InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1301. |
Solve : Not sure what is wrong, might be a virus, I'm not sure.? |
|
Answer» OK, my issue is that I can't sign into AIM, MSN messenger or Yahoo Messenger, and I also cannot use any browser except for Firefox. I'm running Windows XP and this only happened recently.
|
|
| 1302. |
Solve : Bearshare? |
|
Answer» I foolishly downloaded "Bearshare" and it seemed to want to take over my computer. |
|
| 1303. |
Solve : Windows Police Pro on Friends PC? |
|
Answer» Quote from: evilfantasy on August 31, 2009, 10:34:55 PM Download UnHackMe and save it to the desktop. kk we will give it a try but like i said it malware bytes and hijack this just close out after a few seconds most .exes don't even run.Try it in Safe Mode also. Try RUNNING HJT in Safe Mode also. I need logs... Quote from: evilfantasy on September 01, 2009, 10:50:39 AM Try it in Safe Mode also.Hello Evil Fantasy WE run Unhackme Found alot of nasties I made sure to research them on google we deleted them are only problem now is that We still get riderects to odd sites.. We still can't run HJT or Mbam any idea?Download RegRun Reanimator * Open an executable file to start program installation. Follow the installer instructions. * At the end of installing software on your computer you will be prompted to run Scan for Viruses * Click on the Fix Problems button. * Restart your computer for the changes to take effect. ---------- Now try Malwarebytes.yup this is the nasty virus i have as well, i can't even run unhack me in safemode. I get the debugger 97 error and then it comes back with the error "windows cannot access the specified device, path, or file. You may not have the appropriate permission to access the file" yet i'm running everything as admin that's the issue i get with malware bytes as well, but i cant download the renamer without getting that debugger97 error. Anyone know how to bypass any of these?slixie , you cannot hijack another topic please start your own topicalright i tried that 2 days later it came backYou need to keep going with my instructions until given the all clear. |
|
| 1304. |
Solve : Combat Arms Virus?? |
|
Answer» My AntiVira Antivirus SOFTWARE detects this:
|
|
| 1305. |
Solve : superantispyware step? |
|
Answer» Hello ALLAN, |
|
| 1306. |
Solve : Requesting help fixing trojan infection? |
|
Answer» Let us know how it goes. If needed we can try a few other things.Im having trouble getting the computer to let me choose to boot from the USB. Im still trying to find the option, but no luck so far. After i START the computer and press F8 to get to the options screen before it boots, i cannot find an option for USB or removible harddisk boot.Try using the F12 key.does nothing. F8 is the key on that computer. i can also load a ROM settings screen with F10. but no where in the menu can i boot from anything other then the hard drive. im just going to put the ISO and the unetbootin file on a gig stick and put it all on there and install it from that computer and reboot thereeven after installing directly onto the hard drive of the computer there is never an option to boot any DIFFERENTLY in any of the starting menus. Thanks for the help, but my patience with the computer is GONE now. Gonna just wipe the hard drive and start FRESH. |
|
| 1307. |
Solve : Computer keeps restarting before it even loads up? |
|
Answer» Is this a NetBook? My issue has been resolve with the help of someone else! heyy how did you fix this?? im gettin the same problem!!!! do i have to wipe out my comp?!?! |
|
| 1308. |
Solve : McAfee Detected Suspect File? |
|
Answer» I have an HP computer w/XP. Ran MCAFEE last night and it found the following "POTENTIALLY Unwanted File" : C:\hp\bin\KillWind.exe |
|
| 1309. |
Solve : McAfee Slowing Things Down!? |
|
Answer» Installed MCAFEE 90 day free TRIAL last night. Computer is noticeably slower now. I have HP with XP and FiOS 25/15 internet connection. Is this slowdown typical or should I look for a problem?As a rule I don't badmouth software vendors, but McAfee produces pretty poor products. I don't know which particular McAfee app you've installed, but I strongly suggest uninstalling it and trying a competitor's product (ANY competitor's product).Thanks, the deed is done. What anti-virus do you recommend?There are so many good products out there. I'm a fan of Kaspersky for a number of reasons (for example, they update their definitions HOURLY as opposed to daily or weekly as most other vendors do, their online forum support is OUTSTANDING - as is their PHONE support, and their products are consistently ranked at or near the top of pretty much every reliable comparative evaluation I've seen). Other very good products (paid and free) include NOD, Avira, Avast, etc. Lot's of threads on other forums you might want to check out - not sure if I'm allowed to POST links here though. |
|
| 1310. |
Solve : The Virus Alert Virus? |
|
Answer» Okay now lets take away the unnecessary startups the right way. Msconfig is for troubleshooting and is not a real startup manager.
Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. ---------- If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixLooks like the rest of the family doesn't get time on mama's computer anymore. Here is the log and a screenshot of an error box regarding rundll when combofix was WRAPPING up. [Saving space, attachment deleted by admin]Does that error appear when you restart the computer? How is the computer running now?Well, all was going fine until I was browsing my brother's picture section on myspace. The first time it POPPED up, I was on myspace. I assumed it was from someone else browsing other things on my computer, but looks like myspace may be the culprit. This time it was Antivirus 7. Do you know of any connections between this Antivirus bug and myspace?Sorry for the delay. Are you able to run ComboFix in Safe Mode?It is definitely linked to myspace. Every time I go to someone's picture section (this time my own pics) I get a new antivirus soft virus. I'm really just posting back here to let you know that it HAS to be related to myspace, somehow. Go back to this post and try it again please. Here are the new logs. Thanks for getting me back on the wagon, I was close to giving up. [recovering disk space - old attachment deleted by admin]If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure to save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFix |
|
| 1311. |
Solve : quick help w/ hjt logs? |
|
Answer» Hey guys, i have more svchost s running then that Are you a Malware specialist all of a sudden? I'm sure the SPECIALISTS are greatful for your input.i never said i was but the svchost number really doesnt matter unless you notice other signs of a malware infectionyou should not GIVE advice unless you can stand over it , LEAVE it to the expertsthanks for the help!looking for other replies out here, I'm also wondering what to do about it.. Quote from: printerface on September 08, 2009, 04:52:45 AM looking for other replies out here, I'm also wondering what to do about it.. you will have to start your own topic dont mees with registry and dont take anything out of the hjt log on your own let an expert tell you what to do |
|
| 1312. |
Solve : VIRUS DNA CHANGER? |
|
Answer» HELOO, CAN ANYONE HELP ME? Everytime i delete/turn off my virus dna CHANGER my internet stops any idea how?No NEED to post the same question more than once. |
|
| 1313. |
Solve : Application Cannot Be Executed. The File *** is infected - Under Attack? |
|
Answer» Good EVENING, |
|
| 1314. |
Solve : BAD virus. can't open hijack this, firefox or any other apps.? |
|
Answer» i meanly talk about this part Very important, do the following immediately or as soon as possible!the rest of it is good advice but still if you back up to a flash drive i am sure the virus can also jump drives when trying to retreave off the flash drive so wahts to keep it from infecting another computer?Read the reply. It's all explained.would it possibly be good news at all if none of my photos or music files came up as infected in the scan? i am going to buy a new hard drive tomorrow to transfer these files to. in the meantime, what "action" should i take in the avast scan? should i delete the infected/un-repairable files? they are mostly EXE and tmp files. i know my photoshop, office, etc will be shot, but i would prefer that happen than my photos. by the way, is there any way to salvage my outlook files? OLD emails, address BOOK, etc? Quote from: landa321 on August 26, 2009, 09:17:24 PM would it possibly be good news at all if none of my photos or music files came up as infected in the scan? Yes but I would scan them with another scanner to be sure. Quote from: landa321 on August 26, 2009, 09:17:24 PM i am going to buy a new hard drive tomorrow to transfer these files to. in the meantime, what "action" should i take in the avast scan? should i delete the infected/un-repairable files? they are mostly exe and tmp files. i know my photoshop, office, etc will be shot, but i would prefer that happen than my photos. The files that Avast is going to quarantine will make the drive useless because it will remove critical system files needed for Windows to work. Quote from: landa321 on August 26, 2009, 09:17:24 PM by the way, is there any way to salvage my outlook files? old emails, address book, etc? You can back them up and do the scans on them also. Although I would think that they are the most likely ONES to be infected. Quote from: evilfantasy on August 26, 2009, 09:26:55 PM
should i go ahead and delete those files then? the drive already doesn't boot up anyway since i did the avira scan. i am more concerned with saving what i can before doing the reformat/fresh install. Quote from: evilfantasy on August 26, 2009, 09:26:55 PM is it possible to back them without starting outlook? can i go in and just copy the file? i am not 100% what folder those files are located in. would those be pst and pab files?I'm not sure where they are located and I believe they are .PST files.how about the files? let avast remove them or quarantine? i know i am eventually going to reformat this drive, but i still feel better getting rid of those files. does it matter?When you reformat you will be getting rid of them,I am finally back up on my desktop. I was able to save all of my important files on to a brand new HD and I ran scans on that HD to make sure all the files were safe. I ended up reformatting an older hard drive that was only 100GB and doing a fresh XP install on that. This way, I can reformat the infected 750GB HD and just use it as external storage. this way, if I get infected in the future, I will have all of my important files backed up. Lesson learned. Thanks all around.sometimes spywares are blocking some of our downloads, so you can just close your spyware and download hijack, but if the problem still insist, how about reformatting your computer. Quote from: printerface on September 08, 2009, 04:41:37 AM sometimes spywares are blocking some of our downloads, so you can just close your spyware and download hijack, but if the problem still insist, how about reformatting your computer.That's exactly what he/she did. |
|
| 1315. |
Solve : Antivirus just labeled Hosts file as virus and removed it.? |
|
Answer» Sorry before hand if post should have been directed elsewhere. |
|
| 1316. |
Solve : can't get rid of virus/rootkit infection - need help...? |
|
Answer» hi,
