Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

901.

Solve : HiJack This Log Tool not helping?

Answer»

After using this tool twice now, there is one FILE that won't delete. What should I do? BTW, here is my scan:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:55:47 PM, on 12/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\wuauclt.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\PROGRA~1\McAfee\MSC\mcshell.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: McAfee Application Installer Cleanup (0234181261426650) (0234181261426650mcinstcleanup) - McAfee, Inc. - C:\DOCUME~1\Matt\LOCALS~1\Temp\023418~1.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee SCANNER (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe

--
End of file - 4393 bytes
nevermind, I fixed it.

902.

Solve : Riddled with Viruses.?

Answer»

Hi SD,

Please find attached. Hope you and all have a MERRY christmas.

[Saving space, attachment deleted by admin]Problems are back this morning, search engines are impossible to use as Im just getting redirected all over the place. AVG says a Exploit Rogue spyware scanner (type 504) has been found. All in all it seems pretty unstable also, ive had 2 crashes alone this morning.Ok Mackem. Let's try this again:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
pxfzdgdb

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

Update and run SAS and MBAM again. Post the logs and also a new HJT logHi SD,

Took me 4 attempts to get through the SuperAnti scan without getting a blue error screen, but i half all logs of which will hopefully be attached.

All the best.

[Saving space, attachment deleted by admin]Hello Mackem1983. Let's try this:

Go to Start > Run, and copy/paste the following into the Open box (one line at a time) then Click OK after each.

Code: [Select]sc config pxfzdgdb start= disabled
Code: [Select]sc stop pxfzdgdb
Code: [Select]sc delete pxfzdgdb
Could you please run another ESET scan as indicated in Reply # 5 and paste the results here?
Also let me know how your computer's running.

My computer is terrible to be honest SD, its never bee worse. Crashes are frequent, no games work for more than half an hour. Im trying to get the es scan done but it continues to freeze after an hour or so. Im quite concerned  Hello Mackem1983. I'm sorry to hear that things aren't improving. Let's remove ComboFix and I'll try to think what to do next.Sometimes scanners and computers don't get along. When you get a BSOD do you recall what the error is?

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

HI SD,

I have inputted the code's given and uninstalled combofix, I apprieciated your continued suport. I did store a log of the bsod error's but they seem to have gone , i remember it being at least 2 different messedges. However since this morning i have not been getting bsod, just freezing/crashing constantly, what ever i have done recently it certainly doesnt agree with my games as they run for a maximum of 3 0 mins before the system freezes. Also it might be irrelevant but in the bottom right of the windows screen my < sign has gone.

Cheers buddy.Hi Mackem1983. I checked with my mentor and we both agree that your problem now is related to Software or Hardware and not an infection. I would advise you to start a new thread in this forum and perhaps someone with tech knowledge will be able to help you out. Here are some helpful HINTS to keep clean.

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- SECURE your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hi SD,

It does appear to me as if something has gone wrong somewhere with the hardware (drivers or something), however I definatly still have a trojan vundu in the system restore art and its only become this way by trying to remove it.

I remember at the start we did a combo fix and it created back up of which i could select while loading up, if i was to use that would it take my COMP back a week? Because at the moment I still have the trojan, but far worse my sytem is unstable. Quote

however I definatly still have a trojan vundu in the system restore

System Restore was cleared by uninstalling ComboFix.

Quote from: SuperDave on December 20, 2009, 12:48:13 PM

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.


Im not really sure of the point of that, was it no it will not help to try to make my computer work again?We have suggested that you post in this forum to deal with the BSOD. We do malware removal here.Hi folks,

I have restored my system to the original state and it seems well, however it was suggested to me that i post on here to find any information on how was the best way to go about checking if anything bad had stayed on here.
903.

Solve : please check my logs...blue screen problem !?

Answer»

I've had virus/computer SLOWNESS problems on and off for the last few months.  Yesterday, upon scanning using MBAM, computer gets the blue screen with the "your computer has recovered from a serious error" message.  This happens at the point of the scan where MBAM is scanning "zpeng25.dll" .  Here is my SASW log.  The next two to follow....Thanks !SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/22/2009 at 12:48 PM

Application Version : 4.32.1000

Core Rules Database Version : 4402
Trace Rules Database Version: 2235

Scan type       : Quick Scan
Total Scan Time : 00:46:36

Memory items scanned      : 603
Memory threats detected   : 0
Registry items scanned    : 910
Registry threats detected : 0
File items scanned        : 39218
File threats detected     : 14

Adware.Tracking Cookie
   C:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][1].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
   c:\documents and settings\tricia & roger\cookies\tricia_&[email protected][2].txt
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:05:24 PM, on 12/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\SYSTEM32\Brmfrmps.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\Program Files\AppStream\WindowsClient\bin\AppMgrService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AppStream\WindowsClient\Bin\AppMgrGui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\TiVo\Desktop\TiVoServer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Trend Micro\Sniper.exe\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ACTIVEX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - (no file)
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [AppMgrGui] C:\Program Files\AppStream\WindowsClient\bin\exeForService.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry /auto:TivoServer
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Tricia & Roger\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\SYSTEM32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103472 -"Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.16) Gecko/2009120208 Firefox/3.0.16 (.NET CLR 2.0.50727)" -"http://www.neopets.com/games/dgs/play_shockwave.phtml?va=&game_id=473&nc_referer=&age=0&hiscore=&sp=0&questionSet=&r=6256101&width=600&height=440&quality=high"
O4 - HKUS\S-1-5-18\..\RunOnce: [TBInfo] iexplore.exe "http://www.earthlink.net/go/elnktoolbarinstall" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TBInfo] iexplore.exe "http://www.earthlink.net/go/elnktoolbarinstall" (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy CONFIGURATION - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://support.broderbund.com
O15 - Trusted Zone: http://smartdownload.riverdeep.net
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5DA9D8E0-5A57-11CF-9E36-00C0930198C0} (Pegasus ImagN' 32-bit (Windowed) ActiveX Control v4.00) - http://www.ansonncrod.org/imw32o40.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136246925750
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidctl_vsp.closetmaid.com_downloader.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9841D1AE-9C0B-11D3-9452-00105A098C21} (Pegasus PrintPRO Control v2.0) - http://www.ansonncrod.org/prntpro2.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.38.50/ttinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ASWLNDLL - C:\WINDOWS\SYSTEM32\ASWLNDLL.dll
O23 - Service: AWE 5.1.0 Application Manager (AppMgrService) - AppStream Inc. - C:\Program Files\AppStream\WindowsClient\bin\AppMgrService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\SYSTEM32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ZoneAlarm ForceField IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

--
End of file - 13439 bytes
I'm not able to run the MBAM without the bluescreen interruption.Also, HJT says that I do not have antivirus protection on my computer. I have Zone Alarm.

904.

Solve : Big Maleware Prob - Green Desktop - fake msg ....?

Answer»

Hi! i got a big problem with my homepc with xp on it. I got a new acer pc with preinstalled mcafee on it and with windows firewall. i also got servicepack 3.
this happend in order of apperance:

-browser closed
-green background appeard on desktop
-faked marked icons appeared
-faked VIRUS message
-red dot at the RIGHT side of the taskbar with a X in it. by clicking on it they want to sell me something like internet security 2010 (didnt bought anything)
-task manager was blocked
-cant install any programms
-regedit was blocked
-macafee scan -> 2 founds (dont have any logs)
-INSTALLED spyhunter and scanned my pc
-then i've done the "do-first-steps" which are sticky in this forum
-after doing all the steps my task-manager works also regedit
-desktop isnt green anymore - the red x-ed dot vanished - no more virus msg
-BUT mcafee tells something about "pufferüberlauf" in GERMAN which means "pufferoverflow" i guess
-at startup a errormsg appear "memcheck.exe - an application caused an exceptional error, which cant be SOLVED - Prozess-Id=0x428 (1064), Thread-ID=0x42c (1068)" (i translate the error msg by myself)
-my firefox cant load any websites - it said 'finished' at the bottom but the contentframe remain white
-ie also tells me 'website cant be displayed' (the normal 'no-connection' msg)

i hope u could help me
i've added the required log, too




[Saving space, attachment deleted by admin]

905.

Solve : ComboFix found 2 problems - OG prob: userinit login closed by DEP?

Answer»

Here is another more thorough description. http://vil.nai.com/vil/content/v_139473.htm

another difficulty is that, even after RUNNING the removal tool and having what appears to be a clean system, if there is a single infected file, running it will simply reinfect everything else- so as far as removing it, it's all or nothing, which is why reformatting/reinstalling is the only way to be assured it's gone.

Yeppers, polymorphic. A real B*tch!

A scanner just can't isolate them fast enough before it GRABS hold of another file.OK here is where I am now.

I ran all of the software you two suggested and REMOVED even more problems. Since Avast seemed to have a good idea of what the virus was I decided to download and install their Professional version of Anti-Virus software. It rebooted the system and ran a scan before windows starts so that nothing could be running except for it and the kernel.

Upon running it found more Virut and added to the mix JunkPoly. After doing some searching on JunkPoly I found numerous accounts of people researching that problem to IP addresses in China. So I am figuring that CHINESE IP I was connected to was PART of this virus.

The scan is still going. It scans all of the drives and my USB drives are over 300 gigs each with one being filled.

As far as windows updates go, they install now without incident.

Once Avast is done running I plan to run it again and recheck for virut. If it is still finding yet more of it, I will format. The biggest problem is that my USB drives contain backups of all of my data and lots of executables on them were infected. So now I think I will have to delete everything with .exe and perhaps even .dll and go from there.

Thanks to everyone that has helped thus far!

------------------------------------------------------------------------------------

All seems well.. But for peice of mind I will be formatting the HD and deleting all of my software from every drive. I don't feel like doing this all again after I finally do get my PC completely set up. I did get a lot of good info and am confident this type of infection won't happen again for me.  I also got a lot of links to some great software I plan to install as soon as my PC comes back up.Install a good firewall also. Comodo is very good and free.

906.

Solve : userinit login closed by DEP?

Answer»

How does ONE get logged on to FIX this? Windows just goes to the USER screen. Once clicked on, it just goes from LOGGING on to logging off... Welcome to CH.

I moved this to a new topic.

If this is the same virus as the other thread then the answer is short and simple.

There is no answer to this virus other than a clean install.

907.

Solve : Spybot Blocked?

Answer»

Quote from: diggerdave on February 11, 2009, 04:27:34 PM

I haven't had zone alarm security suite running for at least 6 months. I am running the free zone alarm fire wall. Seems to be running well.

OK, it must be seeing the security center as having the Security Suite installed. No problem.

--

You are going to have to remove the CRACKS & Keygens before I can continue helping.

Download the OTMoveIt3 by OldTimer

Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As ADMINISTRATOR.

* Save it to your Desktop.
* Double-click OTMoveIt3.exe to run it.
* Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

Code: [Select]:Processes
explorer.exe

:files
C:\DOCUME~1\David\Application Data\uTorrent\Adobe Acrobat 9 PRO Extended + Crack (PTB-ITA-ESP-NL) (iso).rar.torrent
C:\DOCUME~1\David\Application Data\uTorrent\ConvertXtoDVD-V3 DivX-V6 Nero-V8 WinRar-V3-Full PATCH And Keygen's -2-  MAXIMODIS.zip.torrent
C:\DOCUME~1\David\Application Data\uTorrent\keygen.exe.torrent
C:\DOCUME~1\David\Application Data\uTorrent\Nero 9 Ver. C Iso + Cracks & Apps.rar.torrent
C:\DOCUME~1\David\Application Data\uTorrent\Nero 9. Ultra NEW RELEASE Including+Keygen Valildation Crack.rar.torrent
C:\DOCUME~1\David\Application Data\uTorrent\nero_8_keygen__serials_reg__activation.rar.torrent
C:\DOCUME~1\David\Application Data\uTorrent\RegCure 1.5 with crack.rar.torrent

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

* Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
* Click the red Moveit! button.
* Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTMoveIt3

Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.Here's the log:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder C:\DOCUME~1\David\Application Data\uTorrent\Adobe Acrobat 9 Pro Extended + Crack (PTB-ITA-ESP-NL) (iso).rar.torrent not found.
File/Folder C:\DOCUME~1\David\Application Data\uTorrent\ConvertXtoDVD-V3 DivX-V6 Nero-V8 WinRar-V3-Full Patch And Keygen's -2-  MAXIMODIS.zip.torrent not found.
File/Folder C:\DOCUME~1\David\Application Data\uTorrent\keygen.exe.torrent not found.
File/Folder C:\DOCUME~1\David\Application Data\uTorrent\Nero 9 Ver. C Iso + Cracks & Apps.rar.torrent not found.
File/Folder C:\DOCUME~1\David\Application Data\uTorrent\Nero 9. Ultra NEW RELEASE Including+Keygen Valildation Crack.rar.torrent not found.
File/Folder C:\DOCUME~1\David\Application Data\uTorrent\nero_8_keygen__serials_reg__activation.rar.torrent not found.
File/Folder C:\DOCUME~1\David\Application Data\uTorrent\RegCure 1.5 with crack.rar.torrent not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\David\LOCALS~1\Temp\etilqs_QcjCX8zRcMQq3Ps9d45X scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\David\LOCALS~1\Temp\etilqs_QcjCX8zRcMQq3Ps9d45X-journal scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\David\LOCALS~1\Temp\etilqs_u59Ra7VKA7IFF7KLQAw4 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\David\LOCALS~1\Temp\~DF9103.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\gnserv.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_770.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\spnserv.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\spserv.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT06db8.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\msin5iya.default\OfflineCache\index.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\msin5iya.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\msin5iya.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\msin5iya.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\msin5iya.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\msin5iya.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
 
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02112009_154245
Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixLog attached

[attachment deleted by admin]Everything looks OK.

