display Driver
AutoCAD 2004
AVG Free 9.0
BisonCam
BlueSoleil
CamStudio
CCleaner (remove only)
Combat Arms EU
COMODO Internet Security
Compatibility Pack for the 2007 Office system
Critical Update for Windows Media Player 11 (KB959772)
DivX Web Player
ESET Online Scanner v3
Flary Address
[email protected]
Google Earth
Google Update Helper
HDAUDIO Soft Data Fax Modem with SmartCP
High Definition Audio Driver Package - KB888111
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Customer Participation Program 8.0
HP Deskjet All-In-One Software 8.0
HP Imaging Device Functions 8.0
HP PrecisionScan LTX
HP Product Assistant
HP Smart Web Printing 1.0
HP Solution Center 8.0
HP Update
HPSSupply
Intel(R) PROSet/Wireless Software
Java DB 10.4.1.3
Java(TM) 6 Update 13
Java(TM) 6 Update 17
Java(TM) SE Development Kit 6 Update 12
Java(TM) SE Development Kit 6 Update 17
JCreator LE 4.50
KTP Ware PS/2-WDM 5.0.4.1
L&H TTS3000 British English
Malwarebytes' Anti-Malware
Marvell Miniport Driver
MATLAB Family of Products Release 14
mCore
mDriver
mDrWiFi
mEoU.msi
mHelp
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Encarta Encyclopedia Standard 2001 - WE
Microsoft Encarta PREMIUM Suite 2005
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office FrontPage 2003
Microsoft Office Outlook Connector
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
mIRC
mIWA
mIWCA
mLogView
mMHouse
mPfMgr
mPfWiz
mProSafe
MSN
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Multimedia / Internet Keyboard Driver VerR8.15
mWlsSafe
mXML
mZConfig
National Instruments Software
Nero Suite
PDFCreator
PowerDVD
Realtek High Definition Audio Driver
SafeCast Shared Components
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Segoe UI
Shockwave
Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
Texas Instruments PCIxx21/x515 drivers.
Turbo Pascal 7.0
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Windows Genuine Advantage v1.3.0254.0
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
867.

Solve : slow net browsing with eset v4??

Answer»

i was using avira premium suite at that time my browsing was very fast,but now i m using eset nod32 v4 now pages r OPENING in long time,no firewall in eset v4 which i m using,
i m using windows firewall,OPERATING system xp,browser opera 10.10,The first thing I will need you to do is to go to this link and follow the directions precisely. If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB STORAGE device. I PREFER a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please post any logs that you can generate.I don't see that he said he had a virus, just that his browsing was slower with Nod32 as his antivirus.
I had the same issue.

OP, don't know why you no longer use Avira. But my internet browsing speed increased a lot switching to that from Nod32.

Not trying to be an *censored*, I just think his first post was misread.See Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.

868.

Solve : Installed Norton and now can't access internet?

Answer»

Hi, maybe someone can help.

I recently bought a NEW laptop and part of the extras bundle was Norton 360. I'm not the biggest fan of Norton but installed it on my laptop with Windows 7 and it works fine. I then decided to install on my mum's computer since you can use it on up to 3 PCs. Her computer is running on XP and is a little old and slow. Recently it has been infected by PERSONAL Security sypware and getting it off has been troublesome so i hoped Norton could help.

So i installed Norton and it removed AVG and Zone ALARM which were previously on the computer and then it went to register and it couldn't get onto the wireless internet we have. My laptop right next to it was able to get on so i knew it wasn't an internet fault, but nothing i could do could get the computer to connect. The computer was connected (according to the wireless) but internet explorer wouldn't connect and NEITHER would Firefox. Is this Norton and how do i fix it so it can register and use the internet?

ALSO if anyone can tell me how to remove Personal Security that would be very helpful too.

ThanksInstalling an AV after a system is infected is generally not a good option. You can try to run a scan at boot (I'm guessing you can boot to the Norton 360 cd and run a scan), but you're probably better off just going to the malware forum on this site and following the instructions at the top of the page.Thank you. Will try the steps tonight to remove the spyware if I can get on the internet.

Any idea on why i suddenly can't access the internet after installing Norton?If her system is indeed infected it could be any number of things. Best to go through all the steps and make sure the system is malware free.

869.

Solve : Sysguard?

Answer»

I had apparently contracted Sysguard on my computer...  I'm not sure if I got rid of it, but I had gone into Safe Mode, and used System Restore to go back by eight days.  Do you know if it is gone for sure?  I need to be sure so that it doesn't return.

I'm using Malwarebytes' Anti-Malware at this very moment to be sure.To make certain, go Here and follow the directions precisely.  Post the logs that they mention.How did you know you had sysguard?
Did you test for it again? SysGuard had appeared in the system tray on the lower right.  It's not there now. (There had been a blue shield icon there, and there isn't ONE now.  Nor did I see the entries for the rogue antivirus program in the registry.)

However, while SUPERAntiSpyware is scanning, it has so far detected five entries for "Adware.Vundo/Variant-MSFake", and eleven entries for "Adware.MyWay".

I'll post the complete log when I finish.  I DO want to get rid of this Vundo adware as soon as possible, before it gets worse.  Some of the Vundo files were detected in System Restore...

EDIT:
SUPERAntiSpyware has finished scanning, and aside from the System Restore files, the only other Vundo entry listed is "C:\Program Files\FAST Video Upload\DLL\NTWDBLIB.dll", which I believe is being falsely detected.  Fast Video Upload is a Facebook addon, and I've used it to successfully upload videos of my gaming playthroughs to Facebook.  (The last video capture was "Jaws" for the NES.)

All other entries listed by SuperAntiMalware were removed and put into quarantine.

Speaking of SysGuard, when it was on my computer, I saw things like the images on the following page:

http://www.f-secure.com/v-descs/rogue_w32_sysguard_d.shtmlSpeaking of the SuperAntiSpyware log, here it is:


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/29/2009 at 08:48 PM

Application Version : 4.25.1012

Core Rules Database Version : 4422
Trace Rules Database Version: 2248

Scan type       : Complete Scan
Total Scan Time : 01:02:51

Memory ITEMS scanned      : 604
Memory threats detected   : 0
Registry items scanned    : 9894
Registry threats detected : 10
File items scanned        : 37944
File threats detected     : 6

Adware.MyWay
   HKLM\SOFTWARE\Classes\CLSID\{3D898C55-74CC-4B7C-B5F1-45913F368388}
   HKCR\CLSID\{3D898C55-74CC-4B7C-B5F1-45913F368388}
   HKCR\CLSID\{3D898C55-74CC-4B7C-B5F1-45913F368388}
   HKCR\CLSID\{3D898C55-74CC-4B7C-B5F1-45913F368388}\InprocServer32
   HKCR\CLSID\{3D898C55-74CC-4B7C-B5F1-45913F368388}\InprocServer32#ThreadingModel
   HKCR\CLSID\{3D898C55-74CC-4B7C-B5F1-45913F368388}\ProgID
   HKCR\namespace.IEHelper
   HKCR\namespace.IEHelper\Clsid
   C:\PROGRA~1\ADBLOC~1\NAMESP~1.DLL
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3D898C55-74CC-4B7C-B5F1-45913F368388}
   HKU\S-1-5-21-1839360596-3980712012-3310118372-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3D898C55-74CC-4B7C-B5F1-45913F368388}

Adware.Vundo/Variant-MSFake
   C:\PROGRAM FILES\FAST VIDEO UPLOAD\DLL\NTWDBLIB.DLL
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1002\A0331112.DLL
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{106CF321-99A3-4E3A-9103-1BD027606A99}\RP985\A0323887.DLL
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{106CF321-99A3-4E3A-9103-1BD027606A99}\RP986\A0323993.DLL
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{106CF321-99A3-4E3A-9103-1BD027606A99}\RP998\A0329112.DLL

Do you want a Malwarebytes' Anti-Malware scan?
I completed the MABM scan anyways.  It only found two things:


Malwarebytes' Anti-Malware 1.42
Database version: 3289
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

12/29/2009 10:29:00 PM
mbam-log-2009-12-29 (22-29-00).txt

Scan type: Full Scan (C:\|)
Objects scanned: 276382
Time elapsed: 1 hour(s), 12 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
I removed all old versions of Java, and installed the latest version.  Now here's the HJT log file.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:07 PM, on 12/29/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\iTunesHelper.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Roland\VSC32\vsc32cnf.exe
C:\Program Files\Roland\VSC32\vscvol.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\StkASv2K.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\HP_Administrator\Desktop\JavaRa.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal.wowway.net/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:4128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOL Toolbar Search Class - {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll
R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AOL Toolbar Loader - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll
O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll
O3 - Toolbar: AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll
O4 - HKLM\..\Run: [KBD] "C:\HP\KBD\KBD.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ehTray] "C:\WINDOWS\ehome\ehtray.exe"
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RunDLL32.exe" NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunesHelper.exe"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [P17Helper] "Rundll32" SPIRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [vsc32cnf.exe] "C:\Program Files\Roland\VSC32\vsc32cnf.exe"
O4 - HKLM\..\Run: [vscvol.exe] "C:\Program Files\Roland\VSC32\vscvol.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe"
O4 - HKLM\..\Run: [UVS10 Preload] "C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] "C:\WINDOWS\system32\dumprep.exe" 0 -k
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [lightScribe Control Panel] "C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {00000000-CB06-433A-9302-77436F840932} - C:\Program Files\Ad Blocker\blocker.exe
O9 - Extra 'Tools' menuitem: &Ad Blocker - {00000000-CB06-433A-9302-77436F840932} - C:\Program Files\Ad Blocker\blocker.exe
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in WINSOCK LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194668984023
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Media Toolbox 6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio UPnP Renderer 9 - Unknown owner - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe (file missing)
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: Roxio Upnp Server 9 - Unknown owner - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe (file missing)
O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SessionLauncher - Unknown owner - C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\DX9\SessionLauncher.exe (file missing)
O23 - Service: Syntek STK1160 Service (StkASSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkASv2K.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc.  - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe

--
End of file - 18103 bytes

I won't do anything further without somebody replying and telling me that I need to remove certain checked entries.

