Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1001.

Solve : Symantec...."scanning message 1 of 1"?

Answer»

I have Norton Antivirus 2007.  Yesterday for the first time ever, I noticed that the small Symantec box in the lower right of my screen gradually started FLAGGING with... scanning message 1 of 1 although I am not sending any messages.  Suddenly my whole screen was INUNDATED with hundreds, perhaps thousands of em as they would disappear and reappear replenishing themselves.  I couldn't get to the Symantec main window or anything else for that matter.  The only way I could shut down was to unplug.  When I booted back up I stayed at my desktop until the same thing occurred, and again I unplugged and restarted, only this time I went directly to Norton Antivirus Settings while I could still get there and turned off outgoing email scanning, and set the change for permanently.  This seems to work fine for me although I know that something is wrong.  What sort of problems am I asking for by running like this ?  I ran several full scans and came out clean.  There's no further indication of any sort of problem any where that I know of.

I would appreciate any comments or suggestions 

  Download HijackThis  to your desktop.
Double-click on the file you just downloaded.
Click on the "Install" button to install.
It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Please do not change the default install location.
Upon install, HijackThis should open for you.
Now close HijackThis to rename it to analyze.

Important
Rename the Hijackthis.exe file to analyze.exe.
This is important because some forms of malware can hide from HijackThis.
Right click the HijackThis.exe file in C:\Program Files\Trend Micro\HijackThis
Choose Rename.
Type in analyze and press the enter key.
Right click the analyze.exe file and send to desktop to CREATE a shortcut.

Next click on the "Do a system scan and save a log file" button.
HijackThis will scan and then a log will open in notepad.
In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
Please save the log as a text (.txt) file.
In your post, add the log as an Attachment.

* Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.Thanks evil, I'll check back with you later and tell you how it goes.  I don't have time to play with it at this moment...ThanksIf you are not monitoring your internet connection and are away from the computer, I would physically disconnect it from the internet. (remove the cable from the wall) If you are on an always on connection and this is happening, your ISP will cut you off for spamming.Sorry for the delay evil... Here's the log...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:27:11 PM, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes :
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exeg Process
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\AcO8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147904416968
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147904410343
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:exe.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Pml DRIVER HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--* Please download Combofix by sUBs. Place it on your Desktop. combofix.exe
* Double click combofix.exe & follow the prompts. Enter 1 and press enter at the prompt.
* When finished, it shall produce a log for you. Attach that log in your next reply.
Combofix will create a backup to anything removed in C:\qoovox

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


Next post please add:
Combofix log
New HijackThis logcombofix log.......


ComboFix 07-11-08.3 - Compaq_Owner 2007-11-11 16:58:46.2 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.582 [GMT -10:00]
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\alexaie.dll
C:\WINDOWS\alxie328.dll
C:\WINDOWS\alxtb1.dll
C:\WINDOWS\btgrab.dll
C:\WINDOWS\dlmax.dll
C:\WINDOWS\pynix.dll
C:\WINDOWS\susp.exe
C:\WINDOWS\Temp\1186997838.exe
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((

C:\WINDOWS\alxie328.dll
C:\WINDOWS\alxtb1.dll
C:\WINDOWS\btgrab.dll
C:\WINDOWS\dlmax.dll
C:\WINDOWS\pynix.dll
C:\WINDOWS\susp.exe
C:\WINDOWS\Temp\1186997838.exe
D:\Autorun.inf

))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_ICF
-------\ICF


-------\LEGACY_ICF
-------\ICF




(((((((((((((((((((((((((   Files Created from 2007-10-12 to 2007-11-12  )))))))))))))))))))))))))))))))
.

2007-11-11 16:38   51,200   --a------   C:\WINDOWS\NirCmd.exe
2007-11-11 14:33      d--------   C:\Program Files\Trend Micro
2007-11-11 08:32   552   --a------   C:\WINDOWS\system32\d3d8caps.dat
2007-10-30 19:55   625,032   --a------   C:\WINDOWS\system32\SymNeti.dll
2007-10-30 19:55   242,056   --a------   C:\WINDOWS\system32\SymRedir.dll
2007-10-30 19:55   191,536   --a------   C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-30 19:55   145,968   --a------   C:\WINDOWS\system32\drivers\symfw.sys
2007-10-30 19:55   39,856   --a------   C:\WINDOWS\system32\drivers\symids.sys
2007-10-30 19:55   37,936   --a------   C:\WINDOWS\system32\drivers\symndisv.sys
2007-10-30 19:55   35,120   --a------   C:\WINDOWS\system32\drivers\symndis.sys
2007-10-30 19:55   27,696   --a------   C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-30 19:55   12,848   --a------   C:\WINDOWS\system32\drivers\symdns.sys

.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-08 21:08   14,336   ----a-w   C:\WINDOWS\system32\svchost.exe
2007-11-06 00:02   ---------   d-----w   C:\Program Files\Common Files\Symantec Shared
2007-10-31 05:24   12,963   ----a-w   C:\WINDOWS\system32\drivers\SymRedir.cat
2007-10-31 05:24   1,358   ----a-w   C:\WINDOWS\system32\drivers\SymRedir.inf
2007-10-03 21:51   ---------   d-----w   C:\Program Files\Norton AntiVirus
2007-10-03 21:49   805   ----a-w   C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-03 21:49   60,800   ----a-w   C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-03 21:49   123,952   ----a-w   C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-03 21:49   10,740   ----a-w   C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-03 21:49   ---------   d-----w   C:\Program Files\Symantec
2007-09-20 22:28   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Symantec
2007-09-19 00:44   10,662   ----a-w   C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-19 00:44   10,662   ----a-w   C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-19 00:44   10,658   ----a-w   C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-19 00:44   1,430   ----a-w   C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-19 00:44   1,421   ----a-w   C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-19 00:44   1,415   ----a-w   C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-19 00:43   43,696   ----a-w   C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-19 00:43   317,616   ----a-w   C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-19 00:43   278,576   ----a-w   C:\WINDOWS\system32\drivers\srtsp.sys
2007-08-21 06:15   683,520   ----a-w   C:\WINDOWS\system32\inetcomm.dll
2006-12-03 06:13   160   ----a-w   C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-10-21 20:01]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 15:22]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-21 19:31]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 11:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 06:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" []
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]




C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [2005-10-20 12:04:08]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=C:\WINDOWS\pss\Compaq Connections.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP DIGITAL Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=C:\WINDOWS\pss\SpySubtract.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Status Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Status Monitor.lnk
backup=C:\WINDOWS\pss\Status Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
Rundll32.exe SiSPower.dll,ModeAgent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe


.
Contents of the 'Scheduled Tasks' folder
"2007-11-10 06:18:59 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Compaq_Owner.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-11 17:00:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-11 17:00:57
.
   --- E O F ---
OK, that helped. We will want to do another scan though.

There are a lot of directions here but it only takes a minute to go through. They include mainly details on how to get a correct log that will be needed in the next post.

First however we need to do a quick cleaning.

Please download ATF Cleaner by Atribune. ATF Cleaner.exe This program does not require an installation. The executable actually runs the program.

NOTE: ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
* Double-click ATF-Cleaner.exe to run the program.
* Under Main choose: Select All
* Click the Empty Selected button.

If you use Firefox browser
* Click Firefox at the top and choose: Select All
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
* Click Opera at the top and choose: Select All
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main ATF Cleaner menu to close the program.

==========

Download AVG Anti-Spyware saving the installation file to your desktop.

* Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
* Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
* On the main screen select the icon "Update" then select the "Update now" link.
* Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
* Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
* Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
* Under How to scan?
**All checkboxes should be ticked.
* Under "Reports" Select "Automatically generate report after every scan"
* Also, Un-Select "Only if threats were found".
* Under "What to scan"?
**"Select Scan every file".
* Now close AVG Anti-Spyware and procede to the next set of instructions.

Picture For Visual Reference


* Reboot your computer into "Safe Mode". You can do this by restarting your computer and continually tapping the "F8" key until a menu appears. Use your up arrow key to highlight "Safe Mode" then press "ENTER".
* IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
* Now lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
* Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
* AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
* Once the scan is complete do the following:
* If you have any infections you will prompted, when prompted select "Apply all actions".
* Next select the "Reports" icon at the top.
* Select the "Save Report As" button in the lower left hand of the screen and save it to a text (.txt) file on your desktop (make sure to remember where you saved that file, this is important).
* Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the results of the AVG Anti-Spyware report scan.

=====

Next post please add:
AVG scan log
New HijackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:38:51 PM, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147904416968
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147904410343
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 6647 bytes
I can't seem to complete the AVG Anti-Spyware installation...can't get an icon on the desktop, also can't access the AVG main window...OK, we will try another scanner, first I need you to do this:

Enable Viewing Of Hidden System Files & Folders

Windows XP
1. Right Click Start.
2. Select Control Panel.
3. Select the Tools menu and click Folder Options.
4. Select the View Tab.
5. Under the Hidden files and folders heading select Show hidden files and folders.
6. Uncheck the Hide extensions for known file types option.
7. Uncheck the Hide protected operating system files (recommended) option.
8. Click Apply.
9. Click OK.

Then go to http://www.virustotal.com/
Select "Browse" and navigate to C:\WINDOWS\system32\d3d8caps.dat
Double click d3d8caps.dat it to enter it in the window and then select "Send File"
This will run the file through 32 different virus scanners and show the results.
Let me know what (if anything) is reported.

=====

Again with the long instructions....

 Download Superantispyware (SAS)

SUPERAntispyware Free Edition

Install it and double-click the icon on your desktop to run it.
*  It will ask if you want to update the program definitions, click Yes.
*  Under Configuration and Preferences, click the Preferences button.
*  Click the Scanning Control tab.
*  Under Scanner Options make sure the following are checked:
+  Close browsers before scanning
+  Scan for tracking cookies
+  Terminate memory threats before quarantining.
+  Please leave the others unchecked.
+  Click the Close button to leave the control center screen.
*  On the main screen, under Scan for Harmful Software click Scan your computer.
*  On the left check C:\Fixed Drive.
*  On the right, under Complete Scan, choose Perform Complete Scan.
*  Click Next to start the scan. Please be patient while it scans your computer.
*  After the scan is complete a summary box will appear. Click OK.
*  Make sure everything in the white box has a check next to it, then click Next.
*  It will quarantine what it found and if it asks if you want to reboot, click Yes.
*  To retrieve the removal information for me please do the following:
+  After reboot, double-click the SUPERAntiSpyware icon on your desktop.
+  Click Preferences. Click the Statistics/Logs tab.
+  Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
+  It will open in your default text editor (such as Notepad/Wordpad).
+  Please save the notepad file to your desktop by clicking (in notepad) "File" "Save As".
*  Click close and close again to exit the program.
*  Please add the log in the next post.Ok evil,  I think I got it together this time....


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/11/2007 at 10:16 PM

Application Version : 3.9.1008

Core Rules Database Version : 3342
Trace Rules Database Version: 1343

Scan type       : Complete Scan
Total Scan Time : 01:03:50

Memory items scanned      : 408
Memory threats detected   : 0
Registry items scanned    : 5765
Registry threats detected : 0
File items scanned        : 58730
File threats detected     : 6

Adware.Tracking Cookie
   C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
   C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
   C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
   C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
   C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt

Trojan.Downloader-CounterMeasures
   C:\QOOBOX\QUARANTINE\C\WINDOWS\TEMP\1186997838.EXE.VIR

1002.

Solve : iedefender please help?

Answer»

I keep getting this pop saying my computer is INFECTED and blah, blah, blah, basically its an iedefender pop up, and its pissing me off. I think i deleted all files that have to do with it. i scanned my pc with norton and this pop up is still coming up. anysuggestions?Download HijackThis  to your desktop.
Double-click on the file you just downloaded.
Click on the "Install" button to install.
It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Please do not change the default install location.
Upon install, HijackThis should open for you.

Next click on the "Do a system SCAN and save a log file" button.
HijackThis will scan and then a log will open in notepad.
In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
Please save the log as a text (.txt) file.
In your post, add the log as an Attachment.

* Don't have Hijackthis fix anything yet. Most of what it finds will be HARMLESS or EVEN required.
** Don't use the Analyse This button. It's findings are DANGEROUS if misinterpreted.

1003.

Solve : rookie with virus problem?

Answer»

First I need to take care of this problem:
Windows cannot find C\WINDOWS\rundll32.exe

Seems I can't open anything without this message.

Any thoughts on this?
Do you have your ME install disk?Yes ,,, This is a copy/pasted guide and not mine so please read carefully and ASK any questions if you are unclear on what to do.

Make sure your Windows CD-ROM's in the drive.
Go to Start/run, and type SFC.
Choose 'Extract One File From Installation Disk'.
Type rundll32.exe, not worrying about its location. Then, click Start.
Next to 'Restore From', type in or browse for the file’s location, which is probably in the WinME folder of your installation CD-ROM (typically D:\WinME), or in your Windows\Options\Cabs folder, as the CASE may be.
Then, next to 'Save File In', enter, or browse to C:\Windows, and click OK. System File Checker looks for the file, saves it as you requested, and then tells you that 'the file has been successfully extracted'.
That should put things right.Just WANT to say thanks for all the help. I did a system restore and removed all the anti-virus stuff I had running. I ran the SuperAntiSpyware and EVERYTHING is gone and the computer appears to be running quite normal.