How is the computer running now?It's taking well over a minute at boot up to get from the post to the memory check.Has this just started happening?

Yes. I believe it started after running OTMoveIt3.All that did was remove temporary files. Everything else said "Not found."

Try Dial-a-fix.

Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

  • Open the folder and run Dial-a-fix.exe
  • 2 windows will open. Close the one in the background labeled Restrictive Policies
  • Check the box in section 1, Empty temp folders.
  • Check the box in section 2, Fix Windows Installer.
  • Check the box in section 3, Fix Windows Update.
  • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
  • Check all boxes in section 5, labeled Registration Center.
  • Click Go
  • OK any error messages if received, but write them down and post them here.
  • Restart the computer when done.
.
How is it now?Dial-a-fix has been stuck on the same task for about an hour and a half.Can you see which one it is?Stopping CRYPTSVC...OK stop it and uncheck box 4, labeled SSL/HTTPS/Cryptography

Now run it again please with the other boxes checked.I'm still getting the lengthy delay at boot up.A computer can be slow to start up after cleaning the cache which is what we did when running OTMoveIt. After a few more restarts see if it is still running slow.

We should check for any more malware also as it could be that as well.

Use the Kaspersky Lab Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

  • Click on SCAN NOW
  • Click Accept.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and LET it finish.
.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or something similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save

.
Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
908.

Solve : the middle of my rope?

Answer»

hello ladies and gentlemen
my name is matt. i've been lurking the forums, followed evilfantizes's instructions, but my pc is not up to pre INFECTION speed.

dell lat 620
winxp pro SP2
intel core 2
t7200 2.00 ghz
1.99 gb of ram

it seems like it's gone, but it seems after i got rid of it and ran registry cleaner its seems slower

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:49:09, on 2/17/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\Program Files\JAVA\jre1.6.0_02\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070731
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - RES://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D2349304-8F9E-4A54-ACF6-0F6104B44209} (SketchCtl.Pic1) - http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocx
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 7094 bytes



Malwarebytes' Anti-Malware 1.33
Database version: 1747
Windows 5.1.2600 Service Pack 2

2/12/2009 11:23:23 PM
mbam-log-2009-02-12 (23-23-23).txt

Scan type: Full Scan (C:\|)
Objects scanned: 23444
Time elapsed: 14 minute(s), 12 second(s)

Memory Processes INFECTED: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Avenger\zddyyjvz.sys (Rootkit.Agent) -> Quarantined and deleted successfully.

909.

Solve : NetWork Worm?

Answer»

Hi

I have a worm/virus on my network that KEEPS on locking users account on the domain.

Please HELP I am cluelesshi

I got the worm's name: WORM_DOWNAD.AD and its AFFECTING WINDOWS\system32\gymydbnsi.wy

Please help, this worm is distracting.Start here.

910.

Solve : removing a virus?

Answer» i don't know how to remove a virus without an anti-virus program...
because i think that my computer has some viruses that my anti-virus can't find
plsssss,,help me
Welcome to CH.

Download random's system INFORMATION tool (RSIT) by random/random from and save it to your Desktop.

  • Double click on RSIT.exe to run.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open.
  • log.txt <will be maximized and info.txt <will be minimized
  • Please post the contents of both logs in the next reply.
these are the contents of both logs....


[attachment deleted by admin]Your logs are clean.

Why do you think there is a virus?how did you know that my logs are clean?

could you teach me how to know if my logs are clean?

what are the contents of both logs are all about?


because my computer is running slow,,and when i going to open the command promt.

my computer is shutting down!!!,,my friends said that maybe it has some virus!!About learning, refer here: here.

And then about the "virus" from CMD, it's probably something minor...WHAT kind??? Use the Kaspersky Lab Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

  • Click on SCAN NOW
  • Click Accept.
  • The program will then BEGIN downloading the latest definition FILES.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File NAME area use KScan, or something similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, RESET to 100%.
911.

Solve : PLEASE HELP I have been Hijacked?

Answer»

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Folder::
c:\program files\Winferno\RegistryPowerCleaner

File::
c:\windows\Tasks\rpc.job

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
ok thank you, Here is my new log

ComboFix 09-02-12.03 - Owner 2009-02-14  8:45:02.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.255.105 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
COMMAND switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
 * Created a new restore point
.

(((((((((((((((((((((((((   Files Created from 2009-01-14 to 2009-02-14  )))))))))))))))))))))))))))))))
.

2009-02-12 01:34 . 2009-02-12 01:34      d--------   C:\ca95aaa2e5c16143353336
2009-02-09 10:12 . 2009-02-09 10:12      d--------   c:\windows\Desktop
2009-02-06 01:09 . 2009-02-06 01:16      d---s----   c:\documents and settings\Administrator
2009-02-05 01:45 . 2009-02-05 01:45      d--------   c:\program files\Trend Micro
2009-02-04 21:21 . 2005-09-01 11:03   127,488   ---------   c:\windows\system32\drivers\imagesrv.sys
2009-02-04 21:21 . 2005-09-01 11:03   5,888   ---------   c:\windows\system32\drivers\imagedrv.sys
2009-02-04 15:33 . 2009-02-12 19:41      d--------   c:\program files\MSECACHE
2009-02-04 14:03 . 2009-02-04 13:15   15,688   --a------   c:\windows\system32\lsdelete.exe
2009-02-04 12:58 . 2009-02-04 12:58      d----c---   c:\windows\system32\DRVSTORE
2009-02-04 12:58 . 2009-01-18 16:30   64,160   --a------   c:\windows\system32\drivers\Lbd.sys
2009-02-04 12:56 . 2009-02-04 12:57      d--H-c---   c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-04 12:02 . 2009-01-28 12:06   1,405,680   ---------   C:\WindowsServer2003-KB833167-x86-ENU.EXE
2009-02-04 12:02 . 2009-01-28 12:06   1,081,072   ---------   C:\WINDOWSSERVER2003-KB833167-X86-ENU-Symbols.EXE
2009-02-03 14:10 . 2009-02-03 14:10      d--------   c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-03 12:58 . 2009-02-03 12:56   73,728   --a------   c:\windows\system32\javacpl.cpl
2009-02-03 10:59 . 2009-02-03 10:59      d--------   c:\program files\Java(2)
2009-02-02 15:56 . 2009-02-02 15:56      d--------   c:\windows\ShellNew
2009-02-02 15:55 . 2009-02-02 15:55      d--------   c:\program files\Microsoft ActiveSync
2009-02-02 15:55 . 2009-02-02 15:55      d--------   c:\program files\Common Files\L&H
2009-01-30 20:37 . 2009-02-04 17:27      d--------   c:\windows\system32\NtmsData
2009-01-25 22:52 . 2009-01-25 23:01      d--------   C:\031a77de410c59025efbcd16
2009-01-23 09:28 . 2009-01-23 09:31      d--------   c:\program files\CA Yahoo! Anti-Spy
2009-01-20 17:29 . 2009-02-03 14:12      d--------   c:\program files\QuickTime
2009-01-20 17:23 . 2009-01-20 17:23      d--------   c:\program files\Apple Software Update
2009-01-20 17:23 . 2009-01-20 17:23      d--------   c:\documents and settings\All Users\Application Data\Apple
2009-01-17 21:27 . 2009-01-17 21:27      d--------   c:\program files\CONEXANT
2009-01-14 15:10 . 2001-08-17 13:47   12,928   --a------   c:\windows\system32\drivers\Dot4Prt.sys
2009-01-14 15:10 . 2001-08-17 13:47   12,928   --a--c---   c:\windows\system32\dllcache\dot4prt.sys
2009-01-14 15:09 . 2008-04-13 14:39   206,976   --a------   c:\windows\system32\drivers\Dot4.sys
2009-01-14 15:09 . 2008-04-13 14:39   206,976   --a--c---   c:\windows\system32\dllcache\dot4.sys
2009-01-14 15:09 . 2001-08-17 13:47   23,808   --a------   c:\windows\system32\drivers\Dot4usb.sys
2009-01-14 15:09 . 2001-08-17 13:47   23,808   --a--c---   c:\windows\system32\dllcache\dot4usb.sys

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-13 00:43   ---------   d-----w   c:\program files\Windows MEDIA Connect 2
2009-02-05 21:07   ---------   d-----w   c:\program files\Ahead
2009-02-04 17:55   ---------   d-----w   c:\program files\Lavasoft
2009-02-03 17:56   410,984   ----a-w   c:\windows\system32\deploytk.dll
2009-02-01 14:37   325,128   ----a-w   c:\windows\system32\drivers\avgldx86.sys
2009-02-01 14:37   107,272   ----a-w   c:\windows\system32\drivers\avgtdix.sys
2009-02-01 14:37   10,520   ----a-w   c:\windows\system32\avgrsstx.dll
2009-01-31 01:32   ---------   d-----w   c:\program files\DivX
2009-01-29 07:55   ---------   d-----w   c:\documents and settings\All Users\Application Data\avg8
2009-01-23 15:02   ---------   d-----w   c:\program files\Free Offers from Freeze.com
2009-01-23 14:28   ---------   d-----w   c:\program files\Common Files\Scanner
2009-01-16 21:07   ---------   d-----w   c:\program files\Java
2009-01-06 18:29   ---------   d-----w   c:\program files\LimeWire
2009-01-06 17:55   ---------   d-----w   c:\program files\Real
2009-01-06 17:55   ---------   d-----w   c:\program files\Common Files\Real
2008-12-29 15:01   ---------   d-----w   c:\program files\MSXML 4.0
2008-12-28 02:52   ---------   d--h--w   c:\program files\InstallShield Installation Information
2008-12-28 02:52   ---------   d-----w   c:\program files\Samsung
2008-12-28 02:52   ---------   d-----w   c:\program files\MarkAny
2008-12-20 23:15   826,368   ----a-w   c:\windows\system32\wininet.dll
2008-09-15 09:25   32,768   --sha-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091520080916\index.dat
.

(((((((((((((((((((((((((((((   [email protected]_ 1.57.55.77   )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-04 18:08:14   16,384   -c--a-w   c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-13 03:00:59   16,384   -c--a-w   c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-04 18:08:14   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-13 03:00:59   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-04 18:08:14   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-13 03:00:59   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-14 13:36:55   16,384   ----atw   c:\windows\Temp\Perflib_Perfdata_1ac.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-17 4670704]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [BU]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2008-12-17 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-01-27 1381376]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"LWBMOUSE"="c:\program files\Gigaware\Gigaware Driver\4.06\MOUSE32A.EXE" [2001-11-09 356352]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-01 1601304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SMSTray"="c:\program files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-12-14 132624]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 136600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-04 509784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Billminder.lnk - c:\quickenw\BILLMIND.EXE [2007-07-11 36864]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2007-07-11 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-01 09:37 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-04 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-08-12 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-08-12 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-12 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-12 298264]
R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2007-07-11 34916]
R3 3dfxvs;3dfxvs;c:\windows\system32\drivers\3dfxvsm.sys [2007-07-11 148352]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S3 SMC1211;SMC EZ Card 10/100 PCI (SMC1211 Series) NT 5.0 Driver;c:\windows\system32\drivers\SMC1211.sys [2001-07-11 23153]
.
Contents of the 'Scheduled Tasks' folder

2009-02-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-04 13:14]

2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-02-08 c:\windows\Tasks\rpc.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\mkokt0q1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-14 08:49:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 


**************************************************************************
.
Completion time: 2009-02-14  8:55:10
ComboFix-quarantined-files.txt  2009-02-14 13:53:43
ComboFix2.txt  2009-02-14 13:16:39
ComboFix3.txt  2009-02-12 07:02:10
ComboFix4.txt  2009-02-12 05:54:52

Pre-Run: 13,276,667,904 bytes free
Post-Run: 13,262,733,312 bytes free

165   --- E O F ---   2009-02-12 06:36:29

I don't think you followed the directions correctly. Please try again.Ok Hopefully I did this Right, I had to try it a few times for it to work with out my computer freezing on me, But this time i did it in safe mode and i think it took LOL
Heres my log

ComboFix 09-02-14.01 - Owner 2009-02-15 22:12:53.4 - NTFSx86 MINIMAL
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.255.150 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)

FILE ::
c:\windows\Tasks\rpc.job
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\Tasks\rpc.job
H:\autorun.inf

.
(((((((((((((((((((((((((   Files Created from 2009-01-16 to 2009-02-16  )))))))))))))))))))))))))))))))
.