EDIT: An edit has been made to my second post in this topic, showing what I saw on my computer when the malware was present.Ryan, thanks for doing all of that.  One of our specialists will be with you, just be patient as we are all volunteers here.

I did get your PM, but I don't provide support over PM, and I certainly am not a virus specialist.  Sit tight for a few, they will get you fixed up.

870.

Solve : Cant install Superantispyware?

Answer»

i TRIED installing it and a noitce comes up that says superantispyware has encountered a problem and needs to close... then theres the send error REPORT and DONT send buttons.... i need to INSTALL this to FOLLOW the getting rid of malware steps. help please?Stop starting new threads and using Private Messages. Just wait for someone to help you in your original Malware post.

871.

Solve : some help please??

Answer»

Ok, I think I just got a virus out of my system...however, when I GO to control panel > admin tools, and try to click on one of the options there, it always pops up with an error message.  For example, when I double click on "Services", it pops up as C:\Windows\system32\services.msc - access is denied.  Is there any reason why I wouldn't be able to open this?  Is it CONNECTED to a virus or something malicious? 

Also, how the heck do I get Google Update Service off my system?  It seems that no matter what I have tried, it always shows up in my HijackThis logs....

PS - You people are amazing, keep up the good work...the world would be a better PLACE with more people like you!


Edit - never mind, I fixed the admin tools PROBLEM myself with some OLD fashioned computer hacking and, using the services tab, was able to finally disable Google Update Service for good, at least it looks like it!!   just to make sure plz post a hijackthis log

872.

Solve : trojan horse generic 15. CKLU?

Answer»

The computer I have -I can't log on to. I have the trojan horse generic 15. Cklu. I tried safe modew/networking to no avail. I just installed the harddrive as a secondary drive in another computer. I was going to download an trojan REMOVAL program. I don't know what to do to download a program onto this harddrive. When I boot up this computer,I'm USING the harddrive that is in it ,not the one I ADDED. They're both Sata drives. How do I PROCEED?  I would appreciate anyones help.  ThanksPut the HDD back into your computer and go to this link to create a Rescue CD or to this site to create a Rescue USB. CAREFULLY follow all the instructions for whichever method you choose. This should be able to get your computer booted.

873.

Solve : Pop Up problem (help!)?

Answer»

I download internet download manager.It doesn't work properly so I uninstall it.Even though I unistall it this screen pop up everytime when I'm OPEN something.It said (Internet download manager detected that its registry KEYS had been damaged since the last run.It's possible that you run a flasky spyware program which corrupted system registry.Internet download manager will try to restore all damaged data, but some data may remain corrupted.)How can I stop from that screen popping everytime.If you have any solution to solve that problem Plzzz help me.Thanks!
The first thing I will need you to do is to go to this link and follow the directions precisely. If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any STEP, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please POST any logs that you can generate.

874.

Solve : Need Help - Cant log into AOL - Get Virus Warning!?

Answer»

Hi,

I have Windows Vista and I am running Avast and Malwarebytes Antivirus programs.

I can not log into AOL. When I try I get a virus WARNING from Avast! -

Last infected: http//:cdn.at.atwola.com/_media/uac/tcode3.html

Currently, I am running Malwarebytes but nothing is showing up - I want to do something before this GETS worse.

Please help!

KLThe first thing I will need you to do is to go to this link and follow the directions precisely. If you can't access the internet with your infected COMPUTER you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you RECEIVE back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please post any logs that you can generate.

875.

Solve : Virus Help????

Answer»

O.k. Somehow I Had A Program Called ANTIVIR running on my computer... I thought it waz AVG 8.5 because they have the same Look.

Problem: I Can Only Access My Desktop Threw Safe Mode. When I Try To Log In Without Safe Mode The Welcome Screen In Vista Just Keeps Trying To Load But Never Does Lead Me To My Desktop.

LOgs: I Couldn't Download SuperAntiSpyware... Wouldn't Download. & When I Tried To Update My Java Thing It Said You Can't Update In Safe Mode. But i Attacthed All Of The Other Logs Below..

[SAVING space, attachment deleted by admin]Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
Save Rkill to your desktop.

There are 4 different VERSIONS. If one of them won't run then download and try to run the other one.
 
Vista and Win7 users need to right click Rkill and choose Run as Administrator
 

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, IGNORE them or shutdown your antivirus.

Rkill.exe
Rkill.com
Rkill.scr
Rkill.pif

Once you've gotten one of them to run then try to immediately run the following.
 
Now download and Run exeHelper.

Please download exeHelper from Raktor to your desktop.

  • Double-click on exeHelper.com to run the FIX. A black window should pop up, press any key to close once the fix is completed. A log file named log.txt will be created in the directory where you ran exeHelper.com Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
876.

Solve : Cachedump.....HOW DO I ??

Answer»

How do I dump my cache in a SAFE way?
AVAST is warning me for:"_CACHE_001_.
Location:C:\users\my name\app data\local\mozilla\firefox\profiles\k6ber258.default\cache

I run:Wind.spII.


All the best;Eric..........Tools - Clear Recent History - EverythingThank you.....Wish you all the best and a nice 2010  You're WELCOME - and you too

877.

Solve : clicking on search results?

Answer»

Whenever I do a GOOGLE SEARCH and click on a result I get a white screen with this address in the upper left hand corner:  http://206.161.121.115/go.php
Sometimes it varies on the NUMBERS displayed.  I can copy the WEBSITE and paste it into the address bar and it works fine.  Also, all of my favorites links work fine.  I am running Vista.  Any help WOULD be great, thank you.I have the same problem!! I am running XP. HELP!!

878.

Solve : some kind of trojan??

Answer»

I'm pretty sure I have a trojan of sorts. A whole bunch of my exes randomly corrupted themselves, telnet and notepad keep running everytime I close or run a program (I'm using PROCESS explorer, and it shows them as being run by mbamgui which is my anti-malware program). I don't know what it is, but its rather destructive and it's probably SENDING data back somewhere if it keeps running telnet. Any insights as to what this could be?Sorry to double-post, but I just found 2 other programs that were running themselves called winjpjr.exe and windghno.exe. They were residing in my temp folder, and I just deleted them. Chances are that won't really help, but with any luck that will at LEAST help IDENTIFY what they are.

EDIT:
I just went back into the Temp folder, and three new exes spawned. They are all acting the same as the other TWO I deleted earlier. So I guess whatever this is randomly generates names for the viruses it creates.Follow the instructions in the announcement at the top of this forum.

879.

Solve : "This volumn is dirty"...What is this??

Answer»

Happy New year all...

I have a 4 gig flashdrive and when I access it I get an antivirus message from AVG saying I have a virus namely

"E:\autorun.inf";"Virus identified Worm/AutoRun.EK";"Infected"

 which should be MOVED to the vault.  I do this and then the next time I access the flashdrive, it happens all over again.

Any advice would be greatly appreciated.

Many thanks,
SampTry moving it to the vault and then formatting the flash drive. If that doesn't work, try a different anti virus - could be something with AVG. I'm not suggesting you have more than one AV INSTALLED at the same time, that's a bad IDEA. But you can download either Avira or AVAST then untinstall AVG and install the new one. BTW, both Avira & Avast are GENERALLY considered superior to AVG anyway.

880.

Solve : "Help"please?

Answer»

I have a two part question, both PC and laptop OS is Windows XP Pro. First for my desktop, when I browse the net ( I use Mozilla Firefox) I get a window that states Secure Connection Failed in the box it says INVALID security certificate or expired.if you need more info on everything it says let me know and I'll type it all in it just differs from what I try to open.My desktop also seems to stop and pop up a blue screen saying something about shutting down to prevent harm to computer.It doesn't do it  everytime but alot when I seem to backup my movies.
Next the laptop, my daughter was on the net and a pop up came up and started to download Internet Security 2010 and it is a virus but I have AVG 8.5 and ran tests but without any satisfaction.I have also tried to remove the program but it seems to not be in the add/remove programs to delete it.
So if you could help with any of these problems I would greatly APPRECIATE it.Also if it is spyware is there any free spyware/ad ware programs out there that i could download to prevent this form happening again?Internet security 2010 is a bit of a pain to remove, but it can be done if you follow instructions. Download and run a scan with Malware Bytes - it will remove part of the trojan. Then follow the instructions here: http://www.2-spyware.com/remove-internet-security-2010.html

That will do it, but to be safe you can follow the instructions at the top of the Malware forum at this site if you LIKE.