I'm not getting the error message any longer regarding this file either:

rundll32.exe

Any thoughts?Sounds like you took the system beck to a POINT before the error occurred.

Run an online scan to be sure all is well. http://housecall.trendmicro.com/This is a pretty long scan ,, I'll let you know how I make out. Thanks

1004.

Solve : Unknown symbol on desktop?

Answer»

I discovered this symbol on my desktop. I can not remove it.  It appeared about TWO weeks ago in the top left corner of my desk top.  I can drag it to any part of the screen  and it will stay there. however, when i shut down or restart it appears in the upper left corner again. I click on it it does not open or do anything. I have tried to deleate it, move to recycle ben nothing seems to effect it.   I ran Trend Miicro virus
scan several times found no problems.

Description of the symbol:

It is a small rectangular box, top part completly shaded and bottom half not shaded in. At times the small box appears completly shaded in.

Any help or ideas would be appreciated.


Can you post a screenshot ? ?
Thanks for the response,

There does not seem to be a way to post a screen shot, any ideas let me know. I was able to post the screen shot see ATTACHED. The object or symbol is the small blue rectangle on the bottom of the desktop.

Thanks

[getting disk space - attachment deleted by admin]What happens when you right click on it?If you move your arrow to one of the sides or corners, does it turn into the double arrows pointing in opposite directions?Also, it may help, if you post a screenshot of the icon, itself, possibly magnified.
To get a screenshot, you may want to install free version of ScreenHunter: http://wisdom-soft.com/products/screenhunter.htm
You may magnify it, using MS Paint.I tried right clicking on it, the only thing that happens is the shading inside the box either darkens or lightens.

As for moving the arrrow to the sides or corner, nothing changes.

Quote

Also, it may help, if you post a screenshot of the icon, itself, possibly magnified.
To get a screenshot, you may want to install free version of ScreenHunter: http://wisdom-soft.com/products/screenhunter.htm
You may magnify it, using MS Paint.
Download HijackThis.
Do a system scan and save a log file.
Post your log file at the Computer Viruses and Spyware board.

(I have finally FINISHED reading HijackThis TUTORIAL at AumHa. This time, I'll try to do my best when reading the log) Quote from: dairyman on November 07, 2007, 12:13:55 AM
(I have finally finished reading HijackThis Tutorial at AumHa. This time, I'll try to do my best when reading the log)

You are not qualified to analyze logs until you have gone through the PROPER training of a HijackThis course.  Reading a tutorial is not enough.  How many times does this need to be said? Quote from: CBMatt on November 11, 2007, 05:55:08 AM
You are not qualified to analyze logs until you have gone through the proper training of a HijackThis course.  Reading a tutorial is not enough.  How many times does this need to be said?

OK, I won't read any HJT log's yet.
I am taking a course on how to read HJT logs.
1005.

Solve : Can someone look at my Hijack this log please?

Answer»

Yesterday I was just browsing various websites and then my computer seemed shut down automatically when I saw a popup message that said "Thank you for your upload" or something of the sort I don't remember I was very tired. Today I logged on my computer and my computer was acting weird. I was convinced that someone had hijacked my computer. I browsed various websites and downloaded Hijackthis and deleted (with help) various items.

However my computer is still acting weird and I can log into websites but then it goes back to the website and says I need to log in again. I am currently running Ad-Aware, an anti-virus program and spybot!

Help please I don't know what to do! Here is my log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:31:33 AM, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

--
End of file - 2553 BYTES

The log is not showing any malware. Although we can take a closer look.

First though lets rename HijackThis.

Rename the Hijackthis.exe file to analyze.exe.
This is important because some forms of malware can hide from HijackThis.
Right click the HijackThis.exe file in C:\Program Files\Trend Micro\HijackThis
Choose Rename.
Type in analyze and press the enter key.
Right click the analyze.exe file and send to desktop to create a shortcut.

=====

Next:
Use the ESET Nod32 Online Scanner

Click YES, I accept the Terms of Use. Then Start.

The scan report is saved by default in C:\Program Files\EsetOnlineScanner\log.txt

Add the EsetOnlineScanner\log.txt in your post.

=====

Next post please add
ESET scan log
Renamed HijackThis log

Mokay! Thanks

Hijackthis Log renamed to Analyze.exe

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19:44 AM, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\analyze.exe\Analyze.exe.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

--
End of file - 2624 bytes
 

The ESET scan log is still going. And it'll probably take a while but I figured I might as well post this now.

:/The HijackThis log is still showing no malware.

We will wait on the online scan and go from there.Erg. This is the Eset Scan Log... Thank you!

# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=2652 (20071111)
# vers_arch_module=1.059 (20071108)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=48298892ec71c74f9e9f243035e2557c
# end=finished
# remove_checked=false
# unwanted_checked=false
# utc_time=2007-11-11 04:37:34
# local_time=2007-11-11 11:37:34 (-0500, Eastern Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=450640
# found=1
# scan_time=4684
C:\Documents and Settings\Owner\Local Settings\Temp\wr-1-2000219.exe   Win32/TrojanDownloader.Agent.NPG trojan   48A17609B2A9DF2047D3EB64C62DE654
OK, the scan turned up something new.

A few more steps, this will not take as long.

Please download ATF Cleaner by Atribune. ATF Cleaner.exe This program does not require an installation. The executable actually runs the program.

NOTE: ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd LIKE to save. Please move them to a different directory first.
* Double-click ATF-Cleaner.exe to run the program.
* Under Main choose: Select All
* Click the Empty Selected button.

If you use Firefox browser
* Click Firefox at the top and choose: Select All
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
* Click Opera at the top and choose: Select All
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main ATF Cleaner menu to close the program.

=====

1. Please download Combofix by sUBs. Place it on your Desktop. combofix.exe
2. Double click combofix.exe & follow the prompts. Enter 1 and press enter at the prompt.
3. When finished, it shall produce a log for you. Attach that log in your next reply.
Combofix will create a backup to anything removed in C:\qoovox

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
ComboFix 07-11-08.3 - Owner 2007-11-11 12:53:18.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.562 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\My Documents\ComboFix.exe
 * Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini

.
(((((((((((((((((((((((((   Files Created from 2007-10-11 to 2007-11-11  )))))))))))))))))))))))))))))))
.

2007-11-11 12:51   51,200   --a------   C:\WINDOWS\NirCmd.exe
2007-11-11 10:16      d--------   C:\Program Files\EsetOnlineScanner
2007-11-11 09:20      d--------   C:\WINDOWS\LastGood
2007-11-11 08:41      d--------   C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-11 08:35      d--------   C:\Program Files\Common Files\Wise Installation Wizard
2007-11-11 08:35      d--------   C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-11 07:25      d--------   C:\Program Files\Trend Micro
2007-11-05 20:35      d--------   C:\Documents and Settings\Owner\Application Data\MP3Rocket
2007-11-05 20:27      d--------   C:\Program Files\MP3 Rocket
2007-10-21 09:32      d--------   C:\Documents and Settings\Owner\Application Data\.wyzo
2007-10-19 20:51      d--------   C:\Program Files\iTunes
2007-10-19 20:47      d--------   C:\Program Files\Common Files\Apple
2007-10-19 20:47      d--------   C:\Program Files\Apple Software Update
2007-10-19 20:47      d--------   C:\Documents and Settings\All Users\Application Data\Apple

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-11 13:35   ---------   d-----w   C:\Program Files\Lavasoft
2007-11-11 11:54   ---------   d-----w   C:\Program Files\Symantec AntiVirus
2007-11-11 11:54   ---------   d-----w   C:\Program Files\Microsoft Home Publishing
2007-11-06 01:33   ---------   d-----w   C:\Program Files\Java
2007-11-06 01:29   ---------   d-----w   C:\Program Files\LimeWire
2007-11-01 20:13   ---------   d-----w   C:\Documents and Settings\Owner\Application Data\WeatherBug
2007-10-21 14:32   ---------   d-----w   C:\Documents and Settings\Owner\Application Data\.wyzo
2007-10-21 14:24   ---------   d-----w   C:\Program Files\Motive
2007-10-21 14:24   ---------   d-----w   C:\Program Files\IrfanView
2007-10-20 01:51   ---------   d-----w   C:\Program Files\iPod
2007-10-20 01:49   ---------   d-----w   C:\Program Files\QuickTime
2007-10-05 20:50   ---------   d-----w   C:\Program Files\Cucusoft
2007-09-26 00:31   ---------   d-----w   C:\Documents and Settings\Owner\Application Data\DMCache
2007-09-18 22:35   ---------   d-----w   C:\Program Files\MSN Messenger
2007-08-22 15:01   1,598,759   --sh--w   C:\WINDOWS\system32\jjkmp.ini2
2007-08-22 13:05   1,589,947   --sh--w   C:\WINDOWS\system32\jjkmp.bak2
2007-08-21 23:26   1,590,504   --sh--w   C:\WINDOWS\system32\jjkmp.bak1
2007-08-21 06:15   683,520   ------w   C:\WINDOWS\system32\inetcomm.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LightSurf.lnk]
backup=C:\WINDOWS\pss\LightSurf.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sprint FastConnect virtual assistant.lnk]
backup=C:\WINDOWS\pss\Sprint FastConnect virtual assistant.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

R0 _wff;_wff;C:\WINDOWS\system32\drivers\_wff.sys
R3 FVNETusb;Linksys Wireless-B USB Network Adapter v2.8 Driver;C:\WINDOWS\system32\DRIVERS\vnet558x.sys
S3 GcKernel;Microsoft SideWinder Value Add - Filter Driver;C:\WINDOWS\system32\DRIVERS\GcKernel.sys
S3 HIDSwvd;Microsoft SideWinder Virtual HID Device Mini-Driver;C:\WINDOWS\system32\DRIVERS\HIDSwvd.sys
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d2b75a6-cfe1-11d8-a628-806d6172696f}]
\Shell\AutoRun\command - D:\Info.exe folder.htt 480 480

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-20 01:47:52 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-11 12:54:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-11 12:55:12
.
   --- E O F ---


Oh man, it worked I can go onto websites now and it doesn't go back to the original webpage after I log in!

thank you!
Good to hear, but there is still more to do.

Please download VundoFix.exe to your desktop.

* Double-click VundoFix.exe to run it.
* Put a check next to Run VundoFix as a task.
* You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
* When VundoFix re-opens, click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will shutdown your computer, click OK.
* Turn your computer back on.
* Please post the contents of C:\vundofix.txt and a new HiJackThis log.

Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above INSTRUCTIONS starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

Please let Vundo finish, sometimes it can take multiple passesVundoFix V6.5.11

Checking Java version...

Java version is 1.4.2.3
Old versions of java are EXPLOITABLE and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 1:48:12 PM 11/11/2007

Listing files found while scanning....

No infected files were found.


Beginning removal...

VundoFix V6.5.11

Checking Java version...

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 1:50:25 PM 11/11/2007

Listing files found while scanning....

No infected files were found.


Beginning removal...


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:13:53 PM, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\analyze.exe\Analyze.exe.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

--
End of file - 2531 bytes

Why is your antivirus not turned on?

=====

Now download The Avenger By Swandog46, and save it to your Desktop.

* Extract avenger.exe from the Zip file and save it to your desktop
* Run avenger.exe by double-clicking on it.
* Check the 'Input script manually' box.
* Click on the magnifying glass icon.
* Copy everything in the Quote box below, and paste it in the box that opens:

Quote


Drivers to unload:
_wff
Files to delete:
C:\WINDOWS\system32\drivers\_wff.sys
C:\WINDOWS\system32\jjkmp.ini2
C:\WINDOWS\system32\jjkmp.bak2
C:\WINDOWS\system32\jjkmp.bak1

Note: the above quote was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

* Now click the 'Done' button.
* Click on the traffic light icon and OK the prompt.
* You will be prompted to restart, click OK at the prompt and your PC should reboot, if not, reboot it yourself.
* A log file from Avenger will be produced at C:\avenger.txt

The Avenger will automatically do the following:

* It will Restart your computer. (In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
* On reboot, it will briefly open a black command window on your desktop, this is normal.
* After the restart, it creates a log file that should open with the results of Avenger's actions. This log file will be located at C:\avenger.txt
* The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

Please attach the C:\avenger.txt in your reply.
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\qqrajxig

*******************

Script file located at: \??\C:\Program Files\uokymbqa.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Driver _wff unloaded successfully.
File C:\WINDOWS\system32\drivers\_wff.sys deleted successfully.
File C:\WINDOWS\system32\jjkmp.ini2 deleted successfully.
File C:\WINDOWS\system32\jjkmp.bak2 deleted successfully.
File C:\WINDOWS\system32\jjkmp.bak1 deleted successfully.

Completed script processing.

*******************

Finished!  Terminate.

:] Dankaaaaaa. Ohh and my anti-virus is turned on.... We are almost there!

Please post one more HijackThis log.

I will be working on a few more things that need attention, but they are easy.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:43:27 PM, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\analyze.exe\Analyze.exe.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

--
End of file - 2432 bytes


I have to go to work now, so I won't be able to reply as quickly as I have been but thank you! and yay!  No problem, there will be some closing steps when you return. Thanks for the patience!!!!!Go to Start > Run and copy and paste next command in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit Enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

=======

Stuff to delete:
The Avenger
C:\avenger.txt
VundoFix
C:\vundofix.txt

=======


Your Java is out of date
Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version of Java components and update

Updating Java:
* Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
* Check for any item with Java Runtime Environment (JRE or J2SE) in the name.
Java version is 1.4.2.3 <--Uninstall
Java version is 1.5.0.3 <--Uninstall
* Click the Remove or Change/Remove button.
* Repeat as many times as necessary to remove each of the Java versions.
* Reboot your computer once all Java components are removed.