Here's the ESET log. I don't think that one file it found was actually bad, but I let it delete it anyway just in case. BTW, do you know if there is any updates or anything out there that will prevent future TDSS rootkit infections? I will obviously not make the same mistake again and pay full attention next time I delete bad emails (so that I click Delete instead of the link ). ************************************************************************************ [email protected] as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=7.00.6000.17023 (vista_gdr.100222-0012) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=53084455feb56a4bbcbf6ea0ddeb8a5e # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-05-03 12:04:28 # local_time=2010-05-02 08:04:28 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 109470394 109470394 0 0 # compatibility_mode=3586 16764925 100 81 0 697131779 0 0 # compatibility_mode=5889 16768381 100 100 59385052 112653725 0 59456579 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=129823 # found=1 # cleaned=1 # scan_time=15689 C:\Downloads\Utilities\framework-3.0.exe JS/TrojanDownloader.Psyme.NCX trojan (deleted - quarantined) 00000000000000000000000000000000 C ******************************************************************************* Thanks! Safe surfing. I recommend to stay away from downloading anything, including from P2P programs/sites, torrents. Rootkits get distributed highly in P2P downloads. Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
|
|
| 1317. |
Solve : How does Win Police Pro gets into your computer? |
|
Answer» I have a friend that his OP crashed because he had Win Police Pro. It downloaded itself and BEGAN its DESTRUCTIVE course. My question is how did she get it in her COMPUTER, via e-mail, via the Internet. anyone know it comes thru?Can be via email, but usually from a link on a website or sometimes downloads,,.....Use Web of Trust to screen all websites while browsing and the CHANCES of it happening again will be greatly reduced...... |
|
| 1318. |
Solve : The only thing I can see if my screen saver.? |
|
Answer» Quote from: rker321 on September 09, 2009, 05:03:24 PM A name change UH!!!!!!Didn't mean to confuse you. The name change thing has NOTHING to do with your posts.Ok I downloaded a boot CD and it scanned the computer, it showed all kinds of viruses. most of them low, but about three of them very HIGH. I couldn't clean them because they wanted 40.00 to do the fixing. So I THOUGHT that I would use my McAffe CD to clean the viruses. Is that ok? Now by clicking control- alt-delete and clicking the apps. I was able to see all the folders, but couldn't make Windows open them. So I could not use the antivirus installed in the computer. The desktop seem to be behind the screen saver. Is there a way that I can reach that screen saver and delete it?yes use mcafee who wanted 40.00 to clean it you must have bought it Or you can download a free boot virus scanner (Avira, Avast, etc).One of the three that I was told to get. it was not Karpaski they wanted 89.00 Anyway, I will create a Boot for Avast that is the system that I have in the computer. I could not bring it up or have Win open it upas allen said avast or avira , dont pay for any thing you will get good free stuff here |
|
| 1319. |
Solve : Can't get past welcome screen? |
|
Answer» Had a virus on my netbook. Use XP. Some kind of 'security essential 2010...buy my software or else'. Downloaded spybot and ran it. Might have worked...don't know. Can't get by the welcome screen. When you get to the welcome screen, it has USER there...not what I had set it up for. When I press USER, it looks like it is going to start but then closes down on itself. It doesn't turn off the computer, it just stays at the welcome screen with USER still there. You can't go any farther. sunboysunday - please start your own thread.i did. thank you. |
|
| 1320. |
Solve : Please Help Something is eating my Memory? |
|
Answer» yes this is your TOPIC go ahead and do it Malwarebytes....all the entries say No Action taken.....they were not quarantined or removed. never noticed that , thanks karnac , just amazed at the amount was in the pc xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxx BUYDELL , RERUN SAS AND MALWARE AND DELETE ANYTHING THAT COMES UP PLEASE , and then rerun your hjt and place all 3 logs HERE edit at 1.30 am GMT going to bed have to get for my pension , see them to-morrow |
|
| 1321. |
Solve : Extremely aggressive worm chokes instant messaging? |
|
Answer» New variant of Palevo blasts unprotected systems via fake photo gallery links. |
|
| 1322. |
Solve : How to remove windows defender? |
|
Answer» Hi, |
|
| 1323. |
Solve : Rogue Problem? |
|
Answer» You're welcome! This problem came back again. Should I follow the same procedure in removing this MALWARE? Please download the GMER Rootkit Scanner. Unzip it to your Desktop.
=>LOCKED. |
|
| 1324. |
Solve : Cannot Open Anything? |
|
Answer» I have tried using the "Read this before requesting malware help" thread, but after installing and running CC cleaner, and installing and beginning a scan with SUPER Anti Spyware, my computer froze and now i cant open up CC cleaner, or Super Anti Spyware. I have tried REINSTALLING, but i cannot open the installer.If you've lost your CONNECTION, download the programs to a USB stick on a good PC and transfer them to your PC. |
|
| 1325. |
Solve : Application cannot be executed. The file --- is infected? |
|
Answer» My housemateat university is having issues with his computer which a lot of other forum members seem to be having. Having read some of SuperDave's advice it seems each case is quite unique so I would appreciate any possible help in fixing his laptop. Here is a HJthis log from safe mode, but I can't manage to launch one in normal startup;
|
|
| 1326. |
Solve : computer won't install any mal-ware removal programs? |
|
Answer» Go to this LINK to create a Rescue CD or to this site to create a Rescue USB. Carefully FOLLOW all the instructions for whichever METHOD you choose. |
|
| 1327. |
Solve : APPLICATION CANNOT BE EXECUTED! WHAT DO I DOOO? |
|
Answer» I keep getting this alert and I don't know what to do. My laptop is run by WINDOWS vista bought 2.5 years ago. SOMEONE HELPPPSome applications cannot be run in vista because of compatability issue....Right click on application --> properties --> compatabilty. and select Run this program in compatability mode for then choose the windows version.noooo its a malware thingy rogue program or whateverI FOLLOWED SuperDave's instructions i saw in other threads. But I can't seem to update SUPERAntiSpyware cause of the firewall or something |
|
| 1328. |
Solve : Total Security 2009? |
|
Answer» I've tried everything.. |
|
| 1329. |
Solve : Suspicions of Malware on my laptop? |
|
Answer» Hi guys and girls |
|
| 1330. |
Solve : Yahoo Instant Messenger ??? |
|
Answer» Win XP Java is updated. all other updates currant. On my sisters computer, doing a cleanup. Used AVG and malware BYTES, also deleted all unused programs. Tried to remove Yahoo IM and it will not delete. All other programs not wanted deleted just fine. Runs much faster now but am WORRIED about any file that will not allow us to delete it. We had IE 8 and had to remove it also. Please direct me how to remove. THANKS RC 1) Deleting unused programs does not speed up your system |