2009-02-15 19:27 . 2009-02-15 19:34      d--------   C:\32788R22FWJFW(2)
2009-02-15 19:18 . 2009-02-15 19:34      d--------   C:\RECYCLER(2)
2009-02-15 19:17 . 2009-02-15 19:34      d--------   C:\ComboFix(2)
2009-02-12 01:34 . 2009-02-12 01:34      d--------   C:\ca95aaa2e5c16143353336
2009-02-09 10:12 . 2009-02-09 10:12      d--------   c:\windows\Desktop
2009-02-06 01:09 . 2009-02-06 01:16      d---s----   c:\documents and settings\Administrator
2009-02-05 02:38 . 2009-02-05 02:38      d--------   c:\documents and settings\Owner\Application Data\Apple Computer
2009-02-05 01:45 . 2009-02-05 01:45      d--------   c:\program files\Trend Micro
2009-02-04 21:21 . 2005-09-01 11:03   127,488   ---------   c:\windows\system32\drivers\imagesrv.sys
2009-02-04 21:21 . 2005-09-01 11:03   5,888   ---------   c:\windows\system32\drivers\imagedrv.sys
2009-02-04 15:33 . 2009-02-12 19:41      d--------   c:\program files\MSECACHE
2009-02-04 14:03 . 2009-02-04 13:15   15,688   --a------   c:\windows\system32\lsdelete.exe
2009-02-04 12:58 . 2009-02-04 12:58      d----c---   c:\windows\system32\DRVSTORE
2009-02-04 12:58 . 2009-01-18 16:30   64,160   --a------   c:\windows\system32\drivers\Lbd.sys
2009-02-04 12:56 . 2009-02-04 12:57      d--h-c---   c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-04 12:02 . 2009-01-28 12:06   1,405,680   ---------   C:\WindowsServer2003-KB833167-x86-ENU.EXE
2009-02-04 12:02 . 2009-01-28 12:06   1,081,072   ---------   C:\WINDOWSSERVER2003-KB833167-X86-ENU-Symbols.EXE
2009-02-03 14:10 . 2009-02-03 14:10      d--------   c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-03 12:58 . 2009-02-03 12:56   73,728   --a------   c:\windows\system32\javacpl.cpl
2009-02-03 10:59 . 2009-02-03 10:59      d--------   c:\program files\Java(2)
2009-02-02 15:56 . 2009-02-02 15:56      d--------   c:\windows\ShellNew
2009-02-02 15:55 . 2009-02-02 15:55      d--------   c:\program files\Microsoft ActiveSync
2009-02-02 15:55 . 2009-02-02 15:55      d--------   c:\program files\Common Files\L&H
2009-01-30 20:37 . 2009-02-04 17:27      d--------   c:\windows\system32\NtmsData
2009-01-25 22:52 . 2009-01-25 23:01      d--------   C:\031a77de410c59025efbcd16
2009-01-23 09:28 . 2009-01-23 09:31      d--------   c:\program files\CA Yahoo! Anti-Spy
2009-01-20 17:29 . 2009-02-03 14:12      d--------   c:\program files\QuickTime
2009-01-20 17:23 . 2009-01-20 17:23      d--------   c:\program files\Apple Software Update
2009-01-20 17:23 . 2009-01-20 17:23      d--------   c:\documents and settings\All Users\Application Data\Apple
2009-01-17 21:27 . 2009-01-17 21:27      d--------   c:\program files\CONEXANT

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-16 00:55   ---------   d-----w   c:\documents and settings\Owner\Application Data\mjusbsp
2009-02-13 00:43   ---------   d-----w   c:\program files\Windows Media Connect 2
2009-02-05 21:07   ---------   d-----w   c:\program files\Ahead
2009-02-05 07:41   ---------   d-----w   c:\documents and settings\Owner\Application Data\LimeWire
2009-02-04 17:55   ---------   d-----w   c:\program files\Lavasoft
2009-02-01 14:37   325,128   ----a-w   c:\windows\system32\drivers\avgldx86.sys
2009-02-01 14:37   107,272   ----a-w   c:\windows\system32\drivers\avgtdix.sys
2009-01-31 01:32   ---------   d-----w   c:\program files\DivX
2009-01-29 07:55   ---------   d-----w   c:\documents and settings\All Users\Application Data\avg8
2009-01-23 15:02   ---------   d-----w   c:\program files\Free Offers from Freeze.com
2009-01-23 14:28   ---------   d-----w   c:\program files\Common Files\Scanner
2009-01-19 17:33   ---------   d-----w   c:\documents and settings\Owner\Application Data\Yahoo!
2009-01-16 21:07   ---------   d-----w   c:\program files\Java
2009-01-06 18:29   ---------   d-----w   c:\program files\LimeWire
2009-01-06 17:55   ---------   d-----w   c:\program files\Real
2009-01-06 17:55   ---------   d-----w   c:\program files\Common Files\Real
2008-12-29 15:01   ---------   d-----w   c:\program files\MSXML 4.0
2008-12-28 21:40   ---------   d-----w   c:\documents and settings\Owner\Application Data\FrostWire
2008-12-28 02:52   ---------   d--h--w   c:\program files\InstallShield Installation Information
2008-12-28 02:52   ---------   d-----w   c:\program files\Samsung
2008-12-28 02:52   ---------   d-----w   c:\program files\MarkAny
2008-12-28 02:52   ---------   d-----w   c:\documents and settings\Owner\Application Data\DataCast
2008-09-15 09:25   32,768   --sha-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091520080916\index.dat
.

(((((((((((((((((((((((((((((   [email protected]_ 1.57.55.77   )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-04 18:08:14   16,384   -c--a-w   c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-13 03:00:59   16,384   -c--a-w   c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-04 18:08:14   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-13 03:00:59   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-04 18:08:14   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-13 03:00:59   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-06 06:22:12   229,088   ----a-w   c:\windows\system32\Restore\rstrlog.dat
+ 2009-02-16 00:37:45   465,312   ----a-w   c:\windows\system32\Restore\rstrlog.dat
+ 2006-01-09 14:36:06   40,960   ----a-w   c:\windows\system32\swsc.exe
+ 2009-02-16 03:17:29   16,384   ----atw   c:\windows\temp\Perflib_Perfdata_3cc.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-17 4670704]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [BU]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2008-12-17 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-01-27 1381376]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"LWBMOUSE"="c:\program files\Gigaware\Gigaware Driver\4.06\MOUSE32A.EXE" [2001-11-09 356352]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-01 1601304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SMSTray"="c:\program files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-12-14 132624]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 136600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-04 509784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Billminder.lnk - c:\quickenw\BILLMIND.EXE [2007-07-11 36864]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2007-07-11 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-01 09:37 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-04 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-08-12 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-08-12 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-12 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-12 298264]
R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2007-07-11 34916]
R3 3dfxvs;3dfxvs;c:\windows\system32\drivers\3dfxvsm.sys [2007-07-11 148352]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S3 SMC1211;SMC EZ Card 10/100 PCI (SMC1211 Series) NT 5.0 Driver;c:\windows\system32\drivers\SMC1211.sys [2001-07-11 23153]
.
Contents of the 'Scheduled Tasks' folder

2009-02-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-04 13:14]

2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\mkokt0q1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-15 22:18:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-02-15 22:30:07 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt  2009-02-16 03:30:01
ComboFix2.txt  2009-02-15 21:38:22
ComboFix3.txt  2009-02-14 13:55:13
ComboFix4.txt  2009-02-14 13:16:39
ComboFix5.txt  2009-02-16 00:17:42

Pre-Run: 13,197,402,112 bytes free
Post-Run: 12,912,472,064 bytes free

197   --- E O F ---   2009-02-12 06:36:29
Ok Hopefully I did this Right, I had to try it a few times for it to work with out my computer freezing on me, But this time i did it in safe mode and i think it took LOL
Heres my log

ComboFix 09-02-14.01 - Owner 2009-02-15 22:12:53.4 - NTFSx86 MINIMAL
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.255.150 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)

FILE ::
c:\windows\Tasks\rpc.job
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\Tasks\rpc.job
H:\autorun.inf

.
(((((((((((((((((((((((((   Files Created from 2009-01-16 to 2009-02-16  )))))))))))))))))))))))))))))))
.

2009-02-15 19:27 . 2009-02-15 19:34      d--------   C:\32788R22FWJFW(2)
2009-02-15 19:18 . 2009-02-15 19:34      d--------   C:\RECYCLER(2)
2009-02-15 19:17 . 2009-02-15 19:34      d--------   C:\ComboFix(2)
2009-02-12 01:34 . 2009-02-12 01:34      d--------   C:\ca95aaa2e5c16143353336
2009-02-09 10:12 . 2009-02-09 10:12      d--------   c:\windows\Desktop
2009-02-06 01:09 . 2009-02-06 01:16      d---s----   c:\documents and settings\Administrator
2009-02-05 02:38 . 2009-02-05 02:38      d--------   c:\documents and settings\Owner\Application Data\Apple Computer
2009-02-05 01:45 . 2009-02-05 01:45      d--------   c:\program files\Trend Micro
2009-02-04 21:21 . 2005-09-01 11:03   127,488   ---------   c:\windows\system32\drivers\imagesrv.sys
2009-02-04 21:21 . 2005-09-01 11:03   5,888   ---------   c:\windows\system32\drivers\imagedrv.sys
2009-02-04 15:33 . 2009-02-12 19:41      d--------   c:\program files\MSECACHE
2009-02-04 14:03 . 2009-02-04 13:15   15,688   --a------   c:\windows\system32\lsdelete.exe
2009-02-04 12:58 . 2009-02-04 12:58      d----c---   c:\windows\system32\DRVSTORE
2009-02-04 12:58 . 2009-01-18 16:30   64,160   --a------   c:\windows\system32\drivers\Lbd.sys
2009-02-04 12:56 . 2009-02-04 12:57      d--h-c---   c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-04 12:02 . 2009-01-28 12:06   1,405,680   ---------   C:\WindowsServer2003-KB833167-x86-ENU.EXE
2009-02-04 12:02 . 2009-01-28 12:06   1,081,072   ---------   C:\WINDOWSSERVER2003-KB833167-X86-ENU-Symbols.EXE
2009-02-03 14:10 . 2009-02-03 14:10      d--------   c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-03 12:58 . 2009-02-03 12:56   73,728   --a------   c:\windows\system32\javacpl.cpl
2009-02-03 10:59 . 2009-02-03 10:59      d--------   c:\program files\Java(2)
2009-02-02 15:56 . 2009-02-02 15:56      d--------   c:\windows\ShellNew
2009-02-02 15:55 . 2009-02-02 15:55      d--------   c:\program files\Microsoft ActiveSync
2009-02-02 15:55 . 2009-02-02 15:55      d--------   c:\program files\Common Files\L&H
2009-01-30 20:37 . 2009-02-04 17:27      d--------   c:\windows\system32\NtmsData
2009-01-25 22:52 . 2009-01-25 23:01      d--------   C:\031a77de410c59025efbcd16
2009-01-23 09:28 . 2009-01-23 09:31      d--------   c:\program files\CA Yahoo! Anti-Spy
2009-01-20 17:29 . 2009-02-03 14:12      d--------   c:\program files\QuickTime
2009-01-20 17:23 . 2009-01-20 17:23      d--------   c:\program files\Apple Software Update
2009-01-20 17:23 . 2009-01-20 17:23      d--------   c:\documents and settings\All Users\Application Data\Apple
2009-01-17 21:27 . 2009-01-17 21:27      d--------   c:\program files\CONEXANT