* Download the latest version of Java Runtime Environment (JRE) 6
* Click the Free Java Download button.
* Click the Download Now button.
* When the Software Installation dialog box opens. Click on the Install Now button.
* Follow the prompts to complete installation.

=======

You can keep ATF-Cleaner for a good scrubbing when needed, but it is a powerful cleaner so be sure you know what you are deleting.

A good, safe daily drive and registry cleaner is CCleaner.

Download CCleaner
* Once CCleaner is open use the default options.
* Click Analyze and it will show a log of what will be removed.
* Next click Run Cleaner to remove everything.
* Then on the upper left of CCleaner select the Registry tab.
* Click Scan For Issues.
* Then click Fix selected issues.
* It will prompt you to make a backup. For the first run I would suggest doing so.
* Exit the program and you are done.

=======

I woulds also suggest having a look at this article by TONY Klein So how did I get infected in the first place?
There are some great tips for improved security for everyone.

Let us know if anything else pops up.

Safe surfing.....
1006.

Solve : Can someone please look at my HJT log??

Answer»

You're CORRECT. LET me EDIT my POST.

1007.

Solve : trojan can't be deleted, cleaned or quarantined??

Answer»

Let me see...Much better, but we still have one bad guy: TALEX TROJAN
- O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\System32\regscan.exe

Restart in Safe Mode (now, you know how...LOL).
Go Start>Run, type in:
regedit
Hit Enter.

Registry Editor will open.
Navigate to:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In right pane, you'll see:
RegScan %Windir%\Regscan.exe
or similar combination.
Right click on it, click Delete
Close Registry Editor.

Open Windows Explorer.
Navigate to:
C:\WINDOWS\System32\
Check if file:
regscan.exe
exist.
If yes, delete.
If not, close Windows Explorer.

Restart computer, post new HJT log.

Print the above out.Wait!!!I apologize, I made a mistake, so I had to modify latest instructions. It's all good now. Go ahead, and follow my instructions.alright, so i got into safe mode, went to registry editor, and when i went to HKEY_CURRENT_USER, the only thing in the right pane was (Default) and under type it said REG_SZ. I tried to delete it anyways, but when i tried, it said "Unable to delete all specified VALUES."
So I wasn't sure what to do next so i just got back to normal mode. Hah. What should i do now? Quote

I tried to delete it anyways
NEVER, EVER do anything, what you were not told to do, ESPECIALLY in Registry!!!

Now...
I said, navigate to:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
You do this, in exact same way, as in Windows Explorer.
In this case, you click on a "+" sign next to HKEY_CURRENT_USER.
Then, you'll see SOFTWARE folder. Click on a "+" sign next to it.
Now, you'll see Microsoft folder. Click on a "+" sign next to it.
...and so on, until you reach Run folder.
Make sure, it's highlighted (if it's not, just left click on it - ONCE).
Now look in right pane to see an entry, you're suppose to delete:
RegScan %Windir%\Regscan.exe

PLEASE, DON'T delete anything else. If entry is not there, write down what entries ARE there, and post back.hah wow i'm bad at this. anyways, i deleted the regscan entry, it wasn't in windows explorer, so i did the hjt scan and here it is:
Logfile of Trend MICRO HijackThis v2.0.2
Scan saved at 8:56:44 PM, on 11/10/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\rundll.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Lexie\Desktop\HiJackThis.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1126479238\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1126479238\ee\AOLServiceHost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\wuauclt.exeR3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Propel ACCELERATOR] "C:\Program Files\EarthLink TotalAccess\Accelerator\PropelAC.exe"
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1126479238\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O19 - User stylesheet: C:\Documents and Settings\Lexie\My Documents\blockneopetsads.css (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: rundll.exe - UNKNOWN owner - C:\WINDOWS\rundll.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

--
End of file - 9814 bytes
Quote
i'm bad at this. anyways
You'll be perfectly fine, if you follow instructions.

Quote
i deleted the regscan entry
Nice...you got the sucker!

Quote
it wasn't in windows explorer
Very good!!

Now, I'll take a look at your HJT log.Congratulations!!! Your HJT log is perfectly clean

We killed together quiet a few suckers.

Now, it's time for you to install Windows Service Pack 2, stay away from troubles, and report, that your computer is working fine.

Good luck Go to add/remove programs and uninstall Java jre1.5.0_10

Then visit www.java.com to download the latest version jre1.6.0_3

Outdated Java is an entry point for malware.

I woulds also suggest having a look at this article by Tony Klein So how did I get infected in the first place?

Thanks broni, thank you so much. haha i can't imagine it was easy on your part.
where do i install windows service pack 2?

evilfantasy, should i uninstall everything having to do with java, or just jre.5.0_10?
and thanks for your help. Updates can be downloaded at www.windowsupdate.microsoft.com

First though, since you don't have SP2 I would strongly advise to run an online virus scan to be 100% sure there are no virus on the computer. If there is this can cause big problems.

Use the ESET online scan http://www.eset.com/onlinescan/index.php

If anything is found post the log from the scan found in C:\Program Files\EsetOnlineScanner\log.txt

After getting the windows updates get the Java and delete everything but jre1.6.0_3 (Java (JRE) 6 update 3) Quote
haha i can't imagine it was easy on your part
As long, as you follow instructions, not your imagination (LOL), especially with registry, I'll be fine
1008.

Solve : differences?

Answer»

know the differenceI realize, you're new here, and you're welcome aboard, but FORGET about those polls, for now...hehehe

Thanks to:

http://www.webopedia.com/TERM/V/virus.htm
Quote

A program or PIECE of code that is loaded onto your computer without your knowledge and runs against your wishes. Viruses can also replicate themselves. All computer viruses are manmade. A simple virus that can make a copy of itself over and over again is relatively easy to produce. Even such a simple virus is dangerous because it will quickly use all available memory and bring the system to a halt. An even more dangerous type of virus is one capable of transmitting itself across networks and bypassing security systems.

http://www.webopedia.com/TERM/T/Trojan_horse.html
Quote
A destructive program that masquerades as a benign application. Unlike viruses, Trojan horses do not replicate themselves but they can be just as destructive. One of the most insidious TYPES of Trojan horse is a program that claims to rid your computer of viruses but instead introduces viruses onto your computer.
In layman terms, Trojan doesn't destroy ANYTHING. It's like a bad guy, who has a key to your house, and keep your house door open for other bad guys, who want to destroy your house, or steal something from it.Basically...viruses are vampires, and trojans are the unsuspecting blondes that invite them in.LOL....nicely said...
1009.

Solve : So many issues and I don't know where to start...?

Answer»

Okay I have a Compaq Presario that will be 4 years old in January. I'm running WIndows XP with 756 MB RAM and an 80 GB hard drive. Everything was fine until yesterday. When I login to Ebay I get the following message 

If you are seeing this page, your browser settings prevent you from automatically redirecting to a new URL.
I used to get redirected automatically. I can view my Yahoo email but I can't delete it. I can get on my banks website but I can't login to my bank account.

I downloaded Mozilla Firefox and it's working fine with ebay, my bank and yahoo. SO I assume it's an Internet Explorer issue..but when I try to GO to system restore on my pc there's nothing there. I mean it opens up one big blank window.

I hope to get a new PC after Christmas but in the meantime what can I do to get mine running right again?? I thought about just reformatting it and putting it back like it came but that's so much work.

Thanks for any help!!! and BTW, I've ran Ad Aware, AVG Anti Spyware, McAffee Virus and Spybot and nothing was really found. In IE, go Tools>Internet Options>Security tab, set slider to "Medium-High"Broni's suggestion is valid for the future but it won't FIX any malware that may be on your machine now.

As you've already run some good general "fixing" programs I recommend you post a HijackThis log here for more SPECIFIC advice.


OJ

1010.

Solve : yahoo messenger problem..any help????

Answer»

i can't see the MESSAGES from my friends.any idea?Did you try to click "Yes"? Quote from: Broni on October 11, 2007, 11:23:10 AM

Did you try to click "Yes"?

yes i did.but nothing happensDo you have the latest version of YIM? There were some security issues in EARLIER versions... Quote from: Broni on October 12, 2007, 10:38:03 AM
Do you have the latest version of YIM? There were some security issues in earlier versions...

I'm not sure if am using  this latest issue.but if you have can you upload it sir??tiaLatest version (8.1) is here:
http://messenger.yahoo.com/webmessengerpromo.phpHi,I think Im using this latest version.i've already tried to install older version,but this warning stuff keep on dispalying. ..I found something here:
http://awbholdings.com/techwatch/?p=188:
Quote
Based on testing done in Windows XP SP2 with the latest version of Yahoo! Messenger (8.1.0.421) using the said DLL component, programs or Web sites using the CLSID related to the said DLL can download files from the Internet. Users can be lead to malicious/non-malicious sites that will first PROMPT for an ActiveX warning. When users allow the said ActiveX component to EXECUTE, FT60.DLL downloads files specified by the program or Web site.

I'd advice you to download HijackThis from here: http://www.majorgeeks.com/download5554.html, and post its log at "Computer VIRUSES and Spyware".
1011.

Solve : Cannot run Trend's Online Virus Scan?

Answer»

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\K'Ehleyr\Desktop\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu ITEM: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1141259631536
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) - http://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/cpucheck_1_0_0_5.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} (MediaControl Class) - http://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/Entriq_3_4_0_15_Silent.cab
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - http://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/NBCUniversal_1_0_0_3.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe


I am going to run spybot again CROSSING my fingers!
THANK you
Don't worry, you should be OK.

Most likely, it's just your Windows setting.

If you go to Start > Control Panel > Security Center > Resources and click "Change the way Security Center alerts me" it will open the "Alert Settings". There are three Alerts available:

   1. [X] Firewall
      Alert me if my computer might be at risk because of my firewall settings

   2. [X] Automatic Updates
      Alert me if my computer might be at risk because of my Automatic Updates settings

   3. [X] VIRUS Protection
      Alert me if my computer might be at risk because of my virus protection software settings

When any of these alerts are unchecked, the Windows Security Center will *-NOT-* notify you if any of the above are disabled. However, Spybot Search & Destroy will detect these changes and report that the registry settings are different from the expected defaults in its database which are set to show that all three Security Center alerts are enabled.

So, for instance, if you don't use Windows firewall (using some other firewall), or you do manual Windows updates (like many people do), Spybot will display this warning:
Microsoft.WindowsSecurityCenter.AntiVirusOverride

Now, you tell me what is your case, and post new HJT log.Your HJT log is super clean. Congratulations! I'm so confused.   You say it is clean but, when I run HJT every single line is checkmarked.  Which I thought is a problem situation because you told me to check certain boxes and run fix.  The HJT when ran shows all lines checkmarked everyone. 

When I run Spybot it shows a problem, and when checked it fixes but when I restart my computer and run it again it shows still the problem.  This entry on the problems shown on Spybot.


Microsoft.WindowsSecurityCenter_disable d
   (SBI $2E20C9A9) Settings
   HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscvc\Start

Can someone tell me how I should set the settings for Spybot?

I appreicate your help. Quote

The HJT when ran shows all lines checkmarked everyone.
It shouldn't be, but it's an easy fix. Click on "Config..." button, and remove checkmark next to "Mark everything found for fixing after scan".

Quote
Microsoft.WindowsSecurityCenter_disable d
   (SBI $2E20C9A9) Settings
   HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscvc\Start
I explained this entry in my previous post.
1012.

Solve : Virus Yet again?

Answer»

Oh no. AFEW MINUTES ago the BSOD popped up again, randomly. I wasnt downloading anything... or doing anthyng. It just popped up..You could be having a hardware failure SOMEWHERE or some software conflict. The next time it happens Google the error NUMBER to SEE if you can find what it's related to.Alrighty...

1013.

Solve : stoned empire monkey.b?

Answer»

dell DIMENSION 4600
intel 2.8 ghz - 2.5 gb
win-xp home SP 2
avg virus - comodo fireware pro - spybot search & destroy - AD aware 2007


evening,

i would like to find out just what the "stoned empire monkey.b" wanted from the user's computer. i have learned (from internet forums) that it went to and moved the mbr record on the harddrive. does the virus try to get the passwords and such and then use email to send to off to another address. i have learned that it is a old virus but can not seem to find out just what is was suppose to do the the computer.

i was working/playing with an old computer with a small 325.46M (341090304 bytes) harddrive. i think the drive is less than a gm. in any case, i think i got the virus when i was trying to make a bootdisk off the drive to use once i had fdisk and formated the drive. i was going to reuse that diskette and so PLACED it into my dell machine to format and the avg picked up the virus, stoned empire monkey.b.....

i ran my virus, spybot and ad aware.........all came back clean. i still worry that the boot record was moved and that it is just not seen.



please, any help.

tazpaigeIt sounds likely that AVG picked up the virus on the floppy diskette not on your Dell hard drive.   morning dusty,

thanks for the reply.

yes, it was on the floppy or on the small harddrive i pulled from an older machine to us in the other computer.  it turns out that the drive is only 325.46M.  too small to use for win95 or win98 anyway.  the floppys that i USED while working on the computer, i got rid of......i worried about even trying to format them. my real worry was what the virus did to the computer and could it use the email system.  as i understand it now, is seems that it only ran a message (your computer is stoned) on your computer and does not use email.....

thanks,
tazpaigeFrom what i remember of that virus when it was around if you had any Kellogs Corn Flakes in the cupboard it turned them into reefer...Had a similar incident some years ago when I was given an elderly pc and about 100 floppies all of which had a resident virus.    What a job - formatted every one, end of virus problems.