BTW, I'm not a big AVG fan - you get what you pay for. And also, if you're going to stay with AVG you need to update it to ver 9 - AVG is not going to provide support for any version below 9 after next week.Which antivirus woul you suggest and would that Malware Bytes take care of my desktop also?I tried to add the malwarebytes and was unable to download the program.I've also tried to get into taskmanager to stop Internet Security 2010 but it will not allow me to access it.I also tried to download killbox and delete the program that way but no luck.I was just going to backup the DRIVERS for this laptop and reformat but the virus allows me limited access to the files.Please anymore suggestions?Go to the malware forum on this site and follow the instructions at the top of that forum. Your problems are apparently more severe than just the one trojan.

881.

Solve : virus help??

Answer»

I am getting this pop-up message when I start the computer, the window is titled "SECURITY Center Alert" - it says WINDOWS firewall has blocked a software called "Trojan.Win32.Agent.dcc....it has the options "Keep Blocking", "Unblock", and "Enable Protection", with the first two options grayed out.  It also opens up a window asking me to download some anti-virus software from somewhere.

I also have Norton Anti-Virus that automatically starts when the computer does, but since this problem STARTED, it has not started with the computer.  I attached the Super-AntiSpyware and HijackThis logs, but when I attempted to download the Anti Malware program, when I double-clicked the INSTALLATION icon, it did nothing and just sat there.

Any help is appreciated.  Thank you!

[Saving space, attachment deleted by admin]Ok, I was able to install the Anti-Malware after renaming the installation file and the program file.  I ran it, got the log (which is attached) and everything seems to be working ok again...the anti virus started with windows, no more popups, etc.

[Saving space, attachment deleted by admin]Ok, I really don't mean to be bumping my thread, but more STUFF happens the longer I am working on this

Now when I start the computer, Norton does not load, and two windows pop up, saying something called "Google Installer" and "ViewMgr" have encountered problems and need to close.  Not sure what they are though...Once again, sorry for bumping my thread.  After running Anti-Malware, Super Anti Spyware and HijackThis again, these are the new logs, Norton seems to be really messed up (I have tried uninstalling it and re-installing it, but then when I try to open the program, nothing happens), and the error messages keep popping up on start up about the Google Installer and ViewMgr.  Thanks for taking a look...

[Saving space, attachment deleted by admin]

882.

Solve : Cache problems.....or not.?

Answer»

I would like to KNOW what:"_CACHE_001_"means.My virusscanner warns me for this and I don`t know what it is,what it does and what it is for.
PLEASE HELP...
                                     Thanks

(I`m Dutch,forgive my English) Which anti virus program?I hope I`m doing this correctly.The program is:"Avast"(Free edition).
Thanks for the quick reply.....That's fine. cache_001 is not malware to the best of my knowledge so I just wanted to make sure you're USING a good AV utility. Avast is a good product - what's the warning message you are getting?Avast tells me it is not a virus but it does put a skull and crossed bones in front of it in my virus chest.It also gives a location:"C:\Users\"my name"\App Data\Local\Mozilla\FireFox\Profiles\k6ber258.default\Cache.
Thanx again for your fast reply.
I do not know if you might know this,is the paid Avast better in retreiving worms/virusses/T-horses ect.than the free one.The paid version offers some ADDITIONAL features, but the engine should be the same. I always pay for my AV utility simply because I don't think an AV is something to skimp on and I want the best product available - in my opinion that's KASPERSKY - but different people have different favorites. Avast free is fine.

That's the mozilla cache file, which is what I thought it was. You might just want to empty the cache - it's possible you visited a page / site that Avast doesn't like. It won't hurt anything either way, but it might help get rid of that warning message if you do dump the cache.Thank you very much.I wish you a fine and virus-free 2010....
I do not know if i am supposed to send a thank you on the forum.If it is wrong sorry.
Again:Forgive my English.

 You're very welcome - and Happy New Year to you also. And by the way, your English is just fine Quote from: Eric1611 on December 27, 2009, 04:24:01 PM

Thank you very much.I wish you a fine and virus-free 2010....

Thank you!

Quote
I do not know if i am supposed to send a thank you on the forum.

Not compulsory, but always appreciated.

Quote
If it is wrong sorry.

Never wrong!

Quote
Again:Forgive my English.

Your English is very good


883.

Solve : Befuddled... Mozilla hijacks and something else?

Answer»

Delete ComboFix and download a new copy.

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
C:\WINDOWS\Tasks\YNQPXOGR.job

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
"Uninstall Adobe Download Manager"=-


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeOkay, I let combofix do it's job... But I forgot to turn off anti-virus so it had a problem downloading at first but after realizing my mistake it didn't take log... Here is that log from combofix...

ComboFix 09-12-20.08 - St. Asmodeus 12/21/2009  15:13:37.1.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1902.1315 [GMT -6:00]
Running from: c:\documents and settings\St. Asmodeus\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\St. Asmodeus\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

FILE ::
"c:\windows\Tasks\YNQPXOGR.job"
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\YNQPXOGR.job
c:\windows\Temp\0218441261345893mcinst.exe

.
(((((((((((((((((((((((((   Files Created from 2009-11-21 to 2009-12-21  )))))))))))))))))))))))))))))))
.