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-16 00:55   ---------   d-----w   c:\documents and settings\Owner\Application Data\mjusbsp
2009-02-13 00:43   ---------   d-----w   c:\program files\Windows Media Connect 2
2009-02-05 21:07   ---------   d-----w   c:\program files\Ahead
2009-02-05 07:41   ---------   d-----w   c:\documents and settings\Owner\Application Data\LimeWire
2009-02-04 17:55   ---------   d-----w   c:\program files\Lavasoft
2009-02-01 14:37   325,128   ----a-w   c:\windows\system32\drivers\avgldx86.sys
2009-02-01 14:37   107,272   ----a-w   c:\windows\system32\drivers\avgtdix.sys
2009-01-31 01:32   ---------   d-----w   c:\program files\DivX
2009-01-29 07:55   ---------   d-----w   c:\documents and settings\All Users\Application Data\avg8
2009-01-23 15:02   ---------   d-----w   c:\program files\Free Offers from Freeze.com
2009-01-23 14:28   ---------   d-----w   c:\program files\Common Files\Scanner
2009-01-19 17:33   ---------   d-----w   c:\documents and settings\Owner\Application Data\Yahoo!
2009-01-16 21:07   ---------   d-----w   c:\program files\Java
2009-01-06 18:29   ---------   d-----w   c:\program files\LimeWire
2009-01-06 17:55   ---------   d-----w   c:\program files\Real
2009-01-06 17:55   ---------   d-----w   c:\program files\Common Files\Real
2008-12-29 15:01   ---------   d-----w   c:\program files\MSXML 4.0
2008-12-28 21:40   ---------   d-----w   c:\documents and settings\Owner\Application Data\FrostWire
2008-12-28 02:52   ---------   d--h--w   c:\program files\InstallShield Installation Information
2008-12-28 02:52   ---------   d-----w   c:\program files\Samsung
2008-12-28 02:52   ---------   d-----w   c:\program files\MarkAny
2008-12-28 02:52   ---------   d-----w   c:\documents and settings\Owner\Application Data\DataCast
2008-09-15 09:25   32,768   --sha-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091520080916\index.dat
.

(((((((((((((((((((((((((((((   [email protected]_ 1.57.55.77   )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-04 18:08:14   16,384   -c--a-w   c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-13 03:00:59   16,384   -c--a-w   c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-04 18:08:14   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-13 03:00:59   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-04 18:08:14   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-13 03:00:59   32,768   -c--a-w   c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-06 06:22:12   229,088   ----a-w   c:\windows\system32\Restore\rstrlog.dat
+ 2009-02-16 00:37:45   465,312   ----a-w   c:\windows\system32\Restore\rstrlog.dat
+ 2006-01-09 14:36:06   40,960   ----a-w   c:\windows\system32\swsc.exe
+ 2009-02-16 03:17:29   16,384   ----atw   c:\windows\temp\Perflib_Perfdata_3cc.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-17 4670704]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [BU]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2008-12-17 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-01-27 1381376]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"LWBMOUSE"="c:\program files\Gigaware\Gigaware Driver\4.06\MOUSE32A.EXE" [2001-11-09 356352]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-01 1601304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SMSTray"="c:\program files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-12-14 132624]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 136600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-04 509784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Billminder.lnk - c:\quickenw\BILLMIND.EXE [2007-07-11 36864]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2007-07-11 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-01 09:37 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-04 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-08-12 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-08-12 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-12 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-12 298264]
R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2007-07-11 34916]
R3 3dfxvs;3dfxvs;c:\windows\system32\drivers\3dfxvsm.sys [2007-07-11 148352]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S3 SMC1211;SMC EZ Card 10/100 PCI (SMC1211 Series) NT 5.0 Driver;c:\windows\system32\drivers\SMC1211.sys [2001-07-11 23153]
.
Contents of the 'Scheduled Tasks' folder

2009-02-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-04 13:14]

2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\mkokt0q1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-15 22:18:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-02-15 22:30:07 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt  2009-02-16 03:30:01
ComboFix2.txt  2009-02-15 21:38:22
ComboFix3.txt  2009-02-14 13:55:13
ComboFix4.txt  2009-02-14 13:16:39
ComboFix5.txt  2009-02-16 00:17:42

Pre-Run: 13,197,402,112 bytes free
Post-Run: 12,912,472,064 bytes free

197   --- E O F ---   2009-02-12 06:36:29

    Yes that's better.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Download
ATF Cleaner by Atribune to your Desktop.

Alternate download link

Note: Vista users must use Run As Administrator
  • Under Main: Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • Click Exit on the Main menu to close the program.
.
Note that your system will run slower for a reboot or two after having used this TOOL so don't panic.

----------

Download OTCleanIt.exe and save it to your Desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
.
Important: Restart the computer before continuing.

----------

Use the ESET Online Antivirus Scanner

This scanner requires Internet Explorer

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.

Also let me know how the computer is running now.Thank you my computer is running better,But have one more problem Windows installer keeps opening every time i do something should i try to get a new version or something?

Heres my log from ESET

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3857 (20090216)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=3e83c31cdf5f6f4ea0604f3a36eb9d7e
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2009-02-16 09:36:46
# local_time=2009-02-16 04:36:46 (-0500, Eastern Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=131046
# found=0
# scan_time=2631Download Deckard's Association File Tool (DAFT) and save it to your desktop.
  • Rename daft.exe to daft.com and double click on it to run.
  • Read the disclaimer and click OK.
  • Click on the Scan button.
  • If it finds faulty file associations, they will appear in red beside a checkbox. If this occurs, just place a checkmark (tick) in the boxes in question.
  • Click the Fix button.
.
Was anything found and fixed?I keep getting page not found when i try to download Deckard's Association File Tool
Try Dial-a-fix.

Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

  • Open the folder and run Dial-a-fix.exe
  • 2 windows will open. Close the one in the background labeled Restrictive Policies
  • Check the box in section 1, Empty temp folders.
  • Check the box in section 2, Fix Windows Installer.
  • Check the box in section 3, Fix Windows Update.
  • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
  • Check all boxes in section 5, labeled Registration Center.
  • Click Go
  • OK any error messages if received, but write them down and post them here.
  • Restart the computer when done.
.
Is the problem fixed?Thank you Every thing is good if i use mozilla,But when open any windows With IE installer pops up. I thank you so muchRe-register MsiExec
  • Go to Start > Run
  • Type or Copy and Paste the following:
    • MSIEXEC /UNREGISTER then hit enter.
  • Then again Start > Run
  • Now type or Copy and Paste the following:
    • MSIEXEC /REGSERVER then hit enter.
.
No visible change will take place. Try to install/uninstall again.

If this method fails, you will need to reinstall the Microsoft Windows Installer (MSI)
Windows Installer 3.1
Windows Installer 4.5LOL OK Well i figured out one thing Everytime i download anything from windows it wont install even windows update fails 
Should i go to a different forum and make a new post,so i dont have to bug you with this problemGo to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\.exe]
="exefile"
"Content Type"="application/x-msdownload"

[HKEY_CLASSES_ROOT\.exe\PersistentHandler]
="{098f2470-bae0-11cd-b579-08002b30bfeb}"

[HKEY_CLASSES_ROOT\exefile]
="Application"
"EditFlags"=hex:38,07,00,00
"TileInfo"="prop:FileDescription;Company;FileVersion"
"InfoTip"="prop:FileDescription;Company;FileVersion;Create;Size"

[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
="%1"

[HKEY_CLASSES_ROOT\exefile\shell]

[HKEY_CLASSES_ROOT\exefile\shell\open]
"EditFlags"=hex:00,00,00,00

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shell\runas]

[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shellex]

[HKEY_CLASSES_ROOT\exefile\shellex\DropHandler]
="{86C86720-42A0-1069-A2E8-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers]

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PEAnalyser]
="{09A63660-16F9-11d0-B1DF-004F56001CA7}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PifProps]
="{86F19A00-42A0-1069-A2E9-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\ShimLayer Property Page]
="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"

[HKEY_CLASSES_ROOT\regfile]
="Registration Entries"
"EditFlags"=dword:00100000
"BrowserFlags"=dword:00000008

[HKEY_CLASSES_ROOT\regfile\DefaultIcon]
=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
  00,5c,00,72,00,65,00,67,00,65,00,64,00,69,00,74,00,2e,00,65,00,78,00,65,00,\
  2c,00,31,00,00,00

[HKEY_CLASSES_ROOT\regfile\shell]
="open"

[HKEY_CLASSES_ROOT\regfile\shell\edit]

[HKEY_CLASSES_ROOT\regfile\shell\edit\command]
=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
  00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4e,00,4f,00,\
  54,00,45,00,50,00,41,00,44,00,2e,00,45,00,58,00,45,00,20,00,25,00,31,00,00,\
  00

[HKEY_CLASSES_ROOT\regfile\shell\open]
="MER&ge"

[HKEY_CLASSES_ROOT\regfile\shell\open\command]
="regedit.exe \"%1\""

[HKEY_CLASSES_ROOT\regfile\shell\print]

[HKEY_CLASSES_ROOT\regfile\shell\print\command]
=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
  00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4e,00,4f,00,\
  54,00,45,00,50,00,41,00,44,00,2e,00,45,00,58,00,45,00,20,00,2f,00,70,00,20,\
  00,25,00,31,00,00,00

[HKEY_CLASSES_ROOT\.lnk]
="lnkfile"

[HKEY_CLASSES_ROOT\.lnk\ShellEx]

[HKEY_CLASSES_ROOT\.lnk\ShellEx\{000214EE-0000-0000-C000-000000000046}]
="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\.lnk\ShellEx\{000214F9-0000-0000-C000-000000000046}]
="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\.lnk\ShellEx\{00021500-0000-0000-C000-000000000046}]
="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\.lnk\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}]
="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\.lnk\ShellNew]
"Command"="rundll32.exe appwiz.cpl,NewLinkHere %1"

[HKEY_CLASSES_ROOT\lnkfile]
="Shortcut"
"EditFlags"=dword:00000001
"IsShortcut"=""
"NeverShowExt"=""

[HKEY_CLASSES_ROOT\lnkfile\CLSID]
="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\lnkfile\shellex]

[HKEY_CLASSES_ROOT\lnkfile\shellex\ContextMenuHandlers]

[HKEY_CLASSES_ROOT\lnkfile\shellex\ContextMenuHandlers\Offline Files]
="{750fdf0e-2a26-11d1-a3ea-080036587f03}"

[HKEY_CLASSES_ROOT\lnkfile\shellex\ContextMenuHandlers\{00021401-0000-0000-C000-000000000046}]

[HKEY_CLASSES_ROOT\lnkfile\shellex\DropHandler]
="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\lnkfile\shellex\IconHandler]
="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\lnkfile\shellex\PropertySheetHandlers]

[HKEY_CLASSES_ROOT\lnkfile\shellex\PropertySheetHandlers\ShimLayer Property Page]
="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}]
="Shortcut"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32]
="shell32.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\PersistentAddinsRegistered]

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\PersistentAddinsRegistered\{89BCB740-6119-101A-BCB7-00DD010655AF}]
="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\PersistentHandler]
="{00021401-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID]
="lnkfile"

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\shellex]

[HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\shellex\MayChangeDefaultMenu]

Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

Delete the fixme.reg from the Desktop.

----------

Is it fixed now?
912.

Solve : Re: Spybot Blocked?

Answer»

You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

It is suggested to remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.

  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
  • Viewpoint Toolbar
  • Viewpoint Experience Technology
.
----------

Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

First install the new Sun Java Runtime Environment

Be sure to close all browser windows before beginning the install.

Remove the old VERSION(s)

Download JavaRa
  • Unzip the file and open the JavaRa.exe
  • Click Remove Older Versions
  • JavaRa will search for and remove any outdated version of Java and remove any that are found.
  • Click Additional Tasks
  • Place a check next to Remove Useless JRE Files and click Go
  • Exit JavaRa
  • Delete the JavaRa files from the Desktop
.
Additional Note: The Java Quick Starter (JQS.exe) adds a SERVICE to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.

----------

Download OTCleanIt.exe and save it to your Desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
.
----------

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O23 - Service: AOL Antivirus Update Service (aolavupd) - UNKNOWN owner - C:\Program Files\Common Files\AOL\1125946752\ee\services\safetyCore\ver210_5_2_1\aolavupd.exe (file missing)

Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Open HijackThis, but instead of scanning, click on the Open the MISC tools section button at the bottom of the choices.