Your stoned virus is just a bit of fun, thank goodness, but caused lots of heavy breathing way back when.

LOLthanks,  all of you for the answers.  and yes  it does seem that it was not  a bad virus.

i didn't format the floppies, just got rid of them.

thanks again.

tazpaige

1014.

Solve : Spyware & Viruses... Hijack log help please ;-)?

Answer» EEK, Lost my place. If you need to see I can create an attachment. it exceeds the 20000 characters.I don't think I need to see the rest.

Everything found was not a problem.

Disable the System Restore Utility to prevent re-infection from an old one

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Put a check mark next to Turn off System Restore on All Drives
4) Click the OK button.
5) You will be prompted to restart the computer. Click the Yes button.

Now re-enable System Restore

To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Remove the check mark next to Turn off System Restore on All Drives
4) Click the OK button.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates SITES on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to RUN on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you Evilfantasy. Computer is running great now. No problems at all today. I see the recommended tools that you included with your last post. I was going to ask you about the Malwarebytes, and or the Superspyware program to be used (Not at the same time) with Kaspersky 2009. I want to make it as simple as possible for the owner of this computer in the hopes that its kept up to date to avoid future infections.They can both be used along with Kaspersky.
1015.

Solve : Trouble, can someone read my HJT log??

Answer»

Quote

Sure you can take a closer look. I'm not sure what you MEAN by that.
I can tell you, which programs you need as startups, and which not.

Quote
So basically you just look for anything that looks suspicious or that you don't recognize, then check it out? I guess after a while of doing that you become familiar with a lot of the basic problems.
EXACTLY! It's mostly practice. Quote from: Broni on October 14, 2007, 12:30:55 PM
Quote
Sure you can take a closer look. I'm not sure what you mean by that.
I can tell you, which programs you need as startups, and which not.

Quote
So basically you just look for anything that looks suspicious or that you don't recognize, then check it out? I guess after a while of doing that you become familiar with a lot of the basic problems.
Exactly! It's mostly practice.
Oh ok. No THANKS, I already know. lol.

Thanks for all your help Broni. See ya AROUND...Sure THING
1016.

Solve : Kaspersky Anti Virus??

Answer»

Currently I have been at my mate’s house vigorously tearing through his computer and adding programs to deal with different situations. (Currently I have installed SpyBot search and destroy, Windows Washer and Zone Alarm firewall.) When it came to anti virus my mate refused me to touch it. He stuck with his UNCLE's decision of Kaspersky anti virus, which I have never heard of. This and the fact that his computer is riddled with problems that is most likely caused by Virus’ makes me suspicious. Is it reliable and trustworthy? Does it have anything on AVG. Quite frankly I don't think it's doing its job and should be replaced immediately with AVG free.

Best Regards
                   Jamez.
It's an excellent program. Some of me friends use it, and they are very HAPPY.
http://www.pcworld.com/article/124475-1/article.htmlMust be something else with my mates computer then. Is it better than AVG in your opinion though? From what I've heard on these forums its the best free one out there.

Jamez.Kaspersky is not free.
As for free AV programs, I use AVG myself, and I'm happy with it.
Never had a virus, and what I like about AVG, it's quiet (some others will pop-up OFTEN with some stupid warnings), it's small, it doesn't interfere with other programs, it's easy to remove, etc.If he has issues trust me it's not Kaspersky's FAULT...
Maybe you could talk him into letting you install AVG Anti-Spyware if you take the time to explain it does a completely different job as it searches for Trojans and keyloggers...two things most AV programs don't always CATCH or deal properly with...Thanks Patio. I'm on it ASAP.

Jamez.

1017.

Solve : yt8a.exe virus??

Answer»

Hello everyone! Sorry for not following the guide at first as suggested. I have done so now, and my computer "feels" normal again (at least to the untrained eyes of a novice like myself)! It is running at full speed, the computer fan has stopped, and the browser no longer quits automatically when I come to this thread! Well, here are more details:

1. I uninstalled Norton to install Avast. For some reason, the uninstall process deleted my spybot also.

2. The SuperAntiWare said I had no infection, so I don't have a log for that.

3. The MalwareByte said I had 200+ infections! Please see the log.

4. After I restarted, I ran MalwareByte again to see if I would still have any infection. It turns out I do. This time it SAYS I have 130 infections. Attached is log #2, I know you guys didn't ask for this but I thought it wouldn't hurt to include it here.

5. I got the latest Java Runtime and then deleted all old versions.

6. Hijack this wouldn't work for some reason. Then I saw you guys said to change the file name to sniper and then it worked again. Cool! Can someone explain why changing the file name worked? Anyway, attached is the new log.

Thank you guys so so much. I know I still have tons of infections but my PC SEEMS to be working perfectly again and that's all I can ask for.

Please let me know what to do next! I will listen I promise

[Saving space - attachment deleted by admin] Quote from: btfanusa on October 26, 2008, 11:28:07 AM

6. Hijack this wouldn't work for some reason. Then I saw you guys said to change the file name to sniper and then it worked again. Cool! Can someone explain why changing the file name worked? Anyway, attached is the new log.

This is done by some infections.  When they see that hijackthis.exe is running, they will either hide or CAUSE it to crash.  It's a very popular tool when it comes to malware removal, so they know to look out for it.  But when it's NAMED to something else such as sniper.exe, the infection doesn't know what it is, so it doesn't do anything.  Does that make sense?



In any case, your computer is looking quite a bit better, but there are still some things we need to take care of.  The first thing I'm going to have you do is download ComboFix and save it to your desktop.  Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says.  Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt.  Go ahead and post that here.  Note: Don't click on the window while it's running; this may cause stalls.
1018.

Solve : Can't double click on drive letter?

Answer»

Hello All of you.
There is a strange problem occur in my pc. Can any one HELP me?
In my computer, Whenever I doble click on C:,D:, it can't open. The windows that open is choose the program.
I know that it is a VIRUS. So scan with Avast antivirus.It found virus,but problem can't solved.
So, please help me.
Thanks in advance.What Windows version? Do you remember virus name?
Did you try System Restore?Windows xp 64-bit.
There are different  different name.So I can't remember that.
Give the procedure how to do system restore.1. Click Start, point to All PROGRAMS, point to Accessories, point to System Tools, and then click System Restore.

2. On the Welcome SCREEN, click Restore my computer to an earlier time, and then click Next.

3. On the Select a Restore Point page, select the date from the calendar that shows the point you'd like to restore to, as shown in picture below, and then click Next.



4. On the Confirm Restore Point Selection page, VERIFY that the correct restore point is chosen, and then close any open programs.

5. Click Next if you are ready to proceed or click Back to change the restore point.

6. The computer will shut down automatically and reboot. On reboot, you'll see the Restoration Complete page, and then click OK.

1019.

Solve : i got a virus?

Answer»

according to one of my other threads Broni said i had a virus. I RAN the scans and followed the steps. Here are my logs.

I have vista home premium 32 bit.
Sp1 i think
3gb of ddr2 ram
if you need more info then LET me know.


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/25/2008 at 08:41 PM

Application Version : 4.21.1004

Core Rules Database Version : 3555
Trace Rules Database Version: 1543

Scan type       : Complete Scan
Total Scan Time : 04:42:04

Memory items scanned      : 635
Memory threats detected   : 0
Registry items scanned    : 8284
Registry threats detected : 4
File items scanned        : 809692
File threats detected     : 19

Trojan.Downloader-ChinaHot
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A75E294E-C047-4D29-B07E-37B792881BEF}

Adware.Tracking Cookie
   C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\admin\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\admin\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\admin\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\admin\Cookies\[email protected][2].txt
   C:\Documents and Settings\admin\Cookies\[email protected][1].txt
   C:\Documents and Settings\admin\Cookies\[email protected][1].txt
   C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\admin\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\admin\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\admin\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\admin\Cookies\[email protected][2].txt
   C:\Users\admin\Cookies\[email protected][1].txt
   C:\Users\admin\Cookies\[email protected][2].txt

Adware.Vundo Variant/Rel
   HKLM\Software\Microsoft\Windows\CurrentVersion\Run#MSServer [ rundll32.exe C:\Windows\system32\khfGvvtS.dll,#1 ]

Trojan.DNS-Changer (Hi-Jacked DNS)
   HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS\INTERFACES\{E2777073-7B3F-427E-9E53-99430B3E5CBE}#NAMESERVER
   HKLM\SYSTEM\CONTROLSET003\SERVICES\TCPIP\PARAMETERS\INTERFACES\{E2777073-7B3F-427E-9E53-99430B3E5CBE}#NAMESERVER


Malwarebytes scan
Malwarebytes' Anti-Malware 1.30
Database version: 1321
Windows 6.0.6001 Service Pack 1

10/26/2008 9:19:48 AM
mbam-log-2008-10-26 (09-19-48).txt

Scan type: Quick Scan
Objects scanned: 53281
Time elapsed: 3 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 13
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Program Files\blueshirtstudio\tbblue.dll (Adware.HumourCanineToolbar) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{bfcdcebe-e1fb-40f9-b4e2-7bb1138ef76c} (Adware.HumourCanineToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bfcdcebe-e1fb-40f9-b4e2-7bb1138ef76c} (Adware.HumourCanineToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bfcdcebe-e1fb-40f9-b4e2-7bb1138ef76c} (Adware.HumourCanineToolbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\alewinsecure.winsecure (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\alewinsecure.winsecure.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7be6b643-6201-4cf7-b8b1-d79ffae57cba} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a1789eb6-b263-4bd6-8830-d3daaf78949a} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1} (Trojan.HumourCanine) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{58696980-c6b3-4ad2-ab53-718f1c3c57ca} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{a93a1ba9-9ee8-469f-a9fe-fd1c26700bda} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a75e294e-c047-4d29-b07e-37b792881bef} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Bifrost (Backdoor.Bifrose) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\AleWinSecure.EXE (Adware.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{bfcdcebe-e1fb-40f9-b4e2-7bb1138ef76c} (Adware.HumourCanineToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{bfcdcebe-e1fb-40f9-b4e2-7bb1138ef76c} (Adware.HumourCanineToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{bfcdcebe-e1fb-40f9-b4e2-7bb1138ef76c} (Adware.HumourCanineToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{bfcdcebe-e1fb-40f9-b4e2-7bb1138ef76c} (Adware.HumourCanineToolbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\blueshirtstudio\tbblue.dll (Adware.HumourCanineToolbar) -> Delete on reboot.
C:\Program Files\Conduit\Community Alerts\Alert.dll (Trojan.HumourCanine) -> Quarantined and deleted successfully.



Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:34:46 AM, on 10/26/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\schtasks.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\jusched.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cornerstoneprep.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O2 - BHO: Adblock Pro - {F385C231-605B-4d8f-ACA9-DBFF765BBE17} - C:\Program Files\Adblock Pro\AdblockPro.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SeePassword] C:\Program Files\SeePassword\SeePassword.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe
O8 - Extra context menu item: &Block This Image (ABP) - C:\Program Files\Adblock Pro\blockimg.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Launch PicLens - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\PicLens.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Adblock Pro Preferences - {E7FD3540-AB30-40f1-91E7-101F733C1FD5} - C:\Program Files\Adblock Pro\AdblockPro.dll
O9 - Extra 'Tools' menuitem: Adblock Pro Preferences - {E7FD3540-AB30-40f1-91E7-101F733C1FD5} - C:\Program Files\Adblock Pro\AdblockPro.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://gearsoffear.elementfx.com
O15 - Trusted Zone: http://*.x10hosting.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4E77DBA6-3506-46EC-93C0-AB1E0DBD7E4A} (ZtServiceManager Class) - http://mvod.web.aol.com/mce/new/ServiceMgr.CAB
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Service.exe
O23 - Service: Windows Tribute Service - Unknown owner - C:\Windows\system32\kdven.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11388 bytes
Disable Windows Defender

We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.

  • Open Windows Defender
  • Click on Tools, General Settings
  • Scroll down and uncheck Turn on real-time protection (recommended)
  • After you uncheck this, click on the Save button and close Windows Defender.
After all of the fixes are complete it is very important that you enable Real-time Protection again.

----------

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis, run CCleaner and restart the computer.

----------

Run this online scan.

This scanner requires Internet Explorer

Use the ESET Nod32 Online Scanner

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. ADD the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.

How is everything now?everything is back to normall thanks. I will be posting more logs soon because im helping out a friend and i scanned their computerIf you don't continue posting the requested logs we certainly won't be very willing to help with other issues. We volunteer our time but it is still work.ok and now that i have time. finally heres my last log file

[Saving space - attachment deleted by admin]Disable the System Restore Utility to prevent re-infection from an old one

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Put a check mark next to Turn off System Restore on All Drives
4) Click the OK button.
5) You will be prompted to restart the computer. Click the Yes button.