|
| 1331. |
Solve : "Your System is Infected" is virus leeching my computer - help please! :)? |
|
Answer» I'm not sure what you mean by 'paid' - the PC Guard I was using was 'free' with my broadband, but I was PAYING for the Broadband... so I guess it's paid? It was also updated. However, I've since changed to avast, which has thrown up a few viruses. The file names are: I've deleted the above, but the following system files remain in the avast 'chest', as I didn't know what to do with them: Leave them there. Run a new HijackThis scan and post the log please.Thanks [attachment deleted by admin]Disable Spybot's TeaTimer While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with HijackThis fixes. Please disable TeaTimer for now until we are done. 1. Right click Spybot in the System Tray (looks like a calendar with a padlock symbol). Choose Exit Spybot S&D Resident 2. Run Spybot S&D 3. Go to the Mode menu, and make sure Advanced Mode is selected. 4. On the left hand side, choose Tools > Resident uncheck Resident TeaTimer and OK any prompt and Restart your computer. Note: If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it. If TeaTimer will not turn off then uninstall Spybot until we are done cleaning. ---------- Open HijackThis and select Do a system scan only Place a check mark next to the following entries: (if there) - F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe,C:\WINDOWS\system32\word64main.exe, Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. ---------- Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixI performed the Malwarebytes scan, and checked and fixed F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe,C:\WINDOWS\system32\word64main.exe, However, it seemed to fix it so quickly, that I wasn't sure that I done done it properly. I pressed scan again, and found: F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\word64main.exe, Is this right? I've also attached the latest ComboFix log. [attachment deleted by admin] [attachment deleted by admin]That's the same log you posted earlier.Download OTM by OldTimer to your desktop. Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator. * Save it to your Desktop. * Double-click OTM.exe to run it. * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy) Code: [Select]:Processes explorer.exe :services :reg :files :Commands [purity] [emptytemp] [start explorer] * Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste. * Click the red Moveit! button. * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply. Close OTM Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. Oh dear.... After I copied that information into OTM and clicked Moveit!, the program did its thing, then asked to reboot. I couldn't select any of the information in the Results section, so couldn't copy it. When the computer rebooted, all I got was my background. I managed to get task manager up, and rebooted several times, but still, just the background. I rebooted in Safe Mode, but all I got was a black screen, so had to restart. I've managed to get my internet connected and an internet browser window up using Task Manager, but do not have a Task bar or start button, and there's NOTHING on my desktop. I tried to run OTM, and it brought up a log, so I've posted that. I must have done something wrong, but followed the instructions exactly. I was sure that I only highlighted the text on the previous Code box; would it have made a difference if there was an extra space in it?? With regards to the previous Combo Fix log - I definately attached a log that was different to the previous one - unless I failed to follow previous instructions properly.... [attachment deleted by admin]Start the computer in Safe Mode. Getting into Windows Safe Mode. From the options choose Last Known Good Configuration. Let me know how that goes. Do you have your Windows install CD?I'll do that now. I don't have the Windows Install CD - I have recovery discs, though. Will this do any good? - Had a go at starting in Last Known Good Configuration... no luck. I'll get the recovery discs ready! - Sorry to modify my post yet again, but something STRANGE has happened. I tried to open just any old folder in desperation using Task Manager (I think it was shared documents or something), and a Windows message came up: /idlist.:992:3832,C:\Documents Windows cannot find '/idlist.:992:3832,C:\Documents'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search. My start menu, task bar and Desktop came back at this. When I restarted my computer, they were gone again, but when I opened another folder, I got the Windows message and they came back again, although my computer is slowing down at odd moments, then picking up in speed again. Hummm... is this no longer a malware problem? Should I post this in another forum? ThanksEdited.I had a similar-looking virus wreak havoc on my comp a few weeks ago. I had norton antvirus, which, apparently, proved to be useless. The virus simply messed it up. The virus prevented me from opening any antivirus programs...so I restarted in safe-mode and ran Malwarebytes. MB picked up the virus and squashed it flat against the wall, like a disgusting bug. I know this method doesn't work for everyone...but it's worth a try. Due to no further response from the OP, this thread is locked. If the OP wants it re-opened, please pm me. |
|
| 1332. |
Solve : Undetectable malware/virus/Antispyware Pro?? |
|
Answer» I've been fighting this problem for a few weeks now, off and on. Occasionally I'll be infected with Antivirus Pro 2010, Antivirus Pro 2009, and most recently Antispyware Pro. After running the usual "remedies" such as SAS, Malwarebytes Pro, Trojan REMOVER, and Spybot it'll somewhat go back to NORMAL...only with a random popup here and there. Everytime a popup hits, AVG will tell me that there is a threat, so it's almost like something is there but not being detected.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.Peterwolfe, please don't make this more confusing for the OP. THANK you. |
|
| 1333. |
Solve : AVR09.EXE, Cannot Launch CMD, or Task Manager? |
| Answer» OH sweet lord in heaven. It found it. Rebooting computer to take CHANGES now. Whewww thanks for recommending SUPERAntiSpyware. I checked their website about winupdate.exe, and the POSSIBLE sizes for the files, matched the exact SIZE of my winupdate.exe. I hope this PROBLEM is resolved... | |
| 1334. |
Solve : Rogue.A360AntiVirus and other problems? |
|
Answer» This is a Dell Inspiron 1525 laptop, Vista HOME Basic SP1. |
|
| 1335. |
Solve : anti viruses? |
|