Copy this red text -> aolavupd

  • In HijackThis select Delete an NT Service
  • Paste the text  into the box that opens and then click OK
  • If you receive any error messages just ignore them and continue.
  • Now repeat the above to delete the below Services (if you do not find them or get any errors, just continue):
.
Now exit HijackThis and reboot when it tells you it needs to.

----------

How is the computer running now?
.The computer seems to running better.  However, a few things:

-- Anything regarding Viewpoint was not found in Add/remove programs

-- I ran an Antivir scan last night, and three infections were found:
          -- Rootkit.gen
          -- Crypt.XPack.Gen
          -- A0351077.dll contained a recognition pattern of the (harmful) BDS/TD
-- I usually quarantine the infections.  Is that the right thing to do?

-- Can you recommend a very user friendly firewall?  I am doing this (well, you are lol) for a friend's parents, and they arent too computer savvy.

Again, thank you for taking the time to help.

--I am going to attempt to run Spybot and SAS, just to make sure everything is okay and they can operate again.Download ViewpointKiller.zip
  • Unzip the program and all of the contents of ViewpointKiller.zip to a location such as your desktop.
  • Double click the ViewpointKiller icon to run ViewpointKiller.exe.
  • Select the File menu, and select Check to see if you have Viewpoint installed.
  • If ViewpointKiller indicates that any of the Viewpoint variants are installed, select the proper Kill option in the File menu.
  • Follow the prompts and instructions very carefully, answering Yes or No depending on which option you are most COMFORTABLE with.
  • The MsConfig instructions are very important, so be sure to read them carefully.
  • Note: When done with ViewpointKiller right click and delete all files that were unzipped.
,
----------

Disable/Enable the System Restore Utility to flush old infected restore points

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Put a check mark next to Turn off System Restore on All Drives
4) Click the OK button.
5) You will be prompted to restart the computer. Click the Yes button.

Now re-enable System Restore

To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Remove the check mark next to Turn off System Restore on All Drives
4) Click the OK button.

----------

These are all free.

Remember only install ONE firewall

1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
2) Online Armor
3) Sunbelt/Kerio
4) Agnitum
5) PC Tools Firewall Plus

----------

Use the ESET Online Antivirus Scanner

This scanner requires Internet Explorer

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.I did the "Check to see if you have Viewpoint installed" and Viewpoint Manager was the only one present.  After selecting "Kill Viewpoint Manager", a log file appeared.  I have pasted it below.  However, it still says that Viewpoint Manager is installed.  What Msconfig instructions do you SPEAK of?  I do not see them.  Thank you.  I have not proceeded with the other steps you provided me.

ViewpointKiller Version 1.30 (beta)

The removal process was started on Tue Feb 17 12:03:15 2009

Preparing to remove Viewpoint Manager...



ViewpointKiller was not able to close "viewmgr.exe"!

Searching for all known Viewpoint Manager registry values and keys...

Found and removed: Software\Microsoft\Windows\CurrentVersion\Uninstall\Viewpoint Manager

Finished searching for and removing all known Viewpoint Manager registry values and keys.



Searching for all known Viewpoint Manager files and folders...

Could not delete: C:\Program Files\Viewpoint\Viewpoint Manager

Could not delete: C:\Program Files\Viewpoint

Finished searching for and removing all known Viewpoint Manager files and folders.Looks like it worked. Viewpoint isn't malware just a nuisance. It's installed with AOL/AIM but serves no real purpose.I downloaded and am running Online Armor.  After installing, I restarted the computer, and AntiVir Guard is no longer present in the system tray.  Also, I attempted to run the ESET scan, but it gets hung up on C:\dell\MEDIAEXE\ONDRVMED.zip

Edit:  I take that back.  The scan has progressed past that file.You might try reinstalling AntiVir. I have not seen any issues with the two working together but who knows. Software updates sometimes don't go as planned from day to day.# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3865 (20090218)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=5ac917da29dd34439cbfdffc6d6c56ed
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2009-02-17 08:38:31
# local_time=2009-02-17 03:38:31 (-0500, Eastern Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=323027
# found=4
# scan_time=8254
C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5702A24C-178F-4661-97D1-644845A9CBB7}   Win32/Qhost trojan (unable to clean - deleted)   00000000000000000000000000000000
C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{71781886-D1CC-45EB-BC62-87BC19A8EE6E}   Win32/Qhost trojan (unable to clean - deleted)   00000000000000000000000000000000
C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C3A44FE1-4BA1-46B3-9021-943039993BB9}   Win32/Qhost trojan (unable to clean - deleted)   00000000000000000000000000000000
C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{F5619D5D-C2F7-4E2D-ABEF-4050D012CB7D}   Win32/Qhost trojan (unable to clean - deleted)   00000000000000000000000000000000
  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    How is the computer running now?Am I allowed to run this while my protection is active?Yes, it's just removing ComboFix and resetting a few things to their default settings, as they should be.
    913.

    Solve : Mouse automatic getures and clicking?

    Answer»

    My mouse just started moving and clicking on its own today, it extremely annoying, i've run MULTIPLE virus, spyware, and malware checks with no LUCK. any SUGGESTIONS would be greatly appreciatedQuick QUESTION, is this a laptop?

    Does this happen when you are not touching the computer?thanks for the quick REPLY, it turns out that my wireless mouse was doing this due to low batteries.Heh, all right.

    914.

    Solve : CD drive opens and closes automatically.....?

    Answer»

    I know a VBS script that does it on a loop, and it made my computer sound like a hurricane and crashed it!Done.  I thought that you could only run c code and get it to do that stuff.Prepare a boot able floppy.
    Boot from the flippy.
    Let it sit for 10 minuets and see if the CD opens by itself. Quote from: BC_Programmer on FEBRUARY 18, 2009, 04:28:36 PM


    O4 - HKCU\..\Run: [mpx] c:\WINDOWS\system32\mpx.exe

    anybody know what this is or what it does?

    Trojan.Virtumonde - http://www.threatexpert.com/report.aspx?uid=01feba93-ac5e-4014-b820-dc737f5d1e0a

    We need to remove the malware first but honestly the CD tray sounds like a dist problem to me. Some argue it can't carry a current but I think it's been proven it can.

    globalpal_ooty - I suggest uninstalling the Paretlogic Driver Cure. (Unless it's a paid version). This company isn't trusted.

    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    - O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    - O4 - HKCU\..\Run: [mpx] c:\WINDOWS\system32\mpx.exe


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    Go to Start > Run and type notepad.exe then click OK

    Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

    Code: [Select]REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "Alcmtr"=-

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "mpx"=-

    Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

    Make sure that you tell me if you RECEIVE a success message about adding the above to the registry. If you do not get a success message, it did not work.

    Delete the fixme.reg from the Desktop.

    ----------

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note:  It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of SECURITY programs that should be disabled and how to disable them.
     
    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFix
    915.

    Solve : Hidden virus??

    Answer»

    Im dam sure i have another infection. But nothings picking it up

    All my games are making my ping high , i know im infected.

    Evil fantasy what logs would you like to see.

    Code: [Select]Logfile of HijackThis v1.99.1
    Scan saved at 8:03:15 PM, on 2/19/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\MOBILE DEVICE Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Xfire\Xfire.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\Program Files\AVG\AVG8\avgui.exe
    C:\Program Files\AVG\AVG8\avgscanx.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Documents and Settings\Tony\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HTTP://www.tiscali.co.uk/broadband
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.tiscali.co.uk/broadband
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(TM) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.22\RivaTuner.exe" /S
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D6D13D0B-17FB-44C6-8961-E7F3C26F05FD}: NameServer = 212.139.132.9 212.139.132.8
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

    916.

    Solve : HELP!!! I have a virus..?

    Answer»

    I am running windows XP. I cannot USE any of my programs. If I click on an icon I get a "Path does not exist" error msg. I cannot download anything because when I click on the icon to INSTALL then I get the same error. Can I get into my computer files somehow and REMOVE it that way? I have Macafee but it DIDNT catch it. now I cannot run that either. I am at my wits end. The only thing I can use is my windows IE. I HATE IE so this is driving me NUTS. I tried to open my add/ramove programs but that wont open either. Someone PLEASE help me.

    917.

    Solve : Have I been hijacked??

    Answer»

    Hi,

    Malware Bytes told me I had a trojan, so I QUARANTINED it and got rid of it.  Then I ran Hijack This.  I have no idea how my computer got a trojan!  (I ran AVG, Super Anti-Spyware, and Malware Bytes again and it doesn't show up again).

    Can you tell me if my computer has been hijacked by the following log?

    THANK YOU SO MUCH!

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:42:52 PM, on 2/18/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running PROCESSES:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Linksys WIRELESS-G USB Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv2.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\Program Files\Trend Micro\ABCThis\HijackThis.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Home
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy:8080
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ACTIVEX\AcroIEHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QUICKTIME Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - Global Startup: Resolution Assistant.lnk = C:\Program Files\Dell\Resolution Assistant\MotiveAssistant\bin\matcli.exe
    O4 - Global Startup: Windows Media PowerPoint Helper.lnk = C:\Program Files\Windows Media Components\Tools\nsppthlp.exe
    O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
    O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install-ie/alttiff.cab
    O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} (Auctiva Image Uploader Control) - http://www.auctiva.com/Aurigma/ImageUploader55.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: WUSB54Gv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

    --
    End of file - 6629 bytes
    they are easy to get and get rid of as you did but wait for the advice of an expert , harry

    918.

    Solve : Is your DNS sending you bad stuff??

    Answer»

    This is a real security issue. It is not, per se, a virus, but it is one way a virus can GET into your system. I have tried to say before and everybody would say that it can not happen if you have a good firewall and a good anti-virus and if you are carefull. Not So! Look at this:
    Quote

    Dan Kaminsky, who for years was AMBIVALENT about securing DNS, has become an ardent supporter of DNS Security
    I would put this in the News section, but then the people who NEED to know about it would never read it, It is about making your PC secure. Anti-virus and firewalls are not enough. The DENS you are using is another backdoor into your system, The anti-virus does not even try to verify the quality of your DNS.

    Related th that, Up to now people have thought that the SSL was all that it takes to stop a HACKER from getting into your system. Not with the high power servers that lie offshore. There are thousand of servers that are out of jurisdiction and they can do what they want with SSL certificates. Even with odds of one in a million, that is all that it takes when you have thousands of servers doing millions of spoofs in a short span of time.

    What I am trying to say is this. It is not getting BETTER. The worst is not all behind us. I know many of you do not believe that, you think the new anti-virus software can do anything. Not so!

    Don't t telo me this is an old issue. It is a current issue until you are protected.d What have you done about this? Have you talked to your ISP?
    919.

    Solve : phorm?

    Answer»

    Hi,i heard last year that, virgin, sky,and, talk talk broadbond
    were thinking of useing the phorm or is it phorn servsers
    to spy!! on there customers browsing habits.
    And this would be an opt out service not opt in. i dont
    know if any of them are yet, i have nothing to hide but
    id like them to tell me (virgin) the reason for this post is
    my spyware doctor pops up when i turn on my P.C saying
    possable mallware, in   c:program files\virgin broadband\rps.exe ?
    i can not stop or delet it bcause all my  virgin PROTECTION stops.
    im just hopeing someone can tell me if it is a bad file?
    and if they are useing phorm.. before i phone them..

    sorry for long post, Thanks for your time.....p.....


    You NEED to report it to Spyware Doctor. It's a FALSE positive. http://www.pctools.com/forum/forumdisplay.php?f=54

    Quote

    http://www.bleepingcomputer.com/startups/RPS.exe-15389.html
    Filename:  RPS.exe
    Command: Unknown at this time.
    Description: Related to ntlworld_Netguard Anti-virus a package of services, specifically designed to keep you safe and SECURE with their online services.
    Thanks a lot for your qiuck reply!!!!!
    evilfantasy. i think ill be back later coz
    i keep getting a browser hijack host files
    i use spyware blaster to fix them,it says i1
    file unprotected so i RUN host file gaurd fixed
    5 minutes later its back?

    cheers.p..........
    920.

    Solve : Cannot remove this virus which started with Win32:JunkPoly [Cryp]?

    Answer»

    Quote from: BC_Programmer on February 19, 2009, 02:00:03 AM

    Quote from: h4cker on February 18, 2009, 11:23:27 PM
    Understandable. I have an external drive connected to my PC. What is your suggestion to care of the situation? As I'm sure it has spread to the external, so when I reformat - it may just re-infect the newly installed OS.

    are their any executables on the external?