Now re-enable System Restore

To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Remove the check mark next to Turn off System Restore on All Drives
4) Click the OK button.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - SECURE your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1020.

Solve : Blocking me from my own computer...?

Answer»

So I'm guessing I have a virus, trojan, whatever. Anyways, when i noticed some programs were being installed with out me installing them, I thought I'd do a system restore, but when I try to go to control panel, it says you've been blocked from this area. It's hard to understand since I'm the only person on this computer, meaning I'm the administrator with all control. So then I decided to do a virus scan, and I left it be for a while. When I came back, the scan was STOPPED at scanning 205 files so I though it was just slow; 10 minutes later, it's still there. So I decided I'd go to the website of that company, and it says the page won't load. All of the other websites I tried were, but not that. So I tried going to another virus scan website, Norton, and it wasn't loading either. So obviously something is up. The system is blocking me from myself, and I can't go on some SITES when they're not blocked and are working on other COMPUTERS. Is there a way I can overrun this problem by getting to system restore? Or atleast solving this at all? Thanks in advance...  by the way, I have windows XP and started just out of random when my home page was changed, but I can't remember the last time I was on the web.Did you access this site from the very same computer, or you have another one?
It smells like REINSTALLING Windows, but...first, answer my first question, please.Try rebooting in safe MODE. From there, try restoring. If that will not work, try disabling all startup items in msconfig(I assume you knew how to execute msconfig).Can you answer Broni question, I think I know where he is going...Thats what I would ask also?

1021.

Solve : About System Restore and Viruses?

Answer»

Does system restore help remove viruses ? Thanks for your time! I am doing a project about VIRUS and stuff. Any does ANYONE KNOW the future of virus ? Quote

Does system restore help remove viruses ?
No.Aww thanks, :S Quote from: tommy gusack on November 15, 2007, 09:10:00 PM
Any does anyone know the future of virus ?
New ones will be WRITTEN. stop mocking me  The new ones will be worse than the old ones. Quote
Does system restore help remove viruses ?
What's more, if you had an infection, and it was cleaned up, you need to turn System Restore off, to delete all old Restore Points (which surely contain infected files), then turn System Restore BACK on.
1022.

Solve : I know. I'm an idiot. Help me anyway??

Answer»

Well, here's the deal. I downloaded a PDF of the Anarchist's cookbook 2000. I have no violent intentions, i just wanted to know what's being MADE available to our garden variety psychos.
ANYway, i opened it, and it released a Virus into my computer so that now if i try and open a .JPG the computer shuts off. If i try and make Thumbnails of the Jpgs in a folder, it shuts off. If i RUN my Antivirus (Avast) on a folder containing JPGs, it shuts off.
I ran a PC checker thing, and it did NOTHING. I'm screwed right now because i run my own business designing Greeting Cards, and.. If i can't access .JPGS, i'm ruined.
HELP.Did you try to restart in Safe MODE, and run your AV program from there?Also you MAY want to list what protection programs you currently have...

1023.

Solve : Big Problem!!!!!?

Answer»

Quote from: Broni on October 15, 2007, 12:19:27 PM

Quote
You have no idea how tired im now.
You think, I'm NOT tired?.....LOL....just kidding.
No you are not kidding , im sure you must be tired.

Quote from: Broni on October 15, 2007, 12:19:27 PM
Quote
though it says that  Trojan DOWNLOADER is trying to execute somthing , i deny it.
OPEN a-squared, look under Quarantine, and see, if there are any entries there. If so, get RID of them.
I did that , no files there.

Quote from: Broni on October 15, 2007, 12:19:27 PM
Quote
Trojan remover shows my computer is CLEAN now.
I hope, it'll stay that way.
Me too., since i havent recieved any trojans since i downloaded a-square , i think my comp is ok for now.

Quote from: Broni on October 15, 2007, 12:19:27 PM
Good luck

Thanks a lot for your help , first TIME ever my Virus problem has been almost solved, thanks a lot really , Im amazed you never gave up on my biiiiiig problem  , thanks soooooooooooooooooooooo much.Hey, you are welcome My pleasure
1024.

Solve : Slow computer drivin me maaaadddd >:(?

Answer»

This last month my laptop started to get slower. It takes longer to start up. Also even when im not using it i can hear the hard disk working. I just ran HIJACK this and saved a log. Here it is :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:01:16, on 16/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\WINDOWS\vVX6000.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\MATLAB7\webserver\bin\win32\matlabserver.exe
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\F-Secure Internet Security\FSAUA\program\fsus.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.howstuffworks.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\System32\ZCfgSvc.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191860420625
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure MANAGEMENT Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB7\webserver\bin\win32\matlabserver.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 7752 bytes


Can you please suggest something ?? 

Thanks beforehand.

Simon
Open HijackThis and select Do a system scan only
Place a check mark next to
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Click Fix checked.

The log shows no malware. Have you tried doing system maintenance? CCleaner, defrag, CHKDSK. Windows Updates.

Quote

Also even when im not using it i can hear the hard disk working.
Shut it down. Laptops get hot enough as it is. Heat can cause problems.You have a lot of startups, though. It MAY be another reason for your laptop slowing down.
Let me see, which ones are necessary...*** With HijackThis, you should fix the FOLLOWING:

- O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
(This Spyware is an event monitor. Realtek is using this program to obtain information about their customers.)



*** In msconfig, you can safely "uncheck":

- O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (unless, you really use it on daily basis)

- O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
(Touchpad configuration tray icon for Toshiba laptops. Available via Start -> Settings -> Control Panel)

- O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe (unless, you use it often)
(Toshiba Virtual Sound on a notebook. Can also be launched from Start -> Programs -> Toshiba -> Utilities)


- O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
( CTFMon is involved with the language/alternative input services in Office XP. If you use it, leave it alone)

- O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
(if you use MSN Messenger a whole day in, and out, leave it)


What are your laptop specs, anyway?First of all thanks a lot for your interest

Evilfantasy, i did a defragment and a disk cleanup. I dnt know exactly what the other 2 are... Can you explain a BIT please.

Broni my laptop has a 2.2GHz Dual Core CPU, 1GB of ram and i am running windows XP PRo. I Dont think it should be this slow...

Bdw, is F-Secure a reliable anti virus ?we here always use avg anti virus for virus protection and s&d as a spy ware protection, but i much more prefer using avira anti virus.

http://free.grisoft.com/doc/5390/us/frt/0
http://www.safer-networking.org/
http://www.avira.com/en/download/index.html

i agree with broni, reducing startup files making the pc much more faster, but remember to keep you antivirus and anti spy ware turn on.An anti spyware scan in every week (atleast) are good, using stinger or super anti spyware in safe mode.

http://vil.nai.com/vil/stinger/
http://www.superantispyware.com/
 

Yes F-Secure is an excellent antivirus.

Go to Start > Run type CHKDSK and cklick OK

That will scan your disk for any errors and correct any that may be found.

CCleaner http://www.ccleaner.com/download is a good, safe drive and registry cleaner.
1025.

Solve : Can I give my CC# to this site to search for my father??

Answer» http://www.people118.com/

Or is there a more secure site anyone can recomend for this PURPOSE?

Thanks,
MikeYou're trying to look for someone?

What do you mean by Secure?I ran a search for myself at no charge.  Are they asking you to pay for a background check? Quote from: Carbon Dudeoxide on October 27, 2008, 02:09:35 AM
You're trying to look for someone?

What do you mean by Secure?




 Yes, my father who none of the family has heard from in ~20 YEARS. This site shows that it has information about him but it charges $49.95 for complete information. But when I get to the page to enter my credit card # ect, I don't see the icon for a secure CONNECTION that I usually see when buying online VIA credit card. Quote from: Aegis on October 27, 2008, 02:14:56 AM
I ran a search for myself at no charge.  Are they asking you to pay for a background check?
What site did you use.

Thanks for the help, both of you! 

EDIT = correct quote mistakeBTW, I don't have my fathers SS number. All my papers from those days got burned in a house fire. I did run a check and got several addresses, but no dates, phone numbers, other contact info. Quote
But when I get to the page to enter my credit card # ect, I don't see the icon for a secure connection that I usually see when buying online via credit card.

Might be best to hold off for just a bit.  There are other sites which offer the same services.I din't give them my secure information. Thanks!

Anyone know a secure way for me to do this search?I've never USED this site beyond the free services, but this looks a bit better to me.

http://www.intelius.com/people-search.htmlI saw that one and it claims to have more information, for more $, but I don't know if spending more $ with them will get me any more info than I already have. I guess I'll find out when I get another paycheck. Oh well. It's been 20 years, I guess I can wait another 2 weeks lol.
Thanks again!
MikeIn the meantime, try as many free sites as you can:  white pages, on line directories, etc. -- you might just stumble into some information.
1026.

Solve : mljjh.dll?

Answer»

hello

     I found this virus on my computer I am USING avg free but it wasn't picking it up and a friend refered me to try Antivir and once i installed it and ran a scan i kept picking up this virus and its antivir is driving me crazy with it


Quote

mljjh.dll

where:: C:\WINDOWS\system32\mljjh.dll

What type::  TR/Dldr.ConHook.Gen


do i need that file?? and if not how do i delete it or at LEAST get the virus out..

Thank you
SmackieDownload, and run free "a-squared" from here:
http://www.emsisoft.com/en/software/free/
It's a very good program, and I actually keep it as a startup, so it MONITORS my computer in real time.
Be also prepared to post your HijackThis log here.I know this virus because it's  a stubborn virus...Also I will copy another log file where they used Spybot and A-Sqaured to remove the virus..

http://forums.spybot.info/showthread.php?s=b07cdd2fd9541fd4aa2cd5e8db565225&t=7547Hi,
To the best of my knowledge you have what's known as the Vundo virus and it's recommended you use the Vundo FIX to remove it and if that fails then DOWNLOAD and run VirtumundoBegone...
1027.

Solve : Any LOP Traces to remove??

Answer»

Hey I'v been experiencing some weird things happening when i play some of my games online. I've experienced it before and have gotten rid of it with the help of you guys. Is there anything to remove from my log?
Logfile of HijackThis v1.99.1
Scan saved at 6:31:16 PM, on 10/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Steam\steam.exe
D:\Program Files\mIRC\mirc.exe
C:\Program Files\internet explorer\iexplore.exe
D:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,START Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\rzihjmcz.slt\prefs.js)
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Program Files\IE7Pro\IE7Pro.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160164617859
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bw+0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dllO18 - Protocol: bw60 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLLO18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {81338E24-FA0C-453F-A679-AF0F20ACD10C} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - UNKNOWN owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - D:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

I'll take a look...You are clean.
One "cosmetic" fix:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)thanks  Sure thing What kind of problems are you having when playing games?  And what makes you suspect a Lop infection?

Also, you don't appear to have a firewall.  You're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo.  They're all good free firewalls.  Just be sure you only have one installed at a time!  Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.

1028.

Solve : Mental Meltdown... Please Help...?

Answer»

When I tried to run CHKDSK /f it came up with a message which read...

"The type of the file system is NTFS.
Cannot lock current drive.

Chkdsk cannot run because the volume is in USE by another process. Would you like to SCHEDULE this volume to be checked the next time the system restarts? (Y/N)"

Should I type Y and reboot? Or will it still not WORK?

S.C.W.If you check YES it will run before windows loads so nothing can block it from running.

1029.

Solve : Computer Wont Start in Normal mode, only Safe Mode. Spyware infection. Help plz!?

Answer»

everythings running just fine, HOWEVER i am still getting re-directed. i check on the other computers on my network, they also get re-directed (when i type in www.google.com). either this problem is isp related or somthings on my network?

but my computer seems to have recovered nicely, thanks alot for the help!Download FixWareout by LonnyRJonesfrom from one of the two below links and save it to your Desktop.

  • Run Fixwareout.
  • Click Next
  • then Install
  • Make sure Run fixit is CHECKED
  • Click Finish.
  • The fix will begin; follow the prompts.
  • You will be asked to reboot your computer; please do so.
  • Your system may take longer than usual to load; this is normal.
When you run Fixwareout, just follow the prompts, you will need to restart when prompted.

After rebooting (restart) back into normal boot mode. Make sure you have all web browsers closed.
  • Go into Control Panel > Network Connections.
  • Right click on your connection
  • and click Properties.
  • On the Properties page, highlight Internet Protocol(TCP/IP)
  • Click Properties. This will bring up another page.
  • Select Obtain DNS Server Automatically.
  • Click the OK button. The page will close.
  • Press OK on the page in front of you.
  • Restart the computer.
  • Reconnect to the Internet using Internet Explorer.
  • Add the log from Fixwareout in your next reply.
  • It will be located at c:\fixwareout\report.txt
Go to Start > Run and type in cmd
Click OK.
This will open a command prompt.
Type or copy and paste the following line in the command window:

ipconfig /flushdns

Hit Enter.
Exit the command window.

Restart your computer.

Please post the contents of the logfile C:\fixwareout\report.txt, along with a new HijackThis log.404-not found error on both those links...Very strange. They worked earlier today...