Answer» Quote from: Ironman on DECEMBER 31, 2009, 01:57:13 PM I have 5 pitbulls that serve as my anti-virus and firewall. thats fine , as long as there are no kids there for the DOGS to KILL Quote from: harry 48 on December 31, 2009, 01:11:29 PM avg no , takes up to much room , slows the pc when runningthanks for your info |
|
| 1336. |
Solve : Bad virus help plz? |
|
Answer» Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices. |
|
| 1337. |
Solve : please read this hjt log? |
|
Answer» could you let me know what you think of the log please you don't need info to read the log do youIt usually helps just in case the hjt is clean, So if the person has problems with a clean hjt we can get another tool to examine with. (like RSIT) By the way I found nothing. Hello Harry. The HJT log is clean. Let's try this: Download random's system information tool (RSIT) by random/random from here and save it to your Desktop. •Double CLICK on RSIT.exe to run. •Click Continue at the disclaimer screen. •Once it has finished, two logs will open. •log.txt <will be maximized and info.txt <will be minimized •Please post the contents of both logs in the next reply. Quote from: cat-bomb on October 07, 2009, 04:31:37 PM It usually helps just in case the hjt is clean, So if the person has problems with a clean hjt we can get another tool to examine with. (like RSIT)ok i checked it myself as well and found nothing Quote from: SuperDave on October 07, 2009, 05:07:12 PM Hello Harry. The HJT log is clean. Let's try this: THANKS dave , it's a friends log so i'll pass that on , i got her to take things out of add and remove , i have been going through her pc by e-mail all WEEK and all her logs are clean so after the hjt was clean we will do the post you sent if there is any more bother i'll get her to join up , the pc seems to be going fine but on the last checks now, harry |
|
| 1338. |
Solve : Toshiba Laptop Super slow and non responsive, was directed to post in the malwar? |
|
Answer» I followed the instructions in the guide and I finally got Avast antivirus installed on the laptop but was not able to update it as the system would not let it connect to the web site, I ran a boot scan and it did not find anything, then I was able to update the virus scanner and ran a scan and it found 5 or 6 infections which I placed in the chest, then I installed the cc cleaner and ran it and then I could not connect to have it analyzed so the log is gone, now the computer is so slow that it takes about 20 minutes to get to my desktop, and the control panel will not open, when I click on control panel I get a silhouette of the window and the rest is invisible then it closes on its own, also it keeps closing and locking the user after less than 60 seconds, I am so frustrated and confused I don't know what to do now, Please help!! Irven You have to produce some logs....try running them in safe mode and/or when you save the programs rename them , For example...test.exe or sniper.exe...this will allow the programs to fool the virus.......this may enable you to run them and produce logs for analysis...........You may even have to download the programs to a USB drive and transfer them to the infected pc......Calm down, relax, and someone will get you up and running,,,,Thank you Karnac for your post, I am sorry I did not see it until now as when I posted in this section I neglected to click on notify of posts, But I did make some headway as I was finally able to open the control panel by going through the windows explorer and was able to delete some of the malware using the rogue tool list, As far as starting in safe mode I cannot get past the loading of the files as it sets there for hours and I have to shut it down. I ran the virus scan again and it did not find anything so I tried to back up all of the files that I need to save to my external hard drive but after about 2 hours it failed and the window said that it could not find file 0x80070002, I have no idea what it is, I tried backing up just one file to see if maybe the missing file was in one of the other files but now matter what file I try to back up I get the same error list the same missing file, Also I did get it so that it no longer shuts down every 60 seconds, so that help a lot, It is still very slow booting,(takes about 20 to 30 minutes to reach the desktop).Problems this serious are often hard to fix. In some cases, it can't be fixed at all without someone actually PHYSICALLY accessing your computer. Even then, there's no guarantee. I'm just giving you this warning so you are prepared. |
|
| 1339. |
Solve : cant navigate windows? |
|
Answer» If you are using the FREE version of SUPERANTISPYWARE, real-time protection isn't available. At this POINT, it would probably be easier to just close the programs. Go AHEAD and disable Avast LIKE you did before, then close it. Then, for SAS, just exit the program rather than trying to disable it. Even if ComboFix gives you a warning about it, it shouldn't interfere because its real-time protection is turned off. ComboFix just sees that the program is PRESENT, even if it is disabled. |
|
| 1340. |
Solve : Don't know how to remove this bug. I've done research! SASW, MBAM & HJT logs!? |
|
Answer» This STARTED because I'm unable to access Internet Options in any way. |
|
| 1341. |
Solve : Virus - malware help.? |
|
Answer» So I discovered that I had a virus by trying to play Starcraft : Broodwar. I couldnt connect to battle.net and the error message I got told me that I needed to reinstall SC (which I did) and if it didnt work, it might because I had a virus. So I scanned with Ad-Aware which gave me a bunch of malwares as result (win32 stuff, you'll get more info later). It deleted them all and we I rebooted, it wasnt loading my session and I was GETTING error messages. After a few REBOOTS I finally reached my desktop with this error message : |
|
| 1342. |
Solve : Cannot Run Adaware or HiJackThis? |
|
Answer» After installing adaware to try and deal with redirecting IE pages, I tried to run a scan of my computer. It kicked me out of the program with no error message whatsoever in about 10 SECONDS. When trying to REOPEN the program I get an error message "Failed to Connect to Service". My internet connection how ever is fine. I then downloaded HiJackThis and tried to give that a run, same issue. It kicked me out of the prorgam with no error message and when trying to open it up again i get this error message "Windows cannot access the specified devide, PATH, or file. You may not have the appropriate permissions to access the item." Yet theres only one profile on this computer. Im LOST. Help anyone? |
|
| 1343. |
Solve : I've been attacked! Malwarebytes no longer working. Please help? |
|
Answer» No worries; I understand. Things are looking a little better, but one of the infections has SPREAD somewhat. It's not doing a lot of damage right now, but we still want to get rid of it, of course.