    Yes, 1TB of data. Quote from: BC_Programmer on February 19, 2009, 02:00:03 AM
    Quote from: h4cker on February 18, 2009, 11:23:27 PM
    Understandable. I have an external drive connected to my PC. What is your suggestion to care of the situation? As I'm sure it has spread to the external, so when I reformat - it may just re-infect the newly installed OS.

    are their any executables on the external?

    IE- programs. (Note zips/rars probably don't count)

    because if so I would avoid even navigating near them until you are able to reinstall. BC_Programmer

    I have programs (executables and some of which run directly from the drive), music, iso's and the like. So to answer your question, yes I do.

    Thanks.In any case I'd go withthe method of reinstallation and then SCAN/clean the drive. Until the Virus is able to load into memory it cannot infect further, so the trick is keeping it from doing that- which is actually as simple as not running any EXE files from the external drive (or, DLLs).

    But as evilfantasy said the virus is polymorphic, so even in the scope of infecting a single HD it could mutate enough to not be caught by the virus scanner... which will declare it clean, and that program MIGHT be run in the future- back to square 1.
    the ISO files... and in fact anything that isn't a PE format file should be safe from it (PE=Portable Executable).

    If I were you, I would myself:

    Reformat, Reinstall
    Delete all EXE,DLL, OCX, and SCR files present on the external drive. every last one, regardless of what it was.

    Then- reinstall those apps whose EXE and DLL files are now missing- all of them that were on the drive, really.

    This is still far from a total guarantee that the external won't re-infect the new OS, But deleting the Data itself I imagine isn't even a option. Quote from: BC_Programmer on February 19, 2009, 03:36:01 AM
    But deleting the Data itself I imagine isn't even a option.

    Not an option at ALL, lol. There is over 7 years of data collected on that drive; THOUSANDS of files. I would literally CRY( ) if that data disappeared. Which then you would ask, "So you have a backup right?" Then I answer, "No, because I'm dumb."

    I'm running Dr.Web LiveCD to hopefully have it clean some of the files and will TRY ANOTHER Live! CD with multiple scan engines on it to scan and clean the external. I can post back and let everyone know how it went.You do have the external HD disconnected now, right? Quote from: kpac on February 19, 2009, 03:59:28 AM
    You do have the external HD disconnected now, right?

    No, it's connected. I'm running the Dr. Web LiveCD http://www.freedrweb.com/livecd/ to remove possible traces of the virus without booting.

    I'm using my Ubuntu server right now to type all this. Is it possible that the virus can corrupt the BIOS?

    Does anyone know how long the Dr. Web LiveCD scan takes to complete?
    Thanks.Not sure how long the scan takes. It will vary from one PC to another.

    It's unlikely that your BIOS is infected.

    Good luck!
    921.

    Solve : My computer is so dirty I have to wear Gloves...Help Cleaning Please?

    Answer»

    They are just too close TOGETHER...Half of me believes you and THREE quarters of me doesn't.... Quote from: kpac on February 18, 2009, 03:19:16 PM
    Half of me believes you and three quarters of me doesn't....

    Wanna hear a funny story? I accidentally clicked modify instead of quote almost immediately after Steve made us moderators.... And even funnier it was one of his posts.

    LOL

    Well not to happy about the computer killer virus.
    I have lots of data I want to recover from this computer this is my plan:
    I have a 1TB USB drive to use as  data dump, also installed a second serial drive in the infected computer ( Not hooked up yet)

    On my last system restore I was able to remove the hard drive from infected computer and copy the data files to a lifeboat  computer.(This file contained the virus and reinfected my computer. Lifeboat computer was unaffected.)


    I copied this data file to the USB drive.

    Did a system restore to infested computer.
    INSTALLING programs now.

    Plan to copy the big data block on new hard drive and ACCESS when NECESSARY.  Slowly bring over data files,and try to avoid this virus again.hopefully it works out for you
    922.

    Solve : HELP!! Media player constantly starting on it's own while web browsing!!!?

    Answer»
    My MEDIA player has suddenly started on it's own constantly while I am browsing the internet!  It doesn't matter whether I am using FIREFOX or IE
    I changed all my defaults from Windows Media Player to Realplayer..but that didn't help.  Now, instead of Windows Media Player POPPING up constantly, Real Player starts up constantly.
    What is going on???!!!
    923.

    Solve : virus? windows explorer doesn't work!?

    Answer»

    ugh! i accidentally downloaded something BAD today.
    i noticed a bunch of weird PROGRAMS i never downloaded on my desktop, so i TRIED opening recycle bin to delete, them, and recycle bin didn't work. it would open, then immediately close without me doing anything. so i dragged the programs into recycle bin again and right clicked and emptied them that way. i did the same thing when i found them on my start menu.
    then i downloaded avira antivirus and ran a scan. it found two trojans and i put them in quarantine, then deleted them.
    when that was finished, i ran CCleaner and did a cleanup as well as a check for registry problems.
    then i tried using recycle bin again, and it still fails to work.
    my documents and my computer don't work, either.
    neither does CONTROL panel.
    the only way i can get them to work is by opening IE and the typing in "my computer," etc.
    so what should i do?
    i know the viruses are still there...GO back to page 1 of this topic , go to the top of the page " Read this before requesting malware removal help " and do everything and post all the scans

    924.

    Solve : Laptop needs a good cleaning?

    Answer»

    Howaya!
    Was WONDERING if you could take a look at these log files and tell me if there is anything that needs cleaning.  Using a compaq presario LAPTOP with Windows XP Media Centre edition.  Computer SEEMS to be running a little SLOW these days. I've attached the log files for you to have a look at. Thanks so much, REALLY appreciate it

    [attachment deleted by admin]

    925.

    Solve : No start menu or icons still, Completed list have logs?

    Answer»

    WOW.....You guys have my upmost respect...this stuff is time consuming and frustrating!  I have finally completed the Try this first list.... The only thing I was not able to rename the HijackThis file....I also tried to find the logs that I saved to the desktop and they are no longer there??? I am seriously lost what do I do now??  Below are the events that have occured over the past 36 hours.


    Okay so I have been getting this error msg when I turned on my computer, Explore.exe unable to locate component - This application has failed to start because SHDOCVW.dll was not found.  Reinstalling the application may fix the problem.  I ran AVG 7.5 which came back clear...No threats.  I'm on windows Xp with Sp3 and recently down loaded PC tools threatfire firewall. Earlier today I was trying to down load some cool little cursor.. obviously a big mistake I knew better.  The firewall keep asking me to quarantine the file and I think I did quarantine one.  That's when this started.  I was thinking that it may have quarantined this file and that might just need to reinstall the program.  So my screen is now blank, no icons or start menu, I am able to get to the task window and it allows me to navigate from there.  I've been searching for 5 hours for this file on line and finally came across this site.  Luckily I found you before I did anything detrimental to my computer.  I now know that my anti-virus program is out of date.  So I ATTEMPTED to update.  Did not work!  I uninstalled 7.5 and downloaded 8.0.  It seemed to work but now it won't let me into AVG at all.  I hope that I have provided enough information!  I read the read first section which is how I found out that my AVG was out of date.  PLEASE help...I am out of ideas! 

    Okay update since LAST night....I still can't run my anti-virus program...but I continued to with the help list and attempted to REMOVE some programs....I came across My Web search(cursor mania) This is what I believe started all of this....I tried to remove it and this error came back....RUNDLL  error LOADING  C:\proga~1\MYWEBS~1\bar\2.bin\mwsbar.dll  The specified mode could not be found....Okay so I think this is what caused all of this.....Not sure how to fix...Do I need to delete and reinstall a different anti-virus? 

    Another update...I was able to get rid of AVG and add Avast...According to Avast I have no virus....

    926.

    Solve : Virus Alert in toolbar?

    Answer»

    This is the only PROBLEM I have LEFT on my laptop. I followed your guidelines just as you laid them out, I am left with the virus alert! NOTIFICATION next to my clock. Thank you for the help, my computer is getting back to normal.

    [attachment deleted by ADMIN]

    927.

    Solve : Directx Diagnostics is being forced on me.?

    Answer»

    1. Yes- if you GET no prompt that means all was well and it did it's thing 

    2. It's PROBABLY STILL pointing to the dllcache folder- you can edit the "TARGET" in it's properties dialog and remove the dllcache portion, making it point instead to "C:\windows\system32\freecell.exe"

    928.

    Solve : apparently i have a trojan?

    Answer»

    really the only thing you need to backup WOULD be your  documents, and if they are important to you, game saves. Anything else can be reinstalled from the install discs.

    you COULD also backup the installers for programs you've downloaded, if any.I cant uninstall Flash 9. its in my backup folder. I tried looking for an uninstaller but it only UNINSTALLED Flash 10. I even got rid of the flash ocx and xpt FILE in firefox. I still cant get rid of that darn flash9f.ocx file. it always says cannot delete flash9f.ocx: access is denied. I dont understand. I dont even have any APPLICATIONS running when I try to delete it. I tried clicking on the uninstall_activex file but that did nothing. I even tried running a program called Killbox.

    929.

    Solve : Computer infected; believe it's malware; won't let me run AdAware or Malwarebyte?

    Answer»

    I'm a new user to this site and need to see if anyone can give me some tips.  About two days, I noticed my browser has been hijacked.  When I search the normal Yahoo search bar, it takes me to a page that LOOKS like it's should be right, but some of the links take me to various places I don't want to go.  My system is also locking up, it won't allow me to go back to a prior restore POINT, and no one can seem to help.  I have BSAFE online filtering with what I believe is McAfee.  I ran the scan and it's not picking anything up.  I also installed windows live care, and it didn't find anything either (so I removed it). 

    I called Best Buy and they want to charge me 200.00 to attempt to fix.  But my computer is an older Compaq Presario and I can get one built for 350.00 that's 10 times better.  But I really don't have the extra cash and I am thinking about just wiping out the hard drive and doing a system restore with the original disks. 

    That being said, any ideas?  Like I said in my SUBJECT line, I installed malwarebytes, and the inon is on my desk.  But when I try to run it, it won't do anything.  And it won't even let me start Ad aware.  So whatever is on my computer, it's taken control and won't allow me to do the things it knows will WIPE it out.  HELP!!!!

    $200.00 

    Wow, for that plaice you can go get another computer.
    If you have another computer, you can use it to scan the infected disk drive. You remove the hard drive from the infected computer and place it in the good computer as a slave. Do NOT run and programs  off the infected drive, don't even look at pictures on it. Use a good program, like megabytes, to do a full scan of the infected slave drive.
    The vest way to 'slave' a standard HDD is to just place it on the cable used by the CD-ROM drive. Leave the CD-Drive off for now.  This is when the DRIVES are the standard IDE type found on most computers made in the paste few years.
    Some new ones are SATA and you would put a that drive on the second SATA plug in the good system.

    In either case, check the BIOS to see if slave drive is found by the BIOS.
    Now about the $200 thing. I think you would be better off investing in a good used computer just to have a backup system and to help you with future issues. I know that sounds like overkill, and a few years ago it was, but now used computers are even cheaper that a new HDD! Of course, they do not have all the power and storage you might want, but they have enough to serve ans a backup system.

    Of course, you have to be careful about who you buy from. On eBay you can find out how long they have been in business and what kind of reviews that have received.

    930.

    Solve : Storage devices and viruses?

    Answer»

    I had a back up of some files on my memory stick.
    A few months later (last week) I had a major virus problem which locked me out of the computer, just cycling between log in, log off, log in, log off.

    Someone cleaned the computer for me and I was able to log in.  I got a lot of filles off the computer onto CD's and some on my memory stick.

    After that, I saw more viruses were on the computer and it has now shut down and won't reboot.  It wasn't really cleared of viruses at all.

    But my question is:  Do you think I can get from my memory stick the older files I put there before the files I put on it that may have a virus?  Is it possible the virus, if now on the memory stick, could somehow effect the older files that did not have viruses?

    Can they move across?

    My plan is to use an old computer to READ the files on the memory stick, drag or copy the one file I really need to a cd by itself.  Then scan the CD. 

    I had to buy a new computer and am scared to infect it.  But need to continue working on this file which is a part time job.


    memory sticks , etc  , can carry a virus from pc to pc , if you had a virus and you downloaded files etc , you could have put the virus on the memory stickThanks...but my question is:

    Can files without viruses PREVIOUSLY on the memory stick be infected if new files are loaded on if they have a virus?  Would it effect the old clean files on the device?


    i would say , yes , as the files would be on the pcArgh!!!!  That sucks!  LOL

    Do they have an 'executible' file within them?  What triggers them to run?
    I accept your word, and won't expect the old pre-virus files to be clean, but hard to understand how it happens that they get the virus too.