Do the second part of the instructions beginning with Go into Control Panel > Network Connections.i already had it set to "obtain DNS automatically"
i did the ipconfig /flushdns. Restarted
google.com still redirects to google.co.jp

attached is the hijackthis log

florian

[Saving space - ATTACHMENT deleted by admin]Download HostsXpert
  • Unzip HostXpert to your Desktop
  • Open up the HostXpert program.
  • Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.
  • Click Create Back Up
  • Then click on Restore Microsoft's Host Files
  • Close the HostXpert program
.
Note: if you use SpywareBlaster, Spybot and/or IE-SPYAD, it will be necessary to re-install the protection they afford. For SpywareBlaster, run the program and select Enable all protection. For Spybot run the program and select Immunize. For IE-SPYAD, run the batch file and reinstall the protection.

----------

If that does not work.

Delete all the google entries in your hosts file.

For win xp, the file is under c:\windows\system32\drivers\etc

Open the hosts file with notepad and remove all the google entries.

Then in Notepad go to File > SaveThe program worked (it ran to completion) however i dont think it did anything cause its still being redirected.You will need to edit the Hosts file manually.i went to the host file and found no google entries....
[EDIT]

theres only one ip listed and its my local host.When you get redirected is there an option that says Google in English? Click that if so and it should reset itself. Or go into your Google toolbar options (if you use the toolbar) and make sure it is set to English.

It could also be related to which country setting you have:

Open:
Control Panel/Regional and Language Options

or Run:
Start / Run intl.cpl

Double check the settings.its all writen in japanes, but i just clicked on all the links and one of them turned it to english, it still says "go to google japan" which it never did befor but my computers running fine so im guessing its not anything virus related?


i also checked regional settings there set to Canada.


[EDIT]

I just cleared my cookies and it resets it to JAPANESE google.

[/EDIT]I am really not sure what's going on. It's likely not virus related. Try posting in the Windows forum. Someone there might have seen this problem before and know how to fix it.ok ill try that,
thank you very much for all the help on getting rid of my computer problems.
man do i love this forum!
Florian
1030.

Solve : Video stalls my browser permanently Hijack this log?

Answer»

Thank you very much for all of your help.  That was actually kind of fun.  I have NOTICED that you are shepherding quite a few lost sheep here.  Is it justthat you enjoy helping or do you make a career of this?Nah....just a hobby...fell in LOVE with computers long TIME ago So do I still have an unknown virus that I NEED to figure out?  Because youtube still crashes my browser and I can not turn on Automatic Updates.No, your trojan is gone, and this had to be done to start with.

As for your video problem....we can TRY again tomorrow, or you can start a new, fresh topic, stating there, that your computer has been cured from any malwares, so everyone knows, that this is not a culprit.

I'll try to sleep on your problem, and I'll try to come up with something new by tomorrow.. Thank you You are welcome

1031.

Solve : and some more.... sorry?

Answer»

O4 - HKLM\..\Run: [LXCJCATS] RUNDLL32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll,[email protected]
O4 - HKLM\..\Run: [lxcjmon.exe] "C:\Program Files\Lexmark 8300 Series\lxcjmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 8300 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\RunOnce: [NoIE4StubProcessing] C:\WINDOWS\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPPAVI~1\Pavilion\XPHWWBP4\plugin\bin\PCHButton.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - ?p=ZNxdm824YYAU
O8 - Extra context menu item: &Windows LIVE Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WEATHERBUG - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1162252406000
O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames/zpa_dmno.cab55579.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab53083.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60096.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (ZPA_Backgammon Object) - http://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab55579.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 13585 bytes
Go back to your FIRST post, HIT Reply, and post what you posted right here, back there.
Include HJT header, where it says what HJT version, what Windows version, and what browser version.

1032.

Solve : my antiquated Windows ME needs virus protection?

Answer» HI, my first post here.  We still have an old computer down in the basement which runs like a charm but I noticed last night, there is no virus protection.  I've searched online and LOOKED at various products and for system requirements, they are not listing Windows ME.  (I did read the memo that as of 7/11/06, microsoft no longer supports ME.)

Does the description of new virus software have to say it will support ME or will it automatically support it?.  Do you have any suggestions?

We have a 1 year old computer upstairs, so I am with this century, somewhat.  We use Symantec and like it.

Should I take a hammer to the ME's hard DRIVE and call it a day?  Can you believe I used it faithfully for 6 years and it still runs?Welcome on board

Quote
Can you believe I used it faithfully for 6 years and it still runs?
If you take care of it, it'll run for 6 more years. I got 8 years old with Win 2K on it, and after heavy use, it still runs like a champ

Quote
We use Symantec and like it.
I assume, you use Norton on your new computer, because you don't want to run TWO antivirus programs on the same computer???

Free AVG antivirus is compatible with all Windows since Win98, so it'll work with your ME:
http://free.grisoft.com/ Quote from: Broni on October 15, 2007, 11:38:12 AM
Welcome on board

Quote
Can you believe I used it faithfully for 6 years and it still runs?
If you take care of it, it'll run for 6 more years. I got 8 years old with Win 2K on it, and after heavy use, it still runs like a champ

Quote
We use Symantec and like it.
I assume, you use Norton on your new computer, because you don't want to run TWO antivirus programs on the same computer???

Free AVG antivirus is compatible with all Windows since Win98, so it'll work with your ME:
http://free.grisoft.com/

Hi and thanks for your fast reply.  Symantec is on my new computer upstairs.  The windows ME downstairs has no protection.  My question is, will virus protection software run on it (ME) if the system requirements do not specify that it supports windows ME? If yes, I might BUY another copy of Symantec (norton) for downstairs.

* Some older operating systems such as Microsoft Windows ME, Microsoft Windows NT and Microsoft Windows 98 will only be supported until August 2008 as a minimum.green_thumb:

You asked "...will virus protection software run on it (ME) if the system requirements do not specify that it supports windows ME?".  The answer is no.  Find an anti-virus program that stills lists Win ME as one of the supported operating systems. 

It's at LEAST a six year old system (using 2001 technology?), so its probably not the bigest badest fastest system around.  On top of that, WinMe and the other Win9x operating systems are limited by "system resources (user and GDI)" not memory.  The system designers only allowed a fixed amount of buffer space to support windows displays and dialog boxes.  If these dip too low, as they will if you're running too many programs concurrently, your system will hang.  The WinNT line (WinNT, Win2000, WinXP) and Vista do not have this limitation.  You want an anti-virus program that is light on system resources and designed to be compatible with Win9x/WinME.

If the system is for your personal home non-commercial use the following "free" versions will work well on your system:

    o  AVG Free Edition 7.5 Build 488a1157
    o  Avast! Home Edition 4.7.1043
    o  ClamWin Free Antivirus 0.91.2 (file scanner only, but free for all uses)

The first one "AVG Anti-Virus Free Edition" was also recommended by Broni and is a popular choice for older Windows operating systems.

You can find links to all three and many others in the Anti-Virus section of the "MajorGeeks" download web site:

    http://www.majorgeeks.com/downloads29.html

You didn't say what kind of system you have; how you wish to use it (personal or commercial); or whether it will be connected to the internet either directly or indirectly.  If you're going to access the internet from that system you should add some protection against adware, malware, spyware, trojans, and any other bad boys you can think of.  This protection should also include a firewall.  I prefer separate programs for anti-virus, anti-malware, and firewall protection.  I subscribe to the theory that no one software company is going to be the best in all three categories; so I prefer separate programs for each category rather than an integrated security suite.  But you only asked about anti-virus...

1033.

Solve : Autoplay Autoplay HiJack This?

Answer»

Ok...Done all that except when I tried to uninstall  Internet Expedition a message box appeared.

The box was titled RegSvr32 and had a yellow warning TRIANGLE in it with the following text

LoadLibrary("C:\DocumentsandSettings\Cliffnook\LocalSettings\ApplicationData\microsoft\internetexplorer\V0.15dat") failed - The specified module could not be found


With regards to the Autoplay fix. I did exactly what it said in the instructions. The CD, DVD, and USB Flash Drives do not work with Autoplay now and I need to start them through my computer or windows explorer. This is no big deal but it doesnt seem to have solved the problem of Autoplay appearing.

Just to let you know that while the Combofix Autoscan was running there were no instances of Autoplay appearing instead of the dozens that appeared during my first Autoscan. So it looks as though we may be getting there.


[saving disk space - old attachment deleted by admin]Download Your Uninstaller! This is not a free product but has full functions during the trial period.
You may need to boot to SAFE mode and try to uninstall Internet Expedition that WAY. Guide for booting to safe mode

It seems like there has to be a drive trying to autoplay.
Download TweakUI (FREEWARE) Run TweakUI and expand My Computer, and then AutoPlay. Click on Drives and uncheck the drive letter that you no longer want to AutoPlay. Click on Apply. This may not do any good but it will (maybe) let us know what drive is trying to autoplay.

Download Panda Antirootkit
Unzip it and run the PAVARK.exe file.
Tick the box that says In depth scan and follow the on screen instructions.
Let me know if it turns up anything.

After that please post a fresh HijackThis log.Already have TweakUI and disabled all drives for Autoplay.

Have used Your Uninstaller before and free 21 day trial up. Anything else I can use?

Have run the Panda Antirootkit and it shows nothing found.

Cheers Frank

[saving disk space - old attachment deleted by admin] Revo Uninstaller is free and works much the same way. If this doesn't work we will use a more direct approach to get rid of it.

Also with Revo look for
Pacific Poker
Wanadoo Search Toolbar

They keep coming back in the Hijackthis log.Revo gave the same error message when trying to uninstall Internet Expedition

Pacific Poker and Wanadoo Search Toll bar are not listed as being there.Do you have your XP CD to try a repair install.I have the original XP CD but there is no option for a repair install.

I click the option for install and a message tells me that an install cannot be done because the version on my PC is newer than the one on the CDIt must be an SP1 CD and you have upgraded to SP2.

When I google Internet Expedition and only get one search result for it.

I'm going to do some more googling and see what I can find.

It sounds like you and I are finding of the same solutions, only they aren't working  You're right, I have upgraded to SP2

Thanks for all your efforts. Very much appreciated

Cheers FrankHow to Manually Remove Programs from the Add or Remove Programs Tool (registry)

http://support.microsoft.com/kb/314481Older, free version of "RegCleaner" will do it for you:
http://www.321download.com/LastFreeware/files/RegCleaner.zipWe aren't trying to clean the registry."RegCleaner" has an option to remove dead Add/Remove entries.Again, not what we are trying to do.Ok evilfantasy....that seems to have got rid of internet expedition

1034.

Solve : removal of virusscanner. it sounds weird, but help wanted anyway?

Answer»
    It looks good now.

    Let me know if you have any questions.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then HIT Enter.
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

Disable the System Restore Utility to prevent re-infection from an old one

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) PUT a check mark next to Turn off System Restore on All Drives
4) Click the OK button.
5) You will be prompted to restart the computer. Click the Yes button.

Now re-enable System Restore

To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Remove the check mark next to Turn off System Restore on All Drives
4) Click the OK button.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on BUSINESS practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. ALSO stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1035.

Solve : Task Manger won't run, Home Page Hi-jacked by Microsoft?!!!?

Answer»

No it still won' allow me Try changing it to none...re-boot a few times then try to change it towhich one you want.
Are you running a firewall ? ?Can you get to the page you want as your start page with no trouble or is the page being blocked ? ?It doesn't let me change it at all, when i go into Tools-Internet Options 'use currnet, use default and use blank' are all disabled, its says at the BOTTEM 'Some setting are managed by system addministrator'. Yeah i can get to any page i want when i load up IE no problem, its just a bit annoying that i can't set the home page which is usualy google.I think, your problem is, that I believe, you are not logged in as Administrator. I'm not sure yet how to FIX it, but I think this is the issue we have to work on.Boot into safemode and do it from there and re-boot....

p.s. Follow the same instructions...
p.s.s. Whose MACHINE is this ? ?I own the PC myself. I pressed F8 to go into the options for Safe Mode but when i want to select it the keyboard freezes, it won't let me go up or down to even go into safe mode  . My keyboard only has a USB connection. I tried my old "Dodgy"  keyboard where if i use it the mouse freezes! . So i used the old keyboard, when into F8, went into safe mode, PC starts up but then the mouse has frozen so i can't click my login name Use the Tab button to navigate thru the login screen...
I'd get a new PS2 keyboard as well...thet're not that EXPENSIVE and as you SEE pretty handy to have.

1036.

Solve : Win32: Lmir - PG {RTK}?

Answer»

Sorted!!!
HTTP://phrozendemon.wordpress.com/2007/10/11/acer-aspire-3000-problems/
Though it gets me how it works in Safe MODE with the BATTERY, yet not in normal mode.
When the laptop has BOOTED only then can I insert the battery.
Oh well at least all I have to do is get a new battery.
Thanks for all that HELPED me anyway!

ChrisCool Thanks for the update, Chris.  I hope everything works out!

1037.

Solve : To many programs running at start-up??

Answer»

Which of the programs in my HJT log can disable from starting automatically?
I WANT to keep Trend Micro, sound, Malwarebytes, Secunia, and my bluetooth programs running.