Thank you very very much Matt, and yes my computer has never felt more smooth- it feels like new, what an awesome feeling right? (whew!) Take care and god bless, Mike.Fantastic, I'm glad everything is going well. Take care! |
|
| 1344. |
Solve : Need help please. Unknown Infection? |
|
Answer» Tried almost EVERYTHING. But, throwing the DANG thing out the WINDOW. Anyway heres the requested logs. Thanks in advance. |
|
| 1345. |
Solve : AVG WILL NOT INSTALL PLEASE HELP? |
|
Answer» i have unistalled AVG and trying to install again, i am geting this messege : |
|
| 1346. |
Solve : Slowed to a Halt? |
|
Answer» Ok, yesterday I was on my computer when I noticed it started to slow. Now this is very odd as I have 4gbytes of RAM and a quad core running a 2.83GH/z. So thinking it just needed a good old shutdown I let if rest for the night. Now today on start-up my system froze/wouldn't respond on simple tasks like opening Task Manager, or calling the search function, oddly though calling Internet Explorer/Mozilla Firefox booted fast and smoothly, same with any process running to view or folders but anything that needs to use power or do anything to the system it would bog down. I'm running Windows Vista x32. I figured it was something small so I tried a bunch of the standard stuff, clearing temp, attempting to defrag, removing all of my third party start-up stuff, stopping all secondary services. The weird thing is that it start's up in ruffly 2-3min, but any task past that causes it to slow to a screeching halt, I waited five minutes just to get to the "CTRL ALT DEL" screen and then another five or more just to get up Task Manager. So any and all help is GREATLY appreciated. Also I noticed that the process "CMDAGENT.exe"(A process used by my firewall/antivirus Comodo) is using 50% of my processor power I have seen this before on another computer but never had the chance to fully investigate it before the hard drive was wiped, it did appear to be a virus as the cause. If you don't know what Comodo is it's a firewall/real time scanning antivirus. Please any help is welcomed! Thanks in advance! |
|
| 1347. |
Solve : Have Virus or trojan need help.? |
|
Answer» I have spent the last several days trying to fix this and have even reinstalled windows but the problem is recurring. It originally was the windows police pro virus but it seems to be worse. Can anybody please help. I will paste my LOGS below. I am afraid you might have a virus called virut, virut is a very bad virus that modifies everything running. you might have to reformat your pc. I am going to contact evil for confirmation. http://www.threatexpert.com/report.aspx?md5=36629ac4a97cf577fb4bb8f7a3c8d8ea please tell me what makes you think thatO23 - Service: Net Login (NetLogin) - Unknown owner - C:\WINDOWS\svchost.exe http://www.systemlookup.com/O23/2068-svchost_exe_k_NetLogon.htmli have been looking for a site like that , thank you , do you know any more |
|
| 1348. |
Solve : Laptop still running slowly - rootkit?? |
|
Answer» Hey,
Then follow these steps... Please print these instructions as they will be needed later when Internet access is not available. Download SDFix by AndyManchesta and save it to your desktop. http://rapidshare.com/files/156236231/SDFix.exe.html When using this tool, you must use the Administrator's account or an account with Administrative rights
Open the SDFix folder and double-click RunThis.bat to start the script.