    I'd really like to understand this.  Can you explain? 

    :-)

    Usually when a storage device is infected it's by an autorun worm. But you can transfer infected .exe or other files and cross infect other computers.

    Flash Drive Cleanup

    Download Flash Disinfector by sUBs and save it to your Desktop.
     

    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives INCLUDING your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.
    .
    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.You can also scan your flash drive for virus with Kaspersky.

    Plug in the USB drive prior to performing the steps below.

    Please keep ALL other programs closed during the scan

    Run an online scan with the Kaspersky Online Scanner
    • The program will launch and then start to download the latest definition files.
    • Once the scanner is installed and the definitions downloaded, click Next.
    • Now click on Scan Settings
    • Now under SELECT a target to scan select Your USB drive.
    • Once the scan is complete it will display if your system has been infected.
    • Please do not use your computer while the scan is running. Once the scan is complete it will display if your USB drive has been infected.
    • Click the Save Report As... button.
    • In the Save as... prompt, select Desktop
    • In the File name box, name the file KasScan-ddmmyy (or similar)
    • In the Save as type prompt, select Text file (see below)

    .
    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.Thank you EF!!!!!  This is awesome help and advice and I'll do it carefully.
    I really appreciate you help.

    Fingers crossed....

     

    evil is an expert take his advice , i was just giving you advice not what to do , harry
    931.

    Solve : ...I don't know.?

    Answer»

    that's what I THOUGHT...

    932.

    Solve : her is my log?

    Answer»

    i hope this time ive posted
    my log PROPERLY this time i
    cut and pasted it..
    thanks for your time..........



    ..p..........Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:26:17, on 21/02/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\System32\smss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Virgin Broadband\PCguard\Fws.exe
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\a-squared Free\a2service.exe
    C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    C:\Windows\system32\CTsvcCDA.exe
    C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
    C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe
    C:\Program Files\Virgin Broadband\PCguard\RPS.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Windows\sttray.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Virgin Broadband\PCguard\rpsupdaterR.exe
    C:\Windows\System32\msdtc.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Windows\system32\dllhost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Virgin Broadband\PCguard\pkR.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [Broadbandadvisor.exe] "C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN
    O4 - HKLM\..\Run: [PCguard] "C:\Program Files\Virgin Broadband\PCguard\Rps.exe"
    O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Virgin Broadband\PCguard\ZkRunOnceR.exe"
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Virgin Broadband\PCguard\IdxClnR.exe"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: a-squared Free Service (a2free) - EMSI Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - MACROVISION Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
    O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
    O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard DRIVE Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: Virgin Broadband PCguard Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Virgin Broadband\PCguard\rpsupdaterR.exe
    O23 - Service: PCguard Firewall (RP_FWS) - Virgin Media - C:\Program Files\Virgin Broadband\PCguard\Fws.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: XAudioService - Conexant SYSTEMS, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 8944 bytes

    933.

    Solve : Problems here are my logs?

    Answer»

    Please find attached my logs i have been having problems now for 3 days. i have FOLLOWED the anti malware guide.

    Thanks for ANYONE who can HELP me.

    [attachment DELETED by ADMIN]

    934.

    Solve : Can I delete??

    Answer»

    Hey friends, I was just wondering If I could delete the first 5 processes of this hijack this logg, and how do I get rid of the yellow exclamation things. I RAN LSP Fix, And It came up clean. Also I keep having a problem with mcafee site adviser. The green check marks keep disappearing after a few days, I have tried to uninstall and reinstall but no luck. Logfile of Trend MICRO HijackThis v2.0.2
    Scan saved at 5:46:34 AM, on 2/22/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    BOOT mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ThreatFire\TFTray.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
    C:\Program Files\Trend Micro\Sniper.exe\Sniper.exe.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration CLASS) - http://echat.bellsouth.net/sdccommon/download/tgctlcm.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Chessmaster%20Challenge/Images/stg_drm.ocx
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -
    O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Chessmaster%20Challenge/Images/armhelper.ocx
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    O23 - Service: CachemanXP (CachemanXPService) - Outertech - C:\PROGRA~1\CACHEM~1\CachemanXP.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
    O24 - Desktop Component 1: (no name) - http://mbox.personals.yahoo.com/mbox/mboxlist

    --
    End of file - 6937 bytes
    Quote from: srtony1946 on February 22, 2009, 04:54:22 AM

    I was just wondering If I could delete the first 5 processes of this hijack this logg

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe

    Those? They are needed by the system! Why are you asking?Well, when I run hijackthis and copy and paste it to the hijackthis log TOOL I get these yellow triangle things with a exclamation point inside of them.
    935.

    Solve : deleted?

    Answer» DELETED
    936.

    Solve : Exploit.JPG What is it??

    Answer»

    I had my brother put AVG on his COMPUTER and I had him run a scan with all the settings for scan everything set. It didn't find anything. Then when opening some picture viewer SOFTWARE which shows the jpg's in THUMBNAIL mode avg comes up with a Virus threat detected Exploit.JPG. It's only a couple of pictures out of the total that they have. They ripped these pictures from a CD that one of their friend's put together on their computer. Is it possible that AVG does not see it unless it is accssed by the viewer? Is it piggybacking on the jpg and does not see it until it runs? What is it and how do you get rid of it?

    He's running Windows Vista. And is up to DATE.  Get rid of the pictures.
    -- OR --
    View the pictures in FireFox.
    The exploit becomes active when you try to view the file in some viewers. That was fixed, but it seems that you have a JPG that has the infection. Do you want to save the pictures? You can load then in a photo editor that is immune and then make a trivial change to the picture and save it. The Image program should write a good copy over the original file. Quote from: Geek-9pm on February 22, 2009, 06:07:32 PM

    Get rid of the pictures.
    -- OR --
    View the pictures in FireFox.
    The exploit becomes active when you try to view the file in some viewers. That was fixed, but it seems that you have a JPG that has the infection. Do you want to save the pictures? You can load then in a photo editor that is immune and then make a trivial change to the picture and save it. The Image program should write a good copy over the original file.

    I want to save the pictures.When you say trivial change to the jpg you mean open it in editor like paint for example and make a change for example like putting a dot in the corner of the picture? Is that what you mean by Trivial change? Open the folder with the pictures. Place mouse pointer over the icon or thumbnail. Right click, then open with and select an image program that does not have the problem. Microsoft paint should work. put just a tiny speck on a corner of the image. then save it. The image should now be 'clean' and you can open it in the buggy image viewer.
    If this does NOY work, plese come back here.
    937.

    Solve : "Windows cannot find csrss.exe......?

    Answer»

    Earlier today Threatfire has detected a highly malicious PROCESS related to csrss.exe and I chose to terminate the process.

    However, soon after, I keep getting the message:

    "WINDOWS cannot find csrss.exe. Make sure you typed the name correctly, and then try again. To search a file, CLICK the Start button, and then click Search"

    I do a search on the net and follow an instruction to check the csrss.exe ENTRY in Task Manager and try to terminate it, and I was PROMPTED it is a critical process and cannot be terminated. According to the site, this means it's not a virus.

    So how do I fix this?

    Thanks.Do you know if Threatfire quarantined the process?  If it did, try this:

    To Restore a Quarantined Item:
    1. Select 'Threat Control' from the left of the ThreatFire screen
    2. Click on 'Quarantined' tab
    3. Select the items you would like to be restored
    4. Click on 'Restore Selected' > Yes to Continue > OK

    Post back to see if this worked for you...

    938.

    Solve : computer is dead I think or at least broken. Need guidance plz!?

    Answer»

    I was on the net downloading something I probably shouldn't have obviously or I would not be in this situation.  I had a pop-up on my task bar SAYING I had a virus and needed to download and scan.  I did not click on it in case it was more problems.  My internet would not CLOSE and my computer was totally frozen.  So I had to hold the power button and do a hard shut down.  When I restarted my computer it went through the normal sequence of events that it would normally.  I came to the log in screen and entered my password and my computer continued to do it's thing.  My DESKTOP picture appeared as it always does but that is where everything gets strange.  My task bar does not appear nor does any of my icons.  All that is showing is my desktop picture.  I tried all buttons and mouse clicks to no avail, nothing is happening.  I tried alt, ctrl, delete hoping to view my task manager and it doesn't work and gives me a message about my admin disabled the task manager.  So I did a hard shut down again and tried booting in safe mode.  It did boot in safe mode but still the same results.  A black screen with no task bar or icons with safe mode in each corner.  So that is where I am at and I need some help from all of you that are much more knowledgeable than me about this and I thank you in advance for any and all suggestions that might come my way as I need to get up and running so I can continue to have a job.defineatly seems like your infected, can you click on anything in the START menu?No nothing at all.  I can see my mouse cursor but there is nothing to click on.  I even tried the WINDOWS start button on my keyboard and still no luck.can you try booting off your install disk and doing a repair?

    939.

    Solve : I'm infected?

    Answer»

    Hi,
    I was greatly helped by evil fantasy in the past and once again thank you so much for your selfless sevice to the rest of us. I don't know how I GOT INFECTED again. It has been QUITE a while. I have tried to be safe but my kids use this COMPUTER as well. I did download one video from youtube. I google a lot and so that may also have INVITED trouble, I don't know. Any way here are my logs.

    I ran an older version of CCleaner before looking up your instructions. I did not back up my registry. I hope that isnt going to cause too much trouble.

    Here are my logs
    ( oops, I included the Java log, sorry I don't know how to delete it)
    Thanks again


    [attachment deleted by admin]

    940.

    Solve : System Check Up??

    Answer»

    I was hoping to GET some help with a check up on my SYSTEM, I have had a few problems in the past.. and it seems that a few bugs might be coming up. I was wondering if anyone would be willing to help me run some checks for viruses, spyware, faulty programs, anything of that sort.

    Some of the problems I've been noticing have been related to my ANTIVIRUS not working PROPERLY, installs not connected to the internet, unable to ACCESS hotmail pages, and on IE google results are messed up again.

    Anything else i should be telling you guys?

    Thanks in advance!


    [attachment deleted by admin]

    941.

    Solve : Virus I believe??

    Answer»

    Well i just rebuilt my system so ive downloaded my BACK up files from carbonite and down loaded lots of programs all at the same time the last thing i did was put trend micro pro on for protection my wife opened a email that i thought had a virus  somthing called virus 360 (not associated with norton) removed it and thats when things started to happen.   I also down loaded some dvd codec around that time aswellUpdate Malwarebytes' Anti-Malware and run a Full scan

    • Open Malwarebytes' Anti-Malware
    • Select the Update tab
    • Click Check for Updates
    • After the update have been completed, Select the Scanner tab.
    • Select Perform full scan, then click on Scan
    • Leave the default options as it is and click on Start Scan
    • When done, you will be prompted. Click OK, then click on Show Results
    • Checked (ticked) all items and click on Remove Selected
    • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also FIND the log in the Logs tab. The bottom most log is the latest
    Malwarebytes' Anti-Malware 1.34
    Database version: 1799
    Windows 5.1.2600 Service Pack 3

    2/24/2009 3:41:22 PM
    mbam-log-2009-02-24 (15-41-22).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 110328
    Time elapsed: 9 minute(s), 57 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry KEYS Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    I also removed dvd codecs thinking of removeing trend micro as well any advise on that? I realy appreciate your time THANKSYOU can try removing Trend Micro to see if the COMPUTER acts right. I'm not seeing any files related to malware.
    942.

    Solve : Fast-Spreading Phishing Scam Hits Gmail Users?

    Answer»

    Read this: http://bits.blogs.nytimes.com/2009/02/24/viddyho-phishing-scam-hits-gmail/?hp

    "Gmail users who are LOGGED into the accompanying chat service Google Chat, as most are, have been getting messages that appear to be from friends, urging them to click on a Web address starting with tinyurl.com that takes them to a site called ViddyHo. The site asks for the person’s Gmail log-in information and then hijacks the ACCOUNT, SENDING out chat messages to all of the user’s contacts and spreading itself further."

    I got this spam in my gtalk and clicked on the link.  But unfortunately I did not sign in.  Is my gmail a/c safe???
    I can't even get to the ViddyHo site using Firefox and IE says it isn't a web site. You should use Firefox, it blocks it as a phishing site.

    Download random's system information tool (RSIT) by random/random from and save it to your Desktop.