2009-12-21 10:27 . 2009-12-21 10:29   141526   ----a-w-   C:\MGlogs.zip
2009-12-21 10:27 . 2009-12-21 10:29   --------   d-----w-   C:\MGtools
2009-12-20 14:58 . 2009-12-20 14:58   --------   d-sh--w-   c:\documents and settings\St. Asmodeus\IECompatCache
2009-12-20 01:58 . 2009-12-20 02:21   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\Vso
2009-12-20 01:57 . 2009-12-20 01:57   --------   d-----w-   c:\program files\VSO
2009-12-18 02:19 . 2009-12-21 21:19   52224   ----a-w-   c:\documents and settings\St. Asmodeus\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-16 21:23 . 2009-12-16 21:23   --------   d-----w-   c:\program files\ESET
2009-12-16 01:26 . 2009-12-16 01:26   4844296   ----a-w-   c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-MALWARE\mbam-setup.exe
2009-12-16 01:14 . 2009-12-16 01:14   --------   d-----w-   c:\program files\Trend Micro
2009-12-16 00:44 . 2009-12-16 00:44   1   ----a-w-   c:\documents and settings\St. Asmodeus\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-16 00:43 . 2009-12-16 00:43   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\OpenOffice.org
2009-12-16 00:31 . 2009-12-16 00:31   --------   d-----w-   c:\program files\JRE
2009-12-16 00:31 . 2009-12-16 00:31   --------   d-----w-   c:\program files\OpenOffice.org 3
2009-12-16 00:30 . 2009-12-16 00:29   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-12-16 00:29 . 2009-12-16 00:29   --------   d-----w-   c:\program files\Java
2009-12-16 00:25 . 2009-12-16 00:25   --------   d-sh--w-   c:\documents and settings\St. Asmodeus\PrivacIE
2009-12-14 21:53 . 2002-12-17 22:23   33340   ------w-   c:\windows\system32\dbmsqlgc.dll
2009-12-14 21:53 . 2002-10-20 20:05   24576   ------w-   c:\windows\system32\dbmsgnet.dll
2009-12-14 21:53 . 1998-10-29 21:45   306688   ----a-w-   c:\windows\IsUninst.exe
2009-12-14 21:53 . 2009-12-14 21:53   --------   d-----w-   c:\program files\Microsoft SQL Server
2009-12-14 21:52 . 2009-12-14 21:52   --------   d-----w-   c:\documents and settings\All Users\Application Data\Sony
2009-12-14 21:09 . 2009-10-20 16:20   265728   -c----w-   c:\windows\system32\dllcache\http.sys
2009-12-14 21:08 . 2009-12-14 21:08   --------   d-----w-   c:\documents and settings\St. Asmodeus\ErrorLogs
2009-12-14 03:21 . 2009-12-21 21:18   139056   ----a-w-   c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-13 22:45 . 2009-12-13 23:07   --------   d-----w-   c:\program files\Easy CD-DA Extractor
2009-12-13 22:45 . 1998-02-07 03:37   299520   ----a-w-   c:\windows\uninst.exe
2009-12-13 22:44 . 2009-12-13 22:44   --------   d-----w-   c:\documents and settings\St. Asmodeus\WINDOWS
2009-12-13 20:19 . 2008-10-26 04:48   2651951   -c--a-w-   c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}\DriverScanner_Setup.exe
2009-12-13 20:18 . 2006-12-01 23:26   57856   -c--a-w-   c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}\Windows\winsxs\7z1v718o.6n8\mfcm80u.dll
2009-12-13 19:18 . 2009-12-13 19:18   --------   d-sh--w-   c:\documents and settings\Administrator\IETldCache
2009-12-13 19:17 . 2009-12-13 19:17   --------   d-----w-   c:\program files\ACW
2009-12-13 18:45 . 2009-12-13 18:45   --------   d-----w-   c:\documents and settings\St. Asmodeus\DoctorWeb
2009-12-13 18:17 . 2009-10-29 07:45   12800   -c----w-   c:\windows\system32\dllcache\xpshims.dll
2009-12-13 18:17 . 2009-10-29 07:45   594432   -c----w-   c:\windows\system32\dllcache\msfeeds.dll
2009-12-13 18:17 . 2009-10-29 07:45   55296   -c----w-   c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-13 18:17 . 2009-10-29 07:45   246272   -c----w-   c:\windows\system32\dllcache\ieproxy.dll
2009-12-13 18:17 . 2009-10-29 07:45   1985536   -c----w-   c:\windows\system32\dllcache\iertutil.dll
2009-12-13 18:17 . 2009-10-29 07:45   11069952   -c----w-   c:\windows\system32\dllcache\ieframe.dll
2009-12-13 17:59 . 2008-06-13 11:05   272128   -c----w-   c:\windows\system32\dllcache\bthport.sys
2009-12-13 17:55 . 2008-10-24 11:21   455296   -c----w-   c:\windows\system32\dllcache\mrxsmb.sys
2009-12-13 17:53 . 2009-08-04 15:13   2145280   -c----w-   c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-13 17:53 . 2009-08-04 14:20   2023936   -c----w-   c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-13 17:53 . 2009-08-04 14:20   2066048   -c----w-   c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-13 07:34 . 2009-12-13 07:34   --------   d-----w-   c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-12-13 06:24 . 2009-12-13 06:24   --------   d--h--w-   c:\windows\system32\GroupPolicy
2009-12-13 06:00 . 2009-12-13 06:00   --------   d-----w-   c:\windows\McAfee.com
2009-12-13 00:03 . 2001-08-18 04:36   38912   -c--a-w-   c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2009-12-13 00:02 . 2008-04-14 05:41   400384   -c--a-w-   c:\windows\system32\dllcache\fxsxp32.dll
2009-12-12 23:59 . 2001-08-23 12:00   16384   -c--a-w-   c:\windows\system32\dllcache\isignup.exe
2009-12-12 23:51 . 2008-04-14 04:05   20992   ----a-w-   c:\windows\system32\drivers\RTL8139.sys
2009-12-12 23:48 . 2001-08-23 12:00   24661   -c--a-w-   c:\windows\system32\dllcache\spxcoins.dll
2009-12-12 23:48 . 2001-08-23 12:00   24661   ----a-w-   c:\windows\system32\spxcoins.dll
2009-12-12 23:48 . 2001-08-23 12:00   13312   -c--a-w-   c:\windows\system32\dllcache\irclass.dll
2009-12-12 23:48 . 2001-08-23 12:00   13312   ----a-w-   c:\windows\system32\irclass.dll
2009-12-12 21:32 . 2009-12-12 21:32   --------   d-sh--w-   c:\documents and settings\LocalService\IETldCache
2009-12-12 21:31 . 2009-12-12 21:31   132096   --sha-r-   c:\windows\system32\appmgmtsr.dll
2009-12-12 21:21 . 2009-12-12 21:21   --------   d-----w-   c:\program files\DVDFab 6
2009-12-12 20:43 . 2009-12-12 20:43   368640   ----a-w-   c:\windows\system32\ReWire.dll
2009-12-12 20:43 . 2009-12-12 20:43   233472   ----a-w-   c:\windows\system32\REX Shared Library.dll
2009-12-12 20:38 . 2009-12-12 20:38   --------   d-----w-   c:\documents and settings\All Users\Application Data\Propellerhead Software
2009-12-12 20:38 . 2009-12-12 20:45   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\Propellerhead Software
2009-12-12 20:28 . 2009-12-12 20:28   --------   d-----w-   c:\program files\Propellerhead
2009-12-12 18:13 . 2009-12-14 21:55   --------   d-----w-   c:\program files\Sony Setup
2009-12-10 22:52 . 2009-12-10 22:52   --------   d-----w-   c:\documents and settings\St. Asmodeus\Local Settings\Application Data\Ahead
2009-12-10 22:49 . 2009-12-10 22:53   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\Ahead
2009-12-10 22:48 . 2009-12-10 22:52   --------   d-----w-   c:\program files\Common Files\Ahead
2009-12-10 22:48 . 2009-12-10 22:48   --------   d-----w-   c:\program files\Nero
2009-12-09 01:47 . 2009-12-09 01:47   --------   d-----w-   c:\program files\Common Files\Adobe
2009-12-09 01:45 . 2009-11-20 11:08   38784   ----a-w-   c:\documents and settings\St. Asmodeus\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-09 01:44 . 2009-11-20 11:08   38784   ----a-w-   c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-09 01:44 . 2009-12-09 01:44   --------   d-----w-   c:\program files\Common Files\Adobe AIR
2009-12-09 01:44 . 2009-12-09 01:44   --------   d-----w-   c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-12-09 01:44 . 2009-12-09 01:50   --------   d-----w-   c:\documents and settings\St. Asmodeus\Local Settings\Application Data\Adobe
2009-12-09 01:44 . 2009-12-09 01:44   --------   d-----w-   c:\program files\McAfee Security Scan
2009-12-09 01:43 . 2009-12-09 01:43   86016   ----a-w-   c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-12-09 01:42 . 2009-12-21 21:12   --------   d-----w-   c:\documents and settings\All Users\Application Data\NOS
2009-12-09 01:37 . 2009-12-09 01:37   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\U3
2009-12-06 21:16 . 2009-12-06 21:16   --------   d-----w-   c:\program files\ASIO4ALL v2
2009-12-06 21:15 . 2009-12-06 21:15   --------   d-----w-   c:\program files\Outsim
2009-12-06 21:11 . 2009-12-06 21:15   --------   d-----w-   c:\program files\Image-Line
2009-12-06 21:06 . 2009-12-21 10:29   --------   d-----w-   c:\documents and settings\St. Asmodeus\Local Settings\Application Data\ApplicationHistory
2009-12-06 20:53 . 2006-08-16 15:23   21888   ----a-w-   c:\windows\system32\drivers\ma_cmidi.sys
2009-12-06 20:53 . 2006-08-16 15:23   86016   ----a-w-   c:\windows\system32\ma_cmidn.dll
2009-12-06 20:53 . 2006-08-16 15:24   82944   ----a-w-   c:\windows\system32\USBMN1X1.DLL
2009-12-06 20:53 . 2006-08-16 15:24   24128   ----a-w-   c:\windows\system32\drivers\USBMM1X1.SYS
2009-12-06 20:53 . 2006-08-16 15:24   22208   ----a-w-   c:\windows\system32\drivers\USBMN1X1.SYS
2009-12-06 20:53 . 2006-08-16 15:24   17920   ----a-w-   c:\windows\system32\USBMM1X1.DLL
2009-12-06 20:53 . 2006-08-16 15:24   13504   ----a-w-   c:\windows\system32\drivers\USB11LDR.SYS
2009-12-06 20:53 . 2006-08-16 15:24   12272   ----a-w-   c:\windows\system32\USBMM1X1.DRV
2009-12-06 20:53 . 2006-08-16 15:23   14272   ----a-w-   c:\windows\system32\MA_CMIDI.DRV
2009-12-06 20:53 . 2006-08-16 15:23   17920   ----a-w-   c:\windows\system32\MA_CMIDI.DLL
2009-12-06 20:30 . 2009-12-06 20:30   --------   d-----w-   c:\windows\system32\XPSViewer
2009-12-06 20:30 . 2009-12-06 20:30   --------   d-----w-   c:\program files\MSBuild
2009-12-06 20:30 . 2009-12-06 20:30   --------   d-----w-   c:\program files\Reference Assemblies
2009-12-06 20:29 . 2008-07-06 12:06   89088   ----a-w-   c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2009-12-06 20:29 . 2008-07-06 12:06   575488   ------w-   c:\windows\system32\xpsshhdr.dll
2009-12-06 20:29 . 2008-07-06 12:06   117760   ------w-   c:\windows\system32\prntvpt.dll
2009-12-06 20:29 . 2008-07-06 10:50   597504   ------w-   c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2009-12-06 20:29 . 2008-07-06 12:06   1676288   ------w-   c:\windows\system32\xpssvcs.dll
2009-12-06 20:03 . 2009-12-06 20:03   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\HpUpdate
2009-12-06 20:03 . 2009-12-06 20:03   --------   d-----w-   c:\windows\Hewlett-Packard
2009-12-05 18:51 . 2009-12-20 01:56   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\BitTorrent
2009-12-05 18:48 . 2009-12-05 18:48   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\NetMedia Providers
2009-12-05 18:48 . 2009-12-12 18:20   --------   d-----w-   c:\documents and settings\St. Asmodeus\Local Settings\Application Data\Sony
2009-12-05 18:44 . 2009-12-05 18:44   --------   d-----w-   c:\program files\Microsoft.NET
2009-12-05 18:33 . 2009-12-06 21:15   --------   d-----w-   c:\program files\VSTplugins
2009-12-05 18:33 . 2009-12-05 18:33   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\Publish Providers
2009-12-05 18:32 . 2009-12-14 21:52   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\Sony
2009-12-05 18:29 . 2009-12-12 18:14   --------   d-----w-   c:\program files\Sony
2009-12-05 18:27 . 2009-12-05 18:28   --------   d-----w-   c:\windows\system32\URTTemp
2009-12-05 18:13 . 2009-12-05 18:13   --------   d-----w-   c:\program files\PowerISO
2009-12-05 01:57 . 2009-12-05 01:57   --------   d-sh--w-   c:\windows\system32\config\systemprofile\IETldCache
2009-12-04 22:09 . 2009-12-04 22:11   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\Ventrilo
2009-12-04 22:07 . 2009-12-04 22:07   --------   d-----w-   c:\program files\Ventrilo
2009-12-04 22:04 . 2009-12-20 22:35   138328   ----a-w-   c:\windows\system32\drivers\PnkBstrK.sys
2009-12-04 22:03 . 2009-12-20 22:34   214816   ----a-w-   c:\windows\system32\PnkBstrB.exe
2009-12-04 22:02 . 2009-12-04 22:02   --------   d-----w-   c:\windows\system32\LogFiles
2009-12-04 22:02 . 2009-12-04 22:02   75064   ----a-w-   c:\windows\system32\PnkBstrA.exe
2009-12-04 22:02 . 2009-12-04 22:02   --------   d-----w-   c:\documents and settings\St. Asmodeus\Local Settings\Application Data\PunkBuster
2009-12-04 21:57 . 2009-12-04 22:01   --------   d-----w-   c:\program files\Wolfenstein - Enemy Territory
2009-12-04 21:46 . 2009-12-04 21:46   --------   d-sh--w-   c:\documents and settings\St. Asmodeus\IETldCache
2009-12-04 21:32 . 2009-12-04 21:32   --------   d-----w-   c:\windows\ie8updates
2009-12-04 21:30 . 2009-12-04 21:30   --------   d-----w-   c:\documents and settings\LocalService\Application Data\McAfee
2009-12-04 21:30 . 2009-12-16 01:42   --------   dc-h--w-   c:\windows\ie8
2009-12-04 21:17 . 2009-12-04 21:17   --------   d-----w-   c:\documents and settings\St. Asmodeus\Application Data\Logitech