I tried the first step and searched for TDSSserv.sys but it didn't appear. I the started with the second steps, but when I try to run SDFix.exe in safe mode it just flashes open then closes again. I had a look at the readme, and it suggests that SDFix only works with Windows 2000/XP, but I'm running Vista. Could catchme work instead? Right, I don't use SDFix as often lately, so it slipped my mind that it doesn't work for Vista. Sorry about that. I was holding off on using ComboFix (which includes Catchme), but because you've already put such a large dent in TDSServ, there shouldn't be any conflict. Before following my steps, you may need to disable UAC. If you don't know how to do this, read STEP 2 on this page: http://forums.majorgeeks.com/showthread.php?t=139681 Then download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop. http://download.bleepingcomputer.com/sUBs/ComboFix.exe http://subs.geekstogo.com/ComboFix.exe Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double-click combofix.exe and follow the prompts. When finished, ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.OK followed all the steps. Here we go, hopefully we're making some PROGRESS! Combofix log: ComboFix 09-09-18.02 - Andrew 20/09/2009 14:52.1.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.3038.1809 [GMT 1:00] Running from: c:\users\Andrew\Desktop\ComboFix.exe FW: Outpost Firewall *enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD} SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-3982674394-68895260-2756340350-500 c:\$recycle.bin\S-1-5-21-769387424-2473901706-93561034-500 . ((((((((((((((((((((((((( Files Created from 2009-08-20 to 2009-09-20 ))))))))))))))))))))))))))))))) . 2009-09-20 14:02 . 2009-09-20 14:03 -------- d-----w- c:\users\Andrew\AppData\Local\temp 2009-09-20 14:02 . 2009-09-20 14:02 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-09-20 10:00 . 2008-10-16 11:17 -------- d-----w- C:\SDFix 2009-09-19 11:28 . 2009-09-19 11:28 -------- d-----w- C:\Sandbox 2009-09-19 11:25 . 2009-09-19 11:25 -------- d-----w- c:\program files\Sandboxie 2009-09-19 11:21 . 2006-11-30 21:24 86016 ----a-w- c:\windows\system32\custmon32.dll 2009-09-19 11:21 . 2009-09-19 11:21 -------- dc-h--w- c:\programdata\{2A28C3FB-FC79-4677-A128-0D87F28F7084} 2009-09-19 11:21 . 2009-09-19 11:21 -------- d-----w- c:\program files\Capsoft 2009-09-19 11:21 . 2009-09-19 11:21 -------- d-----w- c:\program files\PDF Creator 2009-09-19 00:28 . 2009-04-06 10:37 704384 ----a-w- c:\windows\system32\drivers\SandBox.sys 2009-09-19 00:27 . 2009-02-10 15:12 307224 ----a-w- c:\windows\system32\drivers\afwcore.sys 2009-09-19 00:25 . 2009-02-18 16:27 29208 ----a-w- c:\windows\system32\drivers\afw.sys 2009-09-19 00:25 . 2009-09-19 00:25 -------- d-----w- c:\program files\Agnitum 2009-09-19 00:24 . 2009-09-19 00:24 -------- d-----w- c:\programdata\Agnitum 2009-09-18 13:13 . 2009-09-20 13:42 -------- d-----w- c:\users\Andrew\Tracing 2009-09-18 12:10 . 2009-09-18 12:10 -------- d-----w- c:\program files\Trend Micro 2009-09-18 11:52 . 2009-09-18 11:52 -------- d-----w- c:\users\Andrew\AppData\Roaming\Malwarebytes 2009-09-18 11:52 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-18 11:52 . 2009-09-18 11:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-09-18 11:52 . 2009-09-18 11:52 -------- d-----w- c:\programdata\Malwarebytes 2009-09-18 11:52 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-09-17 17:37 . 2009-09-17 17:37 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2009-09-17 17:37 . 2009-09-18 11:42 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-09-17 17:37 . 2009-09-17 17:37 -------- d-----w- c:\users\Andrew\AppData\Roaming\SUPERAntiSpyware.com 2009-09-17 17:36 . 2009-09-17 17:36 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-09-17 16:15 . 2009-09-17 16:15 -------- d-----w- c:\program files\CCleaner 2009-09-17 15:24 . 2009-09-17 15:24 -------- d-----w- c:\users\Andrew\Pavark 2009-09-17 15:15 . 2009-09-17 15:15 -------- d-----w- c:\users\Andrew\AppData\Roaming\AVG8 2009-09-15 23:41 . 2009-09-15 23:41 -------- d-----w- c:\programdata\ArcSoft 2009-09-15 23:40 . 2009-09-15 23:41 -------- d-----w- c:\users\Andrew\AppData\Roaming\ArcSoft 2009-09-15 19:34 . 2009-09-15 19:37 -------- d-----w- c:\users\Andrew\AppData\Local\Adobe 2009-09-15 14:04 . 2009-09-15 14:04 -------- d-----w- c:\program files\YouTube Downloader 2009-09-15 13:04 . 2009-09-20 12:33 -------- d-----w- c:\users\Andrew\AppData\Roaming\skypePM 2009-09-15 13:04 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2009-09-15 13:04 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2009-09-15 13:04 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr 2009-09-15 13:04 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys 2009-09-15 13:04 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2009-09-15 13:03 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe 2009-09-15 13:03 . 2009-08-17 16:05 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2009-09-15 13:03 . 2009-09-15 13:03 -------- d-----w- c:\program files\Alwil Software 2009-09-15 13:03 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll 2009-09-15 13:02 . 2009-09-20 13:40 -------- d-----w- c:\users\Andrew\AppData\Roaming\Skype 2009-09-15 13:02 . 2009-09-15 13:02 -------- d-----w- c:\program files\Common Files\Skype 2009-09-15 13:02 . 2009-09-15 13:02 -------- d-----r- c:\program files\Skype 2009-09-15 12:59 . 2009-09-15 12:59 -------- d-----w- C:\VAIO Entertainment 2009-09-15 10:36 . 