    • Double click on RSIT.exe to run.
    • Click CONTINUE at the disclaimer screen.
    • Once it has finished, two logs will open.
    • log.txt <will be maximized and info.txt <will be minimized
    • Please post the contents of both logs in the next reply.
    943.

    Solve : i made some logs! (malware & hijackthis)?

    Answer»

    Hi. Attached are my logs from HijackThis and MALWAREBYTES. SUPERANTISPYWARE found nothing to log.
    I went through the Malware Removal Steps after having found a drivez.log file in my C: drive.
    Thanks in ADVANCE for any help!

    [attachment deleted by admin]

    944.

    Solve : Help with deleting infections?

    Answer»

    It MIGHT find some cookies but I'm pretty sure it won't find anything dangerous. I only use Spybot for the Immunize feature, nothing more. MalwareBytes and SUPERAntiSpyware are the best for scanning/removing malware.It found a double click and right media which are both "1 entries in browsing". Looks clean! Thank you so much, but before this fix section is finished, can you explain immunize a little more. I read the report and don't completely understand it. Basically what does it actually do, and when should I implement it?It works silently. Once you click the Immunize button it ads KNOWN malicious web sites to your Hosts file which protects your browser from malware. It works with Internet Explorer and Firefox.

    See here Interesting Facts About Spybot's Immunize Feature. Thi sarticle is a little old but is still relevant. It now works with Firefox also.

    Here are a few more suggestions.

    Use the Secunia Software Inspector to check for out of date software.

    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all CRITICAL updates.

    ----------

    Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable SHOPPING sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX CONTROLS are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Ok I'll have to check it out, thanks for everything  . Btw for the immunize feature should I keep it on at all times or what? And if I on;y go to safe websites anymore and don't torrent or download games, would I need any of this?You never know when you might stumble on to a bad web site.

    You don't turn on or off the Immunize feature. It just customizes your Hosts file. It doesn't run. Be sure to Immunize whenever you update Spybot.Ok, thank you for everything. I hope other people are as lucky as me to have you fixing there computer. Once again, thanks.Your welcome.

    Safe surfing...
    945.

    Solve : virus/cookies in Hidden folder?

    Answer»

    I scanned my harddrive and some tracking cookies and virus were found in folder like C:\appdata\roaming\microsoft\windows\cookies
    I try to use Window explorer to check out those files but I can't even locate the cookies subfolder.  Is it hidden folder?  How can I locate it?If you want to clean cookies you can automatically do so with CCleaner (free). If you have multiple user accounts it will need to be run on each one.

    Download CCleaner Slim and save it to your Desktop.
    When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
    Follow the prompts to install the program.
    COMPLETE the INSTALLATION then:

    • Double-click the CCleaner shortcut on the desktop to start the program.
    • Click on the Options block on the left, then choose Cookies.
      • Under Cookies to Delete, highlight any cookies you would like to retain permanently
      • Click the right ARROW > to move them to the Cookies to Keep window.
    • Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours
    • Click Cleaner on the left then Run Cleaner on the right to run the program.
    • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner
    • Caution: It is not recommended that you use the 'Registry' feature unless you are very familiar with the registry.
    • Exit CCleaner after it has completed its process.
    ----------

    For scanning and removing unwanted cookies you can use SUPERAntiSpyware Free Edition.

    Download and install SUPERAntiSpyware Free for Home Users
    • Start SUPERAntiSpyware and click Check for updates
    If you encounter any problems while downloading the updates, manually download and unzip them from here

    • Once the update is finished, on the main screen, click Scan your computer
    • Check Perform Complete Scan
    • Click Next to start the scan.
    When finished SUPERAntiSpyware will list all the infections found.
    Make sure everything found has a check next to it and PRESS Next
    Then click Finish

    It is possible that the SUPERAntiSpyware asks to reboot the PC in order to delete some files.
    946.

    Solve : log in/log off loop?

    Answer»

    I got some virus surfing the net.  I brief rundown of my problem.  I have windows XP media center w/SP3.  At first when I logged on I could not see my icons or task bar, just my desktop with nothing else.  I tried alt-ctrl-delete and my task manager was disabled.  I got that part fixed and ran Ad-ware through the task manager and it found a few viruses that I cleaned up and my task bar and icons came back.  It asked me to reboot so I did.  It must have deleted or changed something in my log in/off loop because when I logged back in it LOGS me off in the matter of seconds.  I tried with the admin ACCOUNT and in safe mode with nothing working.  Next I got on my dad's computer and searched some websites and I came ACROSS some suggestions to boot from my xp cd-enter recovery-go to my c:\windows\system32-copy userinit.exe wsaupdater.exe-(it said one file copied)-exit-reboot your computer and you should be able to log in-then got to phase II and regedit.   

    But my problem is after I copied the exe files listed and exited and restarted my computer, I logged in and it logged me right back out so something is still wrong.  I have read other fixes that mention going through a network computer and edit the registry, but I dont have one so this is not an option.

    So basically, I have done all I know how or have read, other than a hammer, and I still cant log in.  Looking for some guidance please!

    Thanks a million,
    bjack2345We can't do MUCH for you if your computer won't boot. Editing the registry is likely a BAD idea.

    You can try running a free Live CD to see if you can repair it that way.

    Dr.Web LiveCD - http://www.freedrweb.com/livecd/
    Avira AntiVir Rescue System - http://www.free-av.com/en/products/12/avira_antivir_rescue_system.html

    947.

    Solve : C:\Windows\sysvxd.exe problem?

    Answer»

    Last week I had a problem in that a program CALLED PC Police downloaded itself to my computer.  It WOULD not let me get to the internet and I did not have a spyware program on my computer.  I bought WEBROOT Spy Sweeper which deleted the PC Police program.

    Now a window pops up that READS C:\Windows\sysvxd.exe  The NTVDM CPU has encountered an illegal instruction.  CS:0dc4 IP:03a1 OP:6361 72645f  Choose 'CLOSE' to terminate application.

    I choose close but it keeps coming back.  I have read thru some of the other posts and found similar items.

    I have read thru the Malware Removal Guide and have attached the 3 logs.

    Please let me know what else I need to do.

    thanks



    [attachment deleted by admin]i have this same error on my network computers, any info how to resolve it?

    948.

    Solve : mcafee error?

    Answer»

    mcafee FRAMEWORK SERVICE is missing in the services.mscMore INFO please.

    How do you EXPECT US to help you with that?

    949.

    Solve : Need help with trojans or a virus plz?

    Answer»

    Hello, you have a very informative site. I have discovered that I have a couple trojans on my computer and need help to remove them. I went thru everything on your 'Read this before requesting malware' page and I have all of the logs that you request.

    My computer was fine until Windows required two downloads earlier today. After the system rebooted, my computer acted strange. IE windows popped up and went to a site I have never been to. Also, after I closed out the IE windows and about five minutes later, I heard advertisements without being on a webpage. My antivirus program, Avira AntiVir Personal, detected two trojans:
    TR/crypt.xpack.gen
    RKIT/Agent.67584 root kit

    Later, it also picked these up:
    windows\temp\omvguyxp.exe
    windows\system32\SHDOCVW.dll

    Also, each time it opened up IE, the page was strange looking. None of the pictures showed up anymore. Some of the icons no longer show on my computer either, such as on 'Help and Support'.

    After my computer rebooted, I received a message from Windows SECURITY Alerts saying it was not on. It will not allow me to turn it on anymore. I get a message stating 'The Security Center service can't be started'.  I am the only person that uses my computer and I run it as the Administrator.

    ADDED AT 7:00am:

    I woke up to about 25 IE windows opened (I stopped counting by then). My antivirus did its normal update but the picture on the confirm screen was not there like it usually is (some on my computer are GONE as stated above). Some of the sites the pages were showing were:
    lemonyard.info
    fixesmanual.info
    impression.name
    godirectshowroom.biz

    As I'm typing right now, IE keeps bringing up new windows.

    Evilfantasy (or any other pro) I eagerly await & appreciate your help in this matter.

    Eevie

    [attachment deleted by ADMIN]

    950.

    Solve : Rootkit removal please help I feel like tearing my hair out?

    Answer»

    Done that and it found no rootkits  I didn't think it would.

    We can do another scan to be sure. It will take a while but should put your mind at ease.

    Run the F-Secure Online Scanner for Viruses, Spyware and RootKits.

    Note: This Scanner is for Internet EXPLORER Only!

    • Click on Online Services and then Online Scanner
    • Accept the License Agreement.
    • Once the ActiveX installs,Click Full System Scan
    • Once the download completes,the scan will begin automatically.
    • The scan will take some time to finish,so please be patient.
    • When the scan completes, click the Automatic cleaning (recommended) button.
    • Click the Show Report button and Copy&Paste the entire report in your next reply.
    Scanning Report
    Friday, February 20, 2009 23:28:25 - 01:04:35

    Computer name: MR-F7ADB6866673
    Scanning type: Scan system for malware, rootkits
    Target: C:\ F:\
    Result: 3 malware found
    TrackingCookie.2o7 (spyware)

        * System

    TrackingCookie.Doubleclick (spyware)

        * System

    TrackingCookie.Webtrends (spyware)

        * System

    Statistics
    Scanned:

        * Files: 29726
        * System: 2849
        * Not scanned: 7

    Actions:

        * Disinfected: 0
        * Renamed: 0
        * Deleted: 0
        * None: 3
        * Submitted: 0

    Files not scanned:

        * C:\PAGEFILE.SYS
        * C:\WINDOWS\SYSTEM32\DRIVERS\SPTD.SYS
        * C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
        * C:\WINDOWS\SYSTEM32\CONFIG\SAM
        * C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
        * C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
        * C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM

    Options
    Scanning engines:

        * F-Secure USS: 3.0.0
        * F-Secure Hydra: 3.6.8511, 2009-02-20
        * F-Secure AVP: 7.0.171, 2009-02-20
        * F-Secure Pegasus: 1.20.0, 1970-00-01
        * F-Secure Blacklight: 0.0.0

    Scanning options:

        * Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JOB LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
        * Use Advanced heuristics

    All that was found is cookies.

    Quote
    TrackingCookie.2o7 (spyware)

    TrackingCookie.Doubleclick (spyware)

    TrackingCookie.Webtrends (spyware)

    I never did put much faith in the AVG Antirootkit scanner. I think it's safe to say I was right..The AVG is still finding "C:\WINDOWS\System32\Drivers\azrbl4oh.SYS";"Hidden driver";"Object is hidden"

    If I still get BSOD do you think I should format the drive?

    I knew it was a problem with the drivers and I blamed the printer at first. One of the 1st blue screens said it was a driver problem and SOMETHING to do with the kernel stack. I have uninstalled just about everything and the problem persists so it can't be any legitimate driversThere aren't many unknown rootkits out there and whatever AVG is hitting on I think is not a rootkit but a system file it sees as malicious. A false positive.

    Although I could be totally wrong so you might want to ask in the AVG Anti-Rootkit forum why it's doing this.Ok many thanks for all your help. You've been brilliant.

    Thank you
    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete:
      • ComboFix and its associated files and folders.
      • VundoFix backups, if present
      • The C:\Deckard folder, if present
      • The C:_OtMoveIt folder, if present
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      1. Double click OTMoveIt3.exe to launch it.
      Vista users right click and choose Run As Administrator
      2. Click on the CleanUp! button.
      3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
      4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
      5. Once complete exit out of OTMoveIt3

      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ---------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Its still ll messed up. Another anti virus keeps coming up with sptd.exe as a problem and also OSA09.sys. Anyway looks like I am going to have to format after all.  I have a problem though I would like to backup my drivers but as this is seemingly where the problem lies I will not be able to do this. Will I be able to find the drivers easily enough after formatting? Quote
      Another anti virus keeps coming up with sptd.exe as a problem

      What is another antivirus?

      Do you have virtual drives or daemon tools installed?Yes and unfortunately I cannot delete it because I deleted all those files before. So its kind of stuck on the systemIt's not malware, it's a Daemon Tools file.

      Download  FindFile by Atribune

      1. Extract the contents to your Desktop
      2. Double click on FileFind.exe to open the program.
      3. In the File: box enter sptd.exe
      4. Click on the Search button.
      5. Wait. If any files are found, a list of file locations will APPEAR in the List of Files: box.
      6. Click on the Export button.
      7. This will open a Notepad file named Export.txt. Copy and paste it to your next post please.

      There will also be a copy of the Export.txt saved in C:\Export.txt

      Also repeat the above steps for OSA09.sys