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-20 14:56 . 2009-12-01 00:50   20432   ----a-w-   c:\documents and settings\St. Asmodeus\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-13 20:26 . 2009-12-13 20:26   --------   dc-h--w-   c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
2009-12-13 20:20 . 2009-12-13 20:19   --------   d-----w-   c:\documents and settings\All Users\Application Data\DriverScanner
2009-12-13 20:19 . 2009-12-13 20:19   --------   dc-h--w-   c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2009-12-12 23:57 . 2009-12-01 00:38   23348   ----a-w-   c:\windows\system32\emptyregdb.dat
2009-12-12 23:57 . 2009-12-01 00:38   --------   d-----w-   c:\program files\Windows Media Connect 2
2009-12-04 21:14 . 2009-12-04 21:14   0   ---ha-w-   c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-12-04 21:14 . 2009-12-04 21:14   0   ---ha-w-   c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-12-04 21:14 . 2009-12-04 21:14   0   ---ha-w-   c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-03 00:51 . 2009-12-01 00:41   86327   ----a-w-   c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-01 00:58 . 2009-12-01 00:58   --------   d-----w-   c:\program files\BitTorrent
2009-12-01 00:57 . 2009-12-01 00:57   0   ----a-w-   c:\windows\nsreg.dat
2009-12-01 00:42 . 2009-12-01 00:42   --------   d-----w-   c:\program files\microsoft frontpage
2009-11-20 11:08 . 2009-12-13 05:54   38784   ----a-w-   c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-04 22:54 . 2009-11-04 22:54   214664   ----a-w-   c:\windows\system32\drivers\mfehidk.sys
2009-10-29 07:45 . 2008-04-14 05:42   916480   ------w-   c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2008-04-14 05:42   75776   ----a-w-   c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2008-04-14 05:41   25088   ----a-w-   c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-14 00:23   265728   ----a-w-   c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2008-04-14 05:42   270336   ----a-w-   c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2008-04-14 05:42   149504   ----a-w-   c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2008-04-14 05:42   79872   ----a-w-   c:\windows\system32\raschap.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-18 2002160]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2006-02-01 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"M-Audio Taskbar Icon"="c:\windows\System32\M-AudioTaskBarIcon.exe" [2008-05-15 356864]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2006-03-18 184320]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-27 16120832]

c:\documents and settings\St. Asmodeus\Start Menu\Programs\Startup\
SpeedFan.lnk - c:\program files\SpeedFan\speedfan.exe [2007-9-17 2902528]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-12-4 805392]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21   548352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42   72208   ----a-w-   c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=ma_cmidn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

R0 amdide1;amdide1;c:\windows\system32\drivers\amdide1.sys [8/31/2009 5:38 AM 9096]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [11/23/2009 8:43 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/23/2009 8:43 AM 74480]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [11/30/2009 7:17 PM 93320]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/23/2009 8:43 AM 7408]
S0 3112Rx47;3112Rx47;c:\windows\system32\drivers\3112Rx47.sys [8/31/2009 5:39 AM 110128]
S2 0218441261345893mcinstcleanup;McAfee Application Installer Cleanup (0218441261345893);c:\windows\TEMP\021844~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\021844~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S3 MAUSBFT;Service for M-Audio Fast Track USB (WDM);c:\windows\system32\drivers\mausbft.sys [12/1/2009 6:15 PM 132096]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - 0218441261345893MCINSTCLEANUP

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
FF - ProfilePath - c:\documents and settings\St. Asmodeus\Application Data\Mozilla\Firefox\Profiles\eo7e0plm.default\
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-21 15:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(560)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\documents and settings\St. Asmodeus\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\documents and settings\St. Asmodeus\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(2700)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\Ati2evxx.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\RTHDCPL.EXE
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2009-12-21  15:27:16 - machine was rebooted
ComboFix-quarantined-files.txt  2009-12-21 21:27
ComboFix2.txt  2009-12-19 22:24

Pre-Run: 111,551,311,872 bytes free
Post-Run: 111,516,999,680 bytes free

- - End Of File - - D393E5DC0CB69BAA980CF675482C05BF


[Saving space, attachment deleted by admin]Are you still getting the redirects?No more redirects....

Thank You so much. I could not help notice that it might have something to do with "c:\windows\Tasks\YNQPXOGR.job" I saw a file  like that before in a spyware\malware I deleted and removed right before I got this problem...

Thank you again so much is there any other scans or logs you need me to do?

Yes it was the YNQPXOGR.job file.

Time to clean up.

Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.

* Click START then RUN
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter.

The above procedure will:
* Delete: ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.

----------

Use the Secunia Software Inspector to check for out of date software.

  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your BROWSER. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in SPYBOT - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for TIPS and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Great! Thank you so much...

I'll going through the  through the clean process in a couple hours after I have dinner... Thanks again, I'll do have super anti-spyware as my real-time protection but I do believe I will also try some of the other programs you've recommended.

Thanks Again for the help...

Your welcome.

Safe surfing.
884.

Solve : Friend Cant Login After rogue removal?

Answer»

Ok so my friend was talking to me about how he got some rogue, "System antivirus 2010" i believe, anyway he said he ran MBAM and it didn't REMOVE it and he couldn't download SAS.  He then ran a McAffe scan (Yes he knows McAffe sucks, and of coarse it did not see anything wrong with the computer), but McAffe shows like changes in the registry or something..so he went and rather wrecklessly deleted a few keys.  Now when he tries to Login, he GETS to the welcome screen and then it LOGS him back out.  I went over and checked it out, couldnt fix it.

He is running windows XP Pro SP3

Any ideas???MBAM will address that trojan, so I don't know what your friend did. And you are correct - McAfee is terrible and I don't know what that did either. Can he boot to safe mode?nah safe mode gets the same result1) Download and run a boot time av scanner
2) Do a repair install of XP

If the above two steps don't solve the problem you MAY need to do a clean reinstall.

885.

Solve : lose of internet connection?

Answer»

Hi There


  I have a intresting problem, running XP and ive lost connection to the internet. The network connection say network CABLE not attached. thought it was a ethernet card problem but apperantly the a VIRUS thats going around that causes this.

   Anyone know of this and if so how to get rid of it

  You can try right click on the network connections icon on the task bar and then click repair and see if it solves the problem.
In the event that it doesn't, unplug your modem and router if you have one, wait a couple of minutes then plug them in and reboot and see if the problem is solved
It's a common problem and seldom malware related. Tried all that nothing, I have 3 laptop that are wireless and there all fine. I even tried hooking the modemn direct into the DESKTOP but its still the same
If your XP computer is hard-wired did you try another cable?tired another cable even tried another modemn but it still SAYS network cable UNATTACHED. A repair tech at futureshop mentioned somethng about a virus thats going around that causes your computer too lose conectionThe best thing to do is to go to this link and follow the directions precisely. Post the necessary logs and we can verify if it's caused by malware.