Thanks,
Mike

[SAVING space - attachment deleted by admin]If you are using windowxp then run the msconfig and see at startup tab Where you can enable or disable startup programs.StartupLite

  • Download StartupLite by MalwareBytes to your Desktop.
  • Doubleclick StartupLite.exe to launch the program.
  • Ensure the Disable box is checked.
  • CLICK Continue.
  • A pop up message will TELL you the unecessary startup items in your list have been disabled and ask you to restart your computer.
  • Re-start your computer.
.
Anything not listed in StartUp Lite needs to be determined by you if it needs to run at startup or not. MSCONFIG is primarily meant to be used for troubleshooting only. A good startup manager is http://www.majorgeeks.com/StartUp_d4436.html Run it, right click anything you don't want running at startup and choose Remove.jugalboro , thanks, but I am familiar with msconfig, I just have a problem figuring out  - 1, which programs the abbreviations used on some of the entries are referring to, and -2, if those particular programs are actually needed or not for my SYSTEM to run as usual without me having to figure out how to open what I need if it's not running.
 Thanks for your help!!!


Quote from: evilfantasy on October 26, 2008, 11:36:29 PM
StartupLite
  • Download StartupLite by MalwareBytes to your Desktop.
  • Doubleclick StartupLite.exe to launch the program.
  • Ensure the Disable box is checked.
  • Click Continue.
  • A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
  • Re-start your computer.
.
Anything not listed in StartUp Lite needs to be determined by you if it needs to run at startup or not. MSCONFIG is primarily meant to be used for troubleshooting only. A good startup manager is http://www.majorgeeks.com/StartUp_d4436.html Run it, right click anything you don't want running at startup and choose Remove.
Thanks once again evilfantasy!!!
That works great. It disabled several programs on start-up that I didn't even realize were running, and non of them is needed for what I normally used. You have once again proven to be an excellent help for me and I very much appreciate it.
Hat's of to you and CHF.  :)

BTW: I still use Malwarebytes full version and am very satisfied. Thanks for recommending it to me.  ;)
As far as the start-up manager program:
 http://www.majorgeeks.com/StartUp_d4436.html
it's just about as confusing to me as msconfig, but it's good to have for dissabling what I do know I don't want running. Thanks for the link!
 
1038.

Solve : Firewall Leak Test?

Answer»

Vista here, Vista firewall enabled + router

Out of curiosity, I just took Steve Gibson "Firewall Leak Test" (http://www.firewallleaktester.com/leaktest1.htm), and it made me unhappy:



So, I went back to Gibson's site, and I found this:

Quote

The Windows XP built-in firewall:

Just so you know, WinXP's built-in firewall does not attempt to manage or restrict outbound connections at all. It appears to be a useful firewall for hiding the machine from the Internet (it has "STEALTH mode" unsolicited packet handling), but you will still need to use a good third-party personal firewall if you wish to manage and control outbound connections from your system.

As I said, I'm on Vista, but it looks like I have same problem.
In this case, I'll seriously consider shutting down Vista's firewall, and installing Comodo.

What do you guys think?

There are more test at that site, so I'm going back there to do more tests.
Quote from: Broni on October 14, 2007, 01:37:56 PM
In this case, I'll seriously consider shutting down Vista's firewall, and installing Comodo.
I think that's a great idea! So you weren't prompted by the Vista Firewall that Leaktest was attempting to access the internet?Well, it looks like Vista firewall:
Quote
does not attempt to manage or restrict outbound connections at all
Same as XP.The new Vista firewall was suppose to restrict outbound traffic, apparently it doesn't. Good question. Let me check.
I'm still only 1 month "old" with Vista, so I keep discovering new things.I think, I'm getting ready for Comodo...
As I can read here:
http://www.microsoft.com/technet/technetmag/issues/2007/06/VistaFirewall/

Quote
Also like Windows XP, Windows Vista by default allows all outbound traffic

and to do something about it:

Quote
The big difference between Windows XP and Windows Vista is the new Advanced Security interface and full GROUP Policy support for configuration and rules

Since in my Home Premium I don't have an access to Group Policy, I'm ready to say "bye, bye" to Vista's firewall.

Oh, well good ole M$. I'm just in a process of testing Vista's firewall, and posting results at my web page...
If anyone interested, feel FREE to check it out:
HEREOK...
After running bunch of tests (link above), I was REALLY disappointed with Vista firewall performance.
So, I did some research, visiting several firewall rating sites, and more, or less, on average, situation looks like this:



Among free firwalls, basically, I have two CHOICES: Comodo (not compatible with Vista, yet...I signed up to be informed, when they are ready), and "PC Tools Firewall Plus" (compatible with Vista).

So, right now, I'm gonna shut Vista firewall down, install PC Tools Firewall, and wait for Comodo.
I'm done.Try jetico...ready for Vista.
Scored in the top 3 in the last firewall leaktest i read which included free and paid programs.Hey, thanks...On some other page, I've read, that they are not ready yet for Vista, but I'll check.
I temporary installed "PC Tools Firewalls", waiting for Comodo.
Better, then crappy Windows firewall. I mean PC Tools.
I'll go to Jetico to check it out.Unfortunatelly, only paid version is compatible with Vista:



plus, free version is way behind paid oneI've dashed a message off to them...i've been recommending them for awhile now.
Don't know if this will produce any rapid results though...
1039.

Solve : Rundll Error - HiJackThis Included?

Answer» RIGHT clik each icon in the tray AREA and SELECT Exit.Blah, STILL nothing.
1040.

Solve : certficate?

Answer»

I have a laptop,purchased in Aug.07.The last two days I am having problems getting into my security sites.
The message reads, problem with websites security certificate.Continue not recommended.I have tried everything I know how to renew the certificate.I also restored to a back date,and wiped out the vista PROGRAM and reinstalled it with no success.
I have never had a problem with window xp renewing certificate.I am not sure I like this new Vista program.
Sure would like some help out there
Confused here. Do you mean Vista program (such as BricoPack) or Vista OS (Operating System) ??

What ANTISPYWARE programs are installed on your computer ??Sorry I did not do A GOOD JOB EXPLAINING.Yes I do have Vista os operating system.
I USE Mc Afee virus scan plus
I also get a error code when scaning for window update.
Thanks for your help
So when you visit a certain web SITE, you receive an error from Internet Explorer, telling you that "there was a problem with this websites certificate, blah blah blah, ETC."

Is this correct?yes that is right Then I assume there is a problem with the website.

Open the web sites certificate and check the date that it expires.It is not one security webb site but all sites that is considered secure.I have approx.6 secure sites Download HijackThis.
Run HijackThis and do a system scan and save a log file.
Post your log file at Computer Viruses and Spyware.

1041.

Solve : desktop background/icon picture and other problems from unkown virus or somethin?

Answer»

Hello people

heres whats wrong:

At first everytime i did a google search the links would re-direct me to random sites but thats stopped after doing a few virus searches. so far I have used kaspersky,spybot,spyware doctor, adaware, registry booster, advanced windows care, windows defender and superanti spyware. I only ever have kaspersky and windows defender open in everyday use but used the others because kaspersky and windows defender didnt find anything.
the internet google search thing seems to have stopped but now theres more problems:

Now my desktop is black and I cant change it evertime I try clicking on the personalise bit and change the background the pictures have nothing on them in my folder just a title. and even when I change the picture my background is still black. (ive attached a word doc with a print screen)

Also when i go into my pictures and other folders there are no pictures on the icons just a title and even if i change to tiles it defaults back.

my virus checkers now say there is nothing there but iam not sure becuase of the problems im still having.

here are some are some programmes I found on CONTROL panel search as instructed that I dont know what they are:

Citrix presentation server clien-web only.
Disc2phone


annybody help me

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:42:36, on 25/10/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Stickies\stickies.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
c:\program files\google\googletoolbar2user.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo RX560 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE /FU "C:\Users\MARKFA~1\AppData\Local\Temp\E_SF688.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [iCalendar] C:\Program Files\Desksware\Desktop iCal\Calendar.exe
O4 - HKCU\..\Run: [Calendar] C:\Program Files\Desksware\Desktop iCal\Calendar.exe
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Stickies.lnk = C:\Program Files\Stickies\stickies.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.xpert.adecco.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - E:\download stuff\Ares\chatServer.exe (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 9617 bytes


heres the results of the malwarebytes log:

Malwarebytes' Anti-Malware 1.30
Database version: 1323
Windows 6.0.6001 Service Pack 1

26/10/2008 15:51:13
mbam-log-2008-10-26 (15-51-13).txt

Scan type: Quick Scan
Objects scanned: 47495
Time elapsed: 4 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\AntispywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AntiSpywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Users\Mark Farmery\AppData\Roaming\AntispywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Users\Mark Farmery\AppData\Roaming\AntispywareBot\Log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Users\Mark Farmery\AppData\Roaming\AntispywareBot\Settings (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.

Files Infected:
C:\Users\Mark Farmery\AppData\Roaming\AntispywareBot\Log\2008 Oct 25 - 08_03_01 PM_992.log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Windows\Tasks\AntispywareBot Scheduled Scan.job (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Users\Mark Farmery\My Documents\My Music\My Music.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Users\Mark Farmery\My Documents\My Pictures\My Pictures.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Users\Mark Farmery\My Documents\My Videos\My Video.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Users\Mark Farmery\My Documents\My Documents.url (Trojan.Zlob) -> Quarantined and deleted successfully.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/26/2008 at 04:37 PM

Application Version : 4.21.1004

Core Rules Database Version : 3609
Trace Rules Database Version: 1595

Scan type       : Complete Scan
Total Scan Time : 00:53:29

Memory items scanned      : 609
Memory threats detected   : 0
Registry items scanned    : 8782
Registry threats detected : 0
File items scanned        : 23803
File threats detected     : 0


[Saving space - attachment deleted by admin]Tea Timer NEEDS to be OFF during the cleaning process as described in the removal instructions. Please turn it off now.

----------

Disable Windows Defender

We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.

  • Open Windows Defender
  • Click on Tools, General Settings
  • Scroll down and UNCHECK Turn on real-time protection (recommended)
  • After you uncheck this, click on the Save button and close Windows Defender.
After all of the fixes are complete it is very important that you enable Real-time Protection again.

----------

Spyware Doctor's OnGuard protective functionality may interfere with certain HijackThis fixes we need to make. Please follow these instructions to disable it.

To deactivate Spyware Doctor's OnGuard Tools

  • Click the Spyware Doctor icon in the System Tray.
  • Click Settings.
  • Click Startup Settings under Pick a Category.
  • Uncheck Run at Windows startup.
  • Click Apply and Exit Spyware Doctor.
  • From within Spyware Doctor, click the OnGuard button on the left side.
  • Uncheck Activate OnGuard.
  • (When we are done, you can re-enable Spyware Doctor)
.
----------

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus protection when ComboFix is complete.
1042.

Solve : Help! Mal/DownLdr-O?

Answer»

I currently have a Dell computer running on XP. I don't know much about computers at all so your help would be awesome! My antivirus is webroot spy SWEEPER and about 2 days ago I ran a sweep and this came up: Mal/DownLdr-O and the sweep listed it as behavioral? So I tried to quarantine it but the quarantine failed. This is the session log:

  6:42 PM:   Informational: Virus infected file c:\be.tmp not cleaned.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 20 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 19 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 18 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 17 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 16 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 15 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 14 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 13 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 12 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 11 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 10 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 9 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 8 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 7 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 6 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 5 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 4 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 3 rounds of disinfection.
6:42 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 2 rounds of disinfection.
6:41 PM:   Informational: File c:\be.tmp still infected with virus Mal/DownLdr-O after 1 round of disinfection.
6:41 PM:   QUARANTINING All Traces: Mal/DownLdr-O
6:41 PM: Removal process initiated
6:26 PM: ApplicationMinimized - EXIT
6:26 PM: ApplicationMinimized - ENTER
5:16 PM: Traces Found: 1
Quote

My antivirus is webroot spy sweeper
Webroot offers several products, and if you just have "Spy Sweeper", it's not an antivirus PROGRAM. It's antispyware program.
Webroot offers also "Webroot AntiVirus with AntiSpyware & Firewall", and then you do have antivirus program, and a firewall (available also separately).
Which one do you have, or rephrasing, do you have a real antivirus protection?
1043.

Solve : The Sims Makin' Magic debugger detected?

Answer»

um...im completely computer illiterate. when i try to start my GAME a message pops up saying a debugger detected remove it. how should i do it?Welcome ABOARD

You NEED to tell us what Windows VERSION you're using, what game you're trying to play, and what exact error message you're getting.

1044.

Solve : tr/crypt.xpack.gen trojan and worm/autorun.blw worm?

Answer»

here are the 3 logs



[SAVING space - attachment deleted by admin]Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- F2 - REG:system.ini: Shell=Explorer.exe scvhost.exe
- O4 - HKLM..Run: [RRT-Auto] \200.200.200.21installer\RRT.exe auto
- O18 - Protocol: <- Place a check mark next to ALL of the O18 entries. There is 100 or more of them.


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

Run CCleaner.

----------

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
"RRT-Auto"=-
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

Delete the fixme.reg from the Desktop.

----------

Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

----------

Do you use the Crawler Toolbar?where can i find ccleanner?


i dont know what is crawler toolbar?
good day, before i do you instruction i already done some actions for those viruses.


i scan my system with AVG anti virus and after that i also try to use the symantec anti virus..

then i do what you have advice


here is the log of combo fix

[Saving space - attachment deleted by admin]CCleaner is one of the tools you were supposed to download in the malware removal guide...