886.

Solve : have a virus, need to format, but unable to backup pictures!?

Answer»

I have some sort of virus thats killing my computer. Im going to reformat my hard drive, but before I do so I need to back up all my pictures. But here lies the PROBLEM. I tried to put my pictures on a usb flash drive, but im unable to copy and PASTE them, or drag them anywhere! I then thought MAYBE I could burn them using nero, but I'm unable to even open nero I keep getting "an ERROR using COM/OLE.exe occurs. Please check installation of COM on your computer." I cant even get nero to run properly.
Please Help I really dont want to lose my pictures!You don't want to transfer potentially infected files. Download and run a boot TIME av.

887.

Solve : putting an infected widows xp hard drive into a new widnows 7 laptop?

Answer»

hi i was WONDERING if you can help me,, my OLD toshiba windows xp LAPTOP is infected with somekind of virus, it wont even let me enter the safe set up mode when you switch it on,, the laptop is old but i have got a LOT of music and photos on it id like to save.
i went out and got a new toshiba windows 7 laptop which is fully protected with norton 360..

can i put the old hard drive from my windows xp laptop into my new fully protected windows 7 laptop???
will the new laptop pick up and erase the virus or will the virus spread to my new computer???

you help is much appreciated
thanks...Just installing the drive will not cause the MALWARE infection to spread, but if you copy any files over........

What I suggest you do is download and run a boot time av on the infected system.forgot to say,, when i switch on my old laptop it wont even load up windows, it wont let me access the safe mode set up..
it says windows had to shut down.... Quote from: Allan on DECEMBER 22, 2009, 05:50:38 AM


What I suggest you do is download and run a boot time av on the infected system.
hey allan thanks for gettin back to me,,
ive switched on my old lappy and now im not even getting a load up screen,, its just black....
i can hear the system working but nothing on the screen at all,,,,,

if i put my old hardrive in my new system and do a norton 360 scan on it will it clear the problems on it??

No way to know. Go ahead and try.

Again, I'd run a boot time scan with the drive right where it is.id have done as you says but i cant get into my old lappy...
ok ill have a go and see what id does and says, ill let you know later on.
thanks,You are booting to a cd, not the HD. As long as the cd drive is at the top of the boot order in bios there should be no problem booting to the cd and running the scan.
888.

Solve : Being attacked by viruses :(?

Answer»

Any help at all would be amazingly appreciated. I'm experiencing alot of popups, my antivirus (WEBROOT AntiVirus with Spyware) keeps telling me things with weird names (like Mal/Generic-A) are trying to access files on my computer, I always choose "block action". And each new antivirus sweep brings a plethora of fun new "Risk warning: 5/5" viruses and trojan horses, even when they're within 5 minutes of eachother. I have no idea where these would have come from.

I can provide ANY information necessary, and I would love an expert's help. Thank you in advance.Go here EDITED and RUN the tool. If this tool FIND any infection it will remove it. If your antivirus software was running and failed to block the virus, uninstall it then go here EDITED and install this free antivirus software, Highly recommended!The first thing I will NEED you to do is to go to this link and follow the directions precisely. If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please POST any logs that you can generate.

889.

Solve : Need help to see if a problem is a virus/spyware????

Answer»

This is a home computer with Vista.  Certain apps and parts of websites are not working properly.  Some examples are the Trend Micro Antivirus screen only loads the top bar and can't be run unless in safe mode.  Big fish games client does not load properly, Real Arcade does not load properly (cannot click on anything).  The score across the top of espn.go.com and the advertisement toward the top of the screen do not load but links on the page work.  hotmail.com will not load to access personal email account.  cannot login to goal line blitz website...  When I try to check my work email on Microsoft Office Outlook Web Access I can log in and see who has sent me an email, but I cannot see what the actual email says or compose a new message.  Finally, the inbox page on my facebook account will not show anything. 

It is almost like certain websites are acting like they would when I use a proxy to access facebook through a firewall at work.  I honestly don't know what to do.  I have attached the logs requested. 

[Saving space, attachment deleted by admin]You're running Hijackthis from Safe Mode, which means all processes that may be running in Normal mode will not be displayed in this log. Unless you're unable to boot into Normal mode we suggest running Hijackthis from there to get a full listing of programs running on the computer.

the above is part of the report on your hjt log

btw , what anti-virus have you got

right click the hjt icon on screen and rename it to snipper.exe and then run itI will try that when I get home and Post the new log.  What about the other 2?  Was it ok to run them in safe mode?  I was running the Super Anti-spyware in normal mode and it got to a point where it would just keep showing that it was scanning the same files over and over so that's why I ran them in safe mode.  they look fineOk it will probably be around 4-5 pm central time.  (About 3 hours from now)Here is the Hijack log run in normal mode.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:10:30 PM, on 12/22/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - RES://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (MSN Games – Matchmaking) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Mystery%20P.I.%20-%20Lost%20in%20Los%20Angeles/Images/stg_drm.ocx
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gsn.worldwinner.com/games/v47/shared/FunGamesLoader.cab
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) - http://www.worldwinner.com/games/v50/tpir/tpir.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (MSN Games – Game Chat) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) - http://zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WOF Control) - http://www.worldwinner.com/games/v57/wof/wof.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mystery%20P.I.%20-%20The%20Vegas%20Heist/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-us.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Software UPDATER (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision DEVELOPMENT, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

--
End of file - 10232 bytes

890.

Solve : the application can't be executed?

Answer»

HELP!  I am also getting the message, "the application cannot be executed.  The ...... file is infected.  Do you want to activate your antivirus?"  My antivirus recently expired and I want to download another recommended one - AVAST.  However, I can't get online to download it no matter how I try.  The message tells me it is unsafe to do so and won't let me do anything.   I read the two other entries on this same subject and the posts from Super Dave.  Wasn't sure I might be able to solve my problem in a similar way and need more advice.  Would appreciate any help!  THANKS!
have you access to another pc/laptopI have access to my mac laptop but my other computer that I'm having problems with is a Dell pc so they aren't compatible-right?Doesn't matter. Download Avast to your Mac, transfer it via usb drive or cd to the Dell, and run a scanThanks. I will try that right now and let you know. Quote from: Allan on January 03, 2010, 08:58:53 AM

Doesn't matter. Download Avast to your Mac, transfer it via usb drive or cd to the Dell, and run a SCAN

thanks allan , thats why i asked the question for that to be done  Allan and Harry,
When I download the Avast, i get this message.
MZêhttp://www.free-av.com/

try this insteadI tried downloading the new one and got the msg. "This program must be run under Win32." When I downloaded Avast onto my mac the message I got was "can't be run in dos". I think I will go to my son in laws and try downloading avast from his pc onto my usb and then try it on my Dell.  Thanks for your help-I'll be in touch!There is often confusion over exactly what "download" means. MANY people seem to believe that "downloading" something to their PC is installing it. However, it is merely copying it. In this case, you download the AV to your Mac; and then COPY that file to a USB drive for  installation on your PC.

The errors you are receiving are because you are trying to Run it; Macs cannot run WINDOWS software.
891.

Solve : antivirus pc 2010?

Answer»

malwarebytes has removed 5 trojans and or worms but my search engines are being hijacked and can not boot safe mode. JustJoe was on my computer and ran some tech stuff from microsoft and could not find the problem so any info to HELP rid my computer of this virus please before I have to GIVE it back to my boss and IT guy please. I am not against you guys logging on and looking at it.--Thanks-John.pls post a hijackthis log and logs from the programs u ran

and list the trojans u removed

and ur osThe first THING I will need you to do is to go to this LINK and follow the directions precisely. If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you USE a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please post any logs that you can generate.

892.

Solve : Virus on HP Mini?

Answer»

My girlfriend has a nasty virus on her new HP Mini from ATT.  This laptop doesn't have a CD/DVD drive nor does it have any anti-virus software loaded on it.

When turning on the computer, it will boot up Windows XP but the screen will FREEZE after a few minutes of running.  It will not allow me to run Windows explorer so I have no way to get out to the Internet to download any of the links you have posted in "READ this before requesting malware removal help". 

The way she described the first occurance of the virus rearing it's ugly head was...  while on the internet a message popped up that said "Your computer is infected with spyware and you must download Norton Antivirus (i think) to fix the problem".  Unfortanately, she did attempt to download the software but it FROZE up... probably adding more bugs in the virus.

Since I can't get on the Internet to download any of the items you reccomend, can you tell me what I can download from another machine onto a thumbdrive and how to run it... so that I can begin the process of getting some antispyware on it as you suggested and then begin your process of clearing the machine of all malware/spyware.

Thank you so much for your help.  I think this what you are doing here is an awesome service and will reccomend you to all my buddies!

gregtry this below

Download a boot time anti virus scanner (pick one: http://www.google.com/search?hl=en&rlz=1T4GGLL_enUS304US305&ei=WHFCS-DZLMW8lAeTsP2fBw&sa=X&oi=spell&resnum=0&ct=result&cd=1&ved=0CAYQBSgA&q=download+boot+time+av+scanner&spell=1). Burn it to a cd and put the cd in the infected computer. Make sure the cd is at the top of the boot order in bios, then boot to the cd and run the scan.

the above by the way of allanThis particular laptop doesnot have a cd/dvd drive.  Can I put this download on a thumbdrive and boot from the thumbdrive?I tried downloading a number of free anti spyware packages onto a thumb-drive and then cut/paste them to the hard drive on the HP mini... but can't get any of them to run... including the three packages that your website recommends.  Do I have any options other than purchasing an external cd/dvd (usb) drive and loading software via that drive?  Is there any options on using the thumbdrives to get some anti-spyware software to work on this HP mini??you could try and download to a  memory stick or memory pen Go to this link to CREATE a Rescue CD or to this site to create a Rescue USB. Carefully follow all the instructions for whichever method you choose.

893.

Solve : "The file wuauclt.exe infected"?

Answer»

Hi there
MERRY CHRISTMAS.
After booting the machine, I'm getting pop-up messages, constantly, every 10sec, "Application cannot be executed. The file wusuclt.exe is infected. Do you want to ACTIVATE your antivirus SOFTWARE now?" also there is another popup, "Antivirus software alert, Infiltration alert.....
I can run mozilla FF, but cannot seem to be able to run Windows System applications, like add-remove programs.
i'm a beginner in computers, so could you please HELP.what os do u have? when did this start?  what antivirus /malware programs are u running?

can u post a hijackthis log for people to reviewThe first thing I will need you to do is to go to this link and follow the directions precisely. If you can't access the INTERNET with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I PREFER a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. INITIALLY, I will need the SuperAntiSpyware, MBAM and HJT logs. Please post any logs that you can generate.

894.

Solve : HELP ME.. PLZ.?

Answer» HI..I have got my system caught by virus.it is repeatedly showing message "do U want to delete this file"? can any body HELP me?First off, if you can, follow these instructions carefully and post the THREE logs required. Then an expert (not me) will be able to help you.
895.

Solve : spyware dll errors?

Answer» [email protected] as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=7.00.6000.21148 (vista_ldr.091027-0032)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=ec0ef99030fbdf42b2956b6a58aba2c5
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2009-12-25 07:42:06
# local_time=2009-12-25 01:42:06 (-0600, CENTRAL STANDARD Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 81144 81144 0 0
# compatibility_mode=7425 16777173 50 77 85692 52394476 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=61932
# found=2
# cleaned=2
# scan_time=6927
C:\Documents and Settings\Owner\DoctorWeb\Quarantine\424e2ccf-18631347   probably a variant of Win32/Agent trojan (deleted - quarantined)   00000000000000000000000000000000   C
C:\System Volume Information\_restore{243C606D-D9F2-4350-B49B-9B1C3B729F3C}\RP1\A0000231.sys   a variant of Win32/Rootkit.Kryptik.AF trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
Nothing there to worry about. Time to finish up.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I recommend you keep SUPERANTISPYWARE and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any SIGNIFICANT amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.thank you
896.

Solve : malicious websites?

Answer»

If you go to a website and you get one of those pop-ups (that looks like it's from your Operating System) SAYING that you need to install some anti-virus software (which I know is a virus) does that mean the website itself is malicious? 

Can hackers use other peoples websites to attempt this kind of attack?  Or would it be more probable that the website itself is malicious?When you say that the website is malicious, what do you mean exactly? That it uses a browser exploit?It could be that, but what I meant is more generalized...  What I mean is, any website set up by a HACKER that looks as if it provides some basic or convenient service, but it is really there so the hacker can attempt to gather information about you or do whatever else hackers do, such as what you said...  Or, use the website to trick you into installing some anti-virus software that, not only you don't need, but is really as trojan horse..Well, unless the site uses a browser exploit against you, it can't download anything without you saying yes.I'll ask my question in another way..

I went to this website: 

www.christianforums.com

I don't recall when exactly it happened, but when I was on that website, I GOT what looked like an urgent MESSAGE from Windows Vista, saying that it has detected a virus and that I need to download some anti-virus software, and it gave me a "yes" or "no" option.  I usually open up task manager and kill it that way, because most of the time, it doesn't matter if you click on "yes" or "no", simply clicking on the Window will download the software/virus...

Based on this, does this mean that the website is likely built by a hacker, or could it be a legitimate website that a hacker is taking advantage of, somehow..

I read somewhere before... I don't remember where, but people can use public servers to host there web sites for free, and hackers can take advantage of those situations... I thought this might be the case...   If I knew more about website hosting/building I might be able to explain it better...Nothing happens when I view the page. I tried both firefox and IE just to make sure. IE complains of a syntax error, but I don't think that's relevant.

In any case, to answer your question, if you get that popup, there is no reason to trust the site that it's on; if there is any doubt, you can try to contact the administrator/webmaster and tell them about it, since it's possible that the server password was cracked/guessed, By somebody else who put said software on it.

It's also possible that your own PC is infected in some fashion; especially if you were using IE to view the page. I'd Double-check that before bothering the webmaster of the site, too.Try the link now,...    There was a typo in it...


I'll run some scans on my system....and thx for the advice Quote

Try the link now,...    There was a typo in it...
I don't see anything. Must be your PC...... Quote from: EEVIAC on January 03, 2010, 05:01:34 PM
Try the link now,...    There was a typo in it...

I noticed that already
897.

Solve : Best antivirus for new laptop??

Answer»

Hello. I've been dealing with viruses on my PC for the last few months.  I recently purchased an HP dv7t laptop.  I want to give it the best protection against what is out there.  Right now, I've got Zone Alarm on it (we already had ZA on the PC).  Is there something I can add (like SASW, MBAM, SpyWare Blaster) to make it more secure?  Does anyone know a little about Security Task Manager ?You want a GOOD anti virus utility. I use Kaspersky, but there a bunch of good ones (Avira, Avast, Nod, NORTON, etc). Pick one, install it, keep it updated, and make sure it is resident AT ALL TIMES. Don't let anyone tell you the one he or she uses is "best" (we always want to think what we do is right). Just go with a name brand.

Install Spyware Blaster for passive protection. Update it weekly and enable it for all installed browsers.

Run MalwareBytes or Super AntiSpyware weekly

Don't open email attachments from ANYONE unless you are certain you know what they are

Pay attention to what you are doing and to where you are browsing.You do understand that ZoneAlarm is not an anti-virus?  Besides the ones suggested, there is also AVG Free, which I use on one computer (and Avira Personal on the other).Also MicroSoft Security Essentials. Free to registered users. Quote from: Computer_Commando on DECEMBER 23, 2009, 04:37:58 PM

You do understand that ZoneAlarm is not an anti-virus? 

Depends on what version. ZoneAlarm Internet Security is a full security suite. Antivirus, firewall, antispyware plus all of the extras. http://www.zonealarm.com/security/en-us/zonealarm-computer-security-suite.htm Quote from: evilfantasy on December 23, 2009, 05:11:28 PM
Depends on what version. ZoneAlarm Internet Security is a full security suite. Antivirus, firewall, antispyware plus all of the extras. http://www.zonealarm.com/security/en-us/zonealarm-computer-security-suite.htm
If that's what the OP had, they wouldn't be asking for an anti-virus, would they?Also, many old AV programs ...
will work on new laptops!   
http://free.avg.com/us-en/homepage Quote from: SuperDave on December 23, 2009, 05:07:39 PM
Also MicroSoft Security Essentials. Free to registered users.

I agree with SuperDave. Quote from: Computer_Commando on December 23, 2009, 05:35:12 PM
If that's what the OP had, they wouldn't be asking for an anti-virus, would they?

Just keeping things factual. They seem confused because they are asking about AV's but mentioning antimalware software.

Quote from: TriciaM on December 23, 2009, 04:14:18 PM
 Is there something I can add (like SASW, MBAM, SpyWare Blaster) to make it more secure?

Also Security Task Manager is a good program. Though I prefer Autoruns and Process Explorer.Sorry for the confusion. I have ZA Extreme right now on my laptop.  I'll try to be clear........The reason I'm concerned about JUST having Zone Alarm Extreme is that I had Zone Alarm (the regular version) on my desktop, and it didn't seem to STOP much from coming in.  Had a lot of virus problems.  Now that I have a new laptop I wanted to make sure that it is properly protected. I do realize now that the previous Zone Alarm that we had was probably not the true antivirus program (I may be using the wrong terms here.) that we have now.  I wanted to also ask about using malware/spyware detecting programs in addition to the Zone Alarm Extreme.  i would sugges microsoft security essentials. it is free, small file and very effective.
the best part of it is it will never slow down ur systemZone Alarm Extreme has everything plus some extra protection not offered by most paid security software. ZA has been around for a long time now and has passed the TEST of time. Nothing is bulletproof.

In addition to that. Sensible surfing and downloading is all that's required. I run very little as far as antivirus/antimalware is concerned and I visit a bunch of websites looking for information on malware. Haven't gotten infected, accidentally ANYWAY, in years.Thanks for the info.   My children will not have access to my laptop, so I have the feeling that most of those problems will stop. avira premium suite(paid one)
take less resourses,never slow down pc,detection rate number one in this whole world,firewall,webguard,mail guard are awesome,

or u can go with eset nod32
898.