Go to Add/Remove Programs and uninstall Crawler Toolbar


----------

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Folder::
C:\Program Files\Crawler

File::
C:\WINDOWS\system32\rrt_is.wav
C:\WINDOWS\system32\rrt_vf.wav
C:\WINDOWS\system32\rrt_tv.wav
C:\WINDOWS\system32\rrt_tn.wav
C:\WINDOWS\system32\blastclnnn.exe
3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: PERFORM this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezehi here is the log, i THINK my computer are now ok... hehe

[Saving space - attachment deleted by admin]before i forgot, i have this the same problem on a laptop... em i going to do the same process?

    Yes do the malware removal guide. Be sure to start a
new topic for any separate computer.

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
  • The above procedure will:
  • Delete the following:
  • ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file EXTENSIONS, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

Download ATF Cleaner by Atribune to your Desktop.

Alternate download link

Note: Vista users must use Run As Administrator
  • Under Main: Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • Click Exit on the Main menu to close the program.
.
Note that your system will run slower for a reboot or two after having used this tool so don't panic.

Important: Restart the computer before continuing.

----------

Final steps.

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.hey thanks for all the thing you advice, pls help me again..  i have 10 to 20 more computers that are infected of this Trojan and 1 more laptop infected of this two virus... thanks again and more power


ill post later or maybe the next day the logs from the laptop that i mentioned... Quote
i have 10 to 20 more computers that are infected of this Trojan and 1 more laptop infected of this two virus

This web site and the helpers are here to assist home users with common PC problems and we are in no way ready to replace an IT department which is who you need to maintain all of those computers. to everyone,

hmmm... i want to ask SOMETHING... is there any way of manual deleting of this tr/crypt.xpack.gen? like using command prompt or dos command.. if you know some thing... pls teach me how..  and pls i want an effective solution...




thanks
Do a Format and clean install on all 20 machines...Post back with the results.is ther any other way, formating may cause file missing or corupt. even i backup files
1045.

Solve : blaster worm??

Answer» O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
This is Realtek tool, which most people consider as a spyware (collects data). On the other hand, there are some reports, that some people were having problem with Realtek's on-board sound chip performance.
I'd remove it. If something wrong with sound, we'll know where to look.Sorry late replying. I am using realtek media player and wanadoo is my ISP so do i still need to delete the following entries or will it cause these programs not to run properly?

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm

Have run spybot and pc is clean according to that. I have had several blue screens since last post and they are giving me different error messages each time.
I have now had:

DRIVER IRQL NOT LESS OR EQUAL

MEMORY-MANAGEMENT

WIN32K.SYS

BAD POOL HEADER

Also all of my bookmarks/favourites  have disappeared for some reason. Event VIEWER showing tons of different error messages.
I have run windows memory diagnostic tool and it shows no errors.
Can someone tell me how to find and post my bug check files please?
I have searched for my debug.log file but all i can find is a notepad which is empty!  Leave those two entries alone.
Your problem looks more like hardware, or bad driver problem.
I'd advice you to make a fresh post under "Hardware", so we can start fresh.
Before you do so, try couple more things:
- remove your RAM, and clean CONNECTORS with eraser (MAKE SURE, YOU GROUND YOURSELF, FIRST)
- Can you boot to Safe MODE?Yes, can get into safe mode and it doesnt blue screen then but i get error messages telling me that random programs need to close.
For some reason there was 3 browsers on pc when i had it. Have been using firefox but it stopped working yesterday (all my favourites disappeared and then the icon wasn't clickable.)
So I uninstalled firefox and I have been using opera since then and amazingly, pc hasnt bluescreened once! 
Is there a KNOWN issue with firefox? Or the fact there was 3 browsers on pc?
Will let you know if it happens again but so far so good! 
Just tried browsing with explorer and GOT a nasty bluescreen within 30minutes. Back using opera again .   Normally, you can have as many browsers, as you wish. They shouldn't interfere with each other.

Did you try that memory stick(s) cleaning?

It would be worth to totally uninstall Firefox. Instructions here: http://kb.mozillazine.org/Uninstalling_Firefox
Then, install a fresh copy.
1046.

Solve : MSN messenger virus removal help?

Answer»

hi i need HELP in removing a virus or something that i got from accpting a file that said something like"remeber when i had hair like this" but i cant remeber exactly, and also the message said "my friend took this funny picture of me" it was a zip file and it had the word photoshop in the name and when i clicked it i couldnt move my mouse and the my contact boxes were opening and closing one by one very fast and i had no control over anything...i took the battery out and put it back in and then i uninstalled msn messenger, after i installed it again everything was FINE and after 30mins the samething happened...now i have msn uninstalled and that file deleted.....

          How can i remove this virus and use msn message again without that problem but i dont NOTICE anything wrong with the rest of the laptop. I had got the virus on October 14 2007
 
THANK you for your time...uninstall your current anti virus, download avira
http://www.avira.de/en/download/index.html
and use s&d
http://www.safer-networking.org/

update & run full scan in safe mode, install back msn and enjoy!I've had this virus; it is Trojan Horse IRC-Bot (or something close to that name). If Avira and Search & Destroy don't work, you'll get it with AVG.

Anyway, I believe that virus uses your Messenger to pass itself on, and it is likely that your friend (or whever gave you the file) is infected with this virus as well. I would recommend telling them about it.thanks for you guy's help i THINK i removed them..You can also go into msn prefrences, and then go to security, and uncheck the accept links in the conversation window, also. Second, check the box that reads, automatically reject file transfers for known unsafe file types. Also, turn off sharing folders.

1047.

Solve : deskpan.dll is missing and do I really need it since my xp Pro works?

Answer»

I ran Sysinternals Autoruns and in the RESULT was deskpan.dll was missing and since it was missing I unchecked it. I did a Google search but the answer to my, I admit, small plight was inconclusive. I discovered that it is a Microsoft file, what it did, but not if it was really needed.

Do I need deskpan.dll?

 I can't find anything wrong with my system, XP Pro SP2, 512MB RAM, primary partition for system, extended partition with two logical drives, all basic, ntfs. Need anymore info?Filename Deskpan.dll
Processname Display Panning CPL
Author Microsoft
Part of Microsoft Windows Operating System
Associated with virus No viruses seems to be using this filename.
Associated with spyware/adware We haven't been able to locate any antispyware information concerning this file.
Description Deskpan.dll is associated with the Display Panning CPL Extension and used to change the way the picture is presented on screen.


Info you PROBABLY already found, it does say it's a CPL Extension, ie. Control Panel, so with that file missing I'd assume you'd have errors when you open up control panel, if not, and no other errors navigating throughout control panel, I wouldn't worry about it.

I can't find it readily to download from "download dll" webpages, so maybe it wasn't standard with windows? sometimes video cards install their own special stuff, maybe try reinstalling your video CARD applications/drivers again if you want to have it back.I dont have any problems, so I will ignore it and keep it in a corner of my brain for future exploration. . Yes, I did find what you quoted.  Thank you.Good to see you again Triple S....
If it does crop up as an issue just go to Start/Run and type in sfc /scannow and hit Enter...have your XP CD handy it will ask for it.
Windows will replace/repair any system siles in this process. Quote

Part of Microsoft Windows Operating System

Must be some bull, because, if you go to MS dlls site, it's not listed there as Micro$oft file:

http://support.microsoft.com/dllhelp/?dlltype=file&l=55&alpha=deskpan.dll&S=1&x=18&y=10Patio,
I am senile. Of COURSE that is the way to do it.  But I am not GETTING any error messages; I didn't see any errors in Application or System event viewers. Apparently I dont need it. My primary computer runs superbly. My Mac has hung up more this year.
1048.

Solve : Virus Infection: Exploit.Java.Gimsh.b?

Answer»

Thanks for taking over, evilfantasy.  I didn't get a chance to provide AMPLE warning of my leave.  Things have been hectic (again!), so he was probably in better HANDS with you anyway.

And mattd, thank you for being patient and following evilfantasy's advice.  I was hoping to have everything completed with you before I had to take off, but that unfortunately didn't happen.  But I assure you that you were left in good hands.


Just to get a better understanding of malware, I suggest READING the post linked below...
http://www.castlecops.com/postlite7736-.htmlYou did such a great job, I can't believe that I could even be in the same "room" with you.

Thank you so much. Maybe I can return the favor some time.  Stay well!For CB Matt (Chris)

3 weeks since you helped me solve my VIRUS problem and no new viruses. I remain grateful for your help.

Sincerely,

mattd

Great, that's what we LIKE to hear!  I'm very glad that evilfantasy and I were able to help you.

1049.

Solve : TROJAN HORSE FOUND BY AVG?

Answer»

hello

i need some iformation please, I am using an old IBM pc, running windows xp professional, service pack 2, and AVG 7.5 free version.On 14 October the antivirus AVG picked up the following TROJAN Horse 7.MCU, and the next day also it picked up the same only in a different location, and with a different file name.
prior to this a few months ago AVG DETECTED  a virus called obfustat.ITZ,
now these two are in quaranting in the virus vault, i am wondering if these could cause any harm, should i delete them from the virus vault.

And are there any possibilities of having any more viruses. I have run spy bot and no threat  were  found.
I would like very much to post a screen shot of the contents in the virus vault, but can't find out how to do it.

Any suggestions or help will be very much appreciated.

thanks

The Saint.
You can  create a screen shot by pressing the print screen key . This will usually TAKE the screen shot and place it into the computer clipboard. Once in the clipboard you can use the screen shot in anyway you want, you may upload it to Photobucket and from there you can copy it and paste it here.( the options to copy it are on the  side of the picture , choose copy to forums option .


Yes, screenshots may be useful.

However, in the meantime, make sure you delete everything from AVG's virus vault.

Then run a couple of good free malware removers such as Superantispyware and AVG Anti Spyware (Google them; they are easy to find).

Next download HijackThis and scan your computer with it.

Post the scan report log in this thread for someone to review it for you. DO NOT change anything with HJT UNLESS under the advice of a trained analyst. Using the program wrongly can trash your computer.


OJHere is a link to Hijack This
Just select the option scan and save a logfile and remember what OddJob said do not change anything with HJT .
Here is a link to Super Anti Spyware
Here is a link to AVG Anti Spyware

I recently had very bad Trojan Problem which was solved with the installation and running of a-squared anti malware
It works just like an antivirus and dosent get in the way of your firewall, removes malware , trojans , keyloggers, worms etc etc

Thought the links would make things easier for you

Best of luck.

Ivy
Ivy,Oddjob

please see the HJT log file below. Please advise. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 11:29:58 AM, on 10/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
E:\SONICS~1\SsAAD.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\CameraFixer.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
E:\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\MTV Networks\URGE\UrgeMS.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\Ipe40.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn0\YTBSDK.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\QVQJDR8X\HijackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify2?.refer=slv&.intl=us&.src=ym
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "D:\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SsAAD.exe] E:\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [PowerBar] "C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LDM] E:\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147867963562
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172741842859
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamemanager/DIGGameManager.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2019FE9F-B74D-44F4-B66F-BBDE5696AE0A}: NameServer = 218.248.240.23 218.248.255.145

Rest continued in next post as the message seems to be more than10000 characters.
HJT log contd...

O18 - Protocol: bw+0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - E:\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

rest in next post since messages contains more that 10000 charactersHJT LOG CONTD...

O18 - Protocol: bwq0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {4F56B6D4-F9C4-4E1B-BE8F-F64B095832D7} - E:\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PML Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe[/b]Your log is fairly clean.

Re. your first post it seems AVG was doing its job. Whatever it found was removed and not on your machine any more (unless it's hiding deeper than HJT can see which is always a possibility).


Do you know what this fie is, what it does and which program installed it ....

C:\WINDOWS\CameraFixer.exe?

Please advise.


Which firewall are you using? I can't see one in the log.


The version of HJT you are using is slightly out of date. Merijn has now sold the program to Trend Micro and the most recent version is available here ....

http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
Please use this one in the future.


Your HJT file is on a temporary place on your computer. The program makes backups which could easily be lost if HJT isn't somewhere more permanent.

Go to the file ...

C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\QVQJDR8X\HijackThis[1].exe

....and drag & drop it directly on to your main hard drive.


All those 018 entires are form Logitech Desktop  Messenger. It clogs up the machine. Best advice is to remove / uninstall that program and fix all this 018 entries with HJT thus ...

Turn off Windows Defender and Spybot's TeaTimer application as they could hinder HJT's fixing process.

Open HJT ... click on 'Do a System Scan Only'... put tick/check marks next to this entry IF it's STILL present ....

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

AND all those 018 entries IF still present.


Remember to close ALL open browser windows – including this one – before clicking on “Fix Checked” at the foot of the HijackThis window.


When this is all done re-activate Defender and Spybot's resident TeaTimer protection.

Post a fresh HJT log with an update on how the computer is behaving now.


OJOddjob,

Should i do the HJT scan wtih the new version, from the link you provided, post the log for you to see in case any thing has been missed   or continue with the old one which is lying in the temp folder?

thanks
The Saint.Follow oddjob's steps after moving/re-downloading HijackThis to a permanent location (such as C:\Program Files\HJT).  The temp folder is a temporary location.  If HijackThis stays in there, it will eventually get deleted and so will its backups, which are important to have.  So, put the program in a permanent location and then run it from there.  You may then safely follow his instructions.
1050.

Solve : CA Security Says clean but pc keeps freezing..?

Answer»

I TOTALLY agree with patio, so I'd RATHER not proceed here any further.Nevermind. I fixed it myself.

Feel free to lock this post and delete it. SORRY for any TROUBLE. How was it fixed??


JB