Solve : Hijack Log Help?

Answer»

Hello all...I think I followed all the steps of Malware, Spyware, CCleaner, Java updates.....etc and this is what I have.  Please let me know if I am okay at this point, and thanks so much for the WORK you all do !

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:03:00 PM, on 1/3/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdxserv.exe
C:\WINDOWS\system32\lxdxcoms.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Roxio\Easy CD CREATOR 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\Sniper\Sniper.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll (file missing)
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [lxdxmon.exe] "C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe"
O4 - HKLM\..\Run: [lxdxamon] "C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /STARTUP
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\SYSTEM32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; .NET CLR 2.0.50727)" -"http://games.gamesxl.com/6a0807c830b8678509c13917d4600ba1/game.php?file=687474703a2f2f67616d65732e67616d6573786c2e636f6d2f36613038303763383330623836373835303963313339313764343630306261312f313235302e646372&width=100%&height=100%&gamesxl=1&cr=1&ovrprldr=1"
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted IP range: 64.127.104.144
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5121243D-9CF3-41A5-926C-398F7C124993} - http://69.50.182.94/1/gdnUS1735.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1231631880312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231631865156
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37670.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - c:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Unknown owner - C:\Program Files\Norton Internet Security\ISSVC.exe (file missing)
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxdxCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdxserv.exe
O23 - Service: lxdx_device -   - C:\WINDOWS\system32\lxdxcoms.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools RESEARCH Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Windows Defender Service (WinDefend) - Unknown owner - C:\Program Files\Windows Defender\MsMpEng.exe (file missing)

--
End of file - 17652 byteswould you please post the sas and mbam logs

899.

Solve : Help with viruses, malware, trojans, ect please?

Answer» Got it fixed myself, thanks anyways



Hello everyone, I need some help please. When I try to access the internet, I recieve 302 error messages in my browser or I am sent to some random webpage. When I click CNTRL ALT DLT I get an error message that the task manager has been disabled by the adminstator.

I ran some programs and have the log files below.

Thanks in advance for any help.

Quote
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/22/2009 at 09:04 PM

Application Version : 4.32.1000

Core Rules Database Version : 4379
Trace Rules Database Version: 1978

Scan type       : Complete Scan
Total Scan Time : 03:21:05

Memory items scanned      : 377
Memory threats detected   : 0
Registry items scanned    : 6867
Registry threats detected : 24
File items scanned        : 202159
File threats detected     : 19

Rootkit.Agent/Gen-DiskFake
   HKLM\System\ControlSet001\Services\ndisdrv
   C:\WINDOWS\SYSTEM32\NDISDRV.SYS
   HKLM\System\ControlSet001\Enum\Root\LEGACY_ndisdrv
   HKLM\System\ControlSet001\Services\winsts
   C:\WINDOWS\SYSTEM32\WINSTS.SYS
   HKLM\System\ControlSet001\Enum\Root\LEGACY_winsts
   HKLM\System\ControlSet002\Services\ndisdrv
   HKLM\System\ControlSet002\Enum\Root\LEGACY_ndisdrv
   HKLM\System\ControlSet002\Services\winsts
   HKLM\System\ControlSet002\Enum\Root\LEGACY_winsts
   HKLM\System\ControlSet003\Services\ndisdrv
   HKLM\System\ControlSet003\Enum\Root\LEGACY_ndisdrv
   HKLM\System\ControlSet003\Services\winsts
   HKLM\System\ControlSet003\Enum\Root\LEGACY_winsts
   HKLM\System\ControlSet005\Services\ndisdrv
   HKLM\System\ControlSet005\Enum\Root\LEGACY_ndisdrv
   HKLM\System\ControlSet005\Services\winsts
   HKLM\System\ControlSet005\Enum\Root\LEGACY_winsts
   HKLM\System\ControlSet006\Services\ndisdrv
   HKLM\System\ControlSet006\Enum\Root\LEGACY_ndisdrv
   HKLM\System\ControlSet006\Services\winsts
   HKLM\System\ControlSet006\Enum\Root\LEGACY_winsts
   HKLM\System\CurrentControlSet\Services\ndisdrv
   HKLM\System\CurrentControlSet\Enum\Root\LEGACY_ndisdrv
   HKLM\System\CurrentControlSet\Services\winsts
   HKLM\System\CurrentControlSet\Enum\Root\LEGACY_winsts

Trojan.Agent/Gen
   C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\scandisk.lnk
   C:\WINDOWS\SYSTEM32\RUMEPOPO.DLL.VIRUS

Trojan.Unknown Origin
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{AD2ACBBD-B800-46EA-85C4-848924B9BE7F}\RP3\A0005223.DLL
   C:\WINDOWS\SYSTEM32\VAWOPIJO.EXE

Trojan.Agent/Gen-Nullo[Short]
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{AD2ACBBD-B800-46EA-85C4-848924B9BE7F}\RP3\A0005224.EXE
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{AD2ACBBD-B800-46EA-85C4-848924B9BE7F}\RP3\A0005229.DLL

Trojan.Agent/Gen-6TO4
   C:\WINDOWS\SYSTEM32\6TO4V32.DLL

Adware.Tracking Cookie
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   F:\Documents and Settings\NetworkService\Cookies\[email protected][1].txt

Trojan.Agent/Gen-WIWOW64
   C:\WINDOWS\SYSTEM32\WMDTC.EXE

Trojan.Agent/Gen-FakeAlert[Calc]
   F:\DOCUMENTS AND SETTINGS\MOM\START MENU\PROGRAMS\STARTUP\SCANDISK.DLL.VIRUS

Quote
Malwarebytes' Anti-Malware 1.42
Database version: 3289
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

12/22/2009 9:25:31 PM
mbam-log-2009-12-22 (21-25-31).txt

Scan type: Quick Scan
Objects scanned: 110706
Time elapsed: 4 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 12
Registry Data Items Infected: 10
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fastnetsrv (Backdoor.Refpron) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BtwSrv (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_BTWSRV (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_FASTNETSRV (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\buildw (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\firstinstallflag (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\updatenew (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mbt (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udfa (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mfa (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\winlogon86.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d05fc09a-3459-4dcc-bdde-77b43dbc76a3}\NameServer (Trojan.DNSChanger) -> Data: 193.104.110.38,4.2.2.1,68.94.156.1 68.94.157.1 -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\notepad.dll.virus (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\FastNetSrv.exe.virus (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\SystemProfile\ntload.dll.virus (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.


Quote
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:36:24 PM, on 12/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Internet\Avast\aswUpdSv.exe
C:\Internet\Avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Internet\Avast\ashMaiSv.exe
C:\Internet\Avast\ashWebSv.exe
C:\Internet\Avast\ashDisp.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Documents and Settings\mom\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Documents and Settings\mom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\mom\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qnntv.com/aspx/qnn/default.aspx
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] C:\Internet\Avast\ashDisp.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [SansaDispatch] C:\Documents and Settings\mom\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\mom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKLM\..\Policies\Explorer\Run: [pyomiwwxv] rundll32 "C:\WINDOWS\system32\rpcns4C.dll",Dbrtccocg
O4 - HKUS\S-1-5-21-329068152-813497703-1957994488-1004\..\Run: [SansaDispatch] C:\Documents and Settings\mom\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (User '?')
O4 - HKUS\S-1-5-21-329068152-813497703-1957994488-1004\..\Run: [Google Update] "C:\Documents and Settings\mom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (User '?')
O4 - HKUS\S-1-5-18\..\Run: [notepad] rundll32.exe C:\DOCUME~1\LOCALS~1\ntload.dll,[email protected] (User '?')
O4 - HKUS\.DEFAULT\..\Run: [notepad] rundll32.exe C:\DOCUME~1\LOCALS~1\ntload.dll,[email protected] (User 'Default user')
O4 - S-1-5-21-329068152-813497703-1957994488-1004 Startup: toolbar.lnk = C:\Download\toolbar\toolbar.exe (User '?')
O4 - Startup: toolbar.lnk = C:\Download\toolbar\toolbar.exe
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: ADD to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: SUN Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/move/06071909/qsp2ie06071909.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: \wisahiri.dll lorizuzu.dll c:\windows\system32\rumepopo.dll c:\windows\system32\kiyituhe.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: boweneyar - {0d3228ce-d891-4152-a99f-1614b23d4a54} - c:\windows\system32\wisahiri.dll (file MISSING)
O21 - SSODL: walufayij - {7a70e709-6cc5-4ba8-bf7b-e09adedde6ff} - c:\windows\system32\rumepopo.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {0d3228ce-d891-4152-a99f-1614b23d4a54} - c:\windows\system32\wisahiri.dll (file missing)
O22 - SharedTaskScheduler: tokatiluy - {7a70e709-6cc5-4ba8-bf7b-e09adedde6ff} - c:\windows\system32\rumepopo.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Internet\Avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Internet\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Internet\Avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Internet\Avast\ashWebSv.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

--
End of file - 6433 bytes
900.

Solve : Google sites (and sometimes Yahoo) not working with any browsers?

Answer» OK, done.You should be GOOD to GO with the REST now.