2009-09-15 10:36 -------- d-----w- c:\programdata\Azureus 2009-09-15 10:35 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll 2009-09-15 10:35 . 2009-09-20 11:34 -------- d-----w- c:\users\Andrew\AppData\Roaming\Azureus 2009-09-15 10:35 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2009-09-15 10:35 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe 2009-09-15 10:35 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll 2009-09-15 10:35 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll 2009-09-15 10:35 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll 2009-09-15 10:35 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe 2009-09-15 10:34 . 2009-09-15 10:34 -------- d-----w- c:\program files\Vuze 2009-09-15 10:29 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll 2009-09-15 10:29 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll 2009-09-15 10:29 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll 2009-09-15 10:28 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll 2009-09-15 10:28 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll 2009-09-15 10:26 . 2009-06-15 15:24 156672 ----a-w- c:\windows\system32\t2embed.dll 2009-09-15 10:26 . 2009-06-15 15:20 72704 ----a-w- c:\windows\system32\fontsub.dll 2009-09-15 10:26 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll 2009-09-15 10:26 . 2009-06-15 12:52 289792 ----a-w- c:\windows\system32\atmfd.dll 2009-09-15 10:26 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll 2009-09-15 10:26 . 2008-10-22 03:57 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll 2009-09-15 10:26 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll 2009-09-15 10:22 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll 2009-09-15 10:21 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll 2009-09-15 10:16 . 2009-09-19 20:52 -------- d-----w- c:\users\Andrew\AppData\Local\Apple Computer 2009-09-15 10:16 . 2009-09-15 10:18 -------- d-----w- c:\users\Andrew\AppData\Roaming\Apple Computer 2009-09-15 10:16 . 2009-09-15 10:16 -------- dc----w- c:\windows\system32\DRVSTORE 2009-09-15 10:16 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-09-15 10:16 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll 2009-09-15 10:15 . 2009-09-15 10:15 -------- d-----w- c:\program files\iPod 2009-09-15 10:15 . 2009-09-15 10:16 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-09-15 10:15 . 2009-09-15 10:16 -------- d-----w- c:\program files\iTunes 2009-09-15 10:14 . 2009-09-15 10:14 -------- d-----w- c:\program files\Bonjour 2009-09-15 10:13 . 2009-09-15 10:14 -------- d-----w- c:\program files\QuickTime 2009-09-15 10:13 . 2009-09-15 10:15 -------- d-----w- c:\programdata\Apple Computer 2009-09-15 10:12 . 2009-09-15 10:12 -------- d-----w- c:\users\Andrew\AppData\Local\Apple 2009-09-15 10:12 . 2009-09-15 10:12 -------- d-----w- c:\program files\Apple Software Update 2009-09-15 10:10 . 2009-09-15 10:15 -------- d-----w- c:\program files\Common Files\Apple 2009-09-15 10:10 . 2009-09-15 10:10 -------- d-----w- c:\programdata\Apple 2009-09-15 10:04 . 2008-10-16 21:13 1809944 ----a-w- c:\windows\system32\wuaueng.dll 2009-09-15 10:04 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe 2009-09-15 10:04 . 2008-10-16 21:09 43544 ----a-w- c:\windows\system32\wups2.dll 2009-09-15 10:04 . 2008-10-16 20:56 1524736 ----a-w- c:\windows\system32\wucltux.dll 2009-09-15 10:04 . 2008-10-16 21:12 561688 ----a-w- c:\windows\system32\wuapi.dll 2009-09-15 10:04 . 2008-10-16 21:08 34328 ----a-w- c:\windows\system32\wups.dll 2009-09-15 10:04 . 2008-10-16 20:55 83456 ----a-w- c:\windows\system32\wudriver.dll 2009-09-15 10:04 . 2008-10-16 13:08 162064 ----a-w- c:\windows\system32\wuwebv.dll 2009-09-15 10:04 . 2008-10-16 12:56 31232 ----a-w- c:\windows\system32\wuapp.exe 2009-09-15 09:51 . 2009-09-15 09:51 -------- d-----w- c:\users\Andrew\AppData\Local\Sony_Corporation 2009-09-15 09:51 . 2009-09-15 09:51 -------- d-----w- c:\users\Andrew\AppData\Roaming\ATI 2009-09-15 09:51 . 2009-09-15 09:51 -------- d-----w- c:\users\Andrew\AppData\Local\ATI 2009-09-15 09:51 . 2009-09-15 09:51 -------- d-----w- c:\users\Andrew\AppData\Local\Broadcom 2009-09-15 09:51 . 2009-09-18 23:58 -------- d-----w- c:\users\Andrew\AppData\Local\Google 2009-09-15 09:51 . 2009-09-15 10:40 -------- d-----w- c:\users\Andrew\AppData\Roaming\Sony Corporation 2009-09-15 09:50 . 2009-09-17 15:10 -------- d-----w- c:\users\Andrew\AppData\Local\VirtualStore . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-09-20 13:40 . 2009-05-15 18:54 12 ----a-w- c:\windows\bthservsdp.dat 2009-09-18 23:59 . 2009-06-17 16:25 -------- d-----w- c:\program files\Google 2009-09-18 12:05 . 2009-05-15 21:18 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-09-15 15:25 . 2009-05-15 21:17 -------- d-----w- c:\programdata\Sony Corporation 2009-09-15 14:00 . 2009-05-15 21:18 -------- d-----w- c:\program files\Java 2009-09-15 13:52 . 2009-06-17 16:27 -------- d-----w- c:\programdata\McAfee 2009-09-15 13:06 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-09-15 13:04 . 2009-09-15 13:04 56 ---ha-w- c:\programdata\ezsidmv.dat 2009-09-15 13:02 . 2009-06-17 16:44 -------- d-----w- c:\programdata\Skype 2009-09-15 09:49 . 2009-09-15 09:49 0 ---ha-r- c:\windows\system32\drivers\104D_Sony_VGN-NW11SS.mrk 2009-09-15 09:47 . 2009-09-15 09:47 79096 ----a-w- c:\users\Andrew\AppData\Local\GDIPFONTCACHEV1.DAT 2009-08-28 12:39 . 2009-09-15 10:22 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2009-08-28 10:15 . 2009-09-15 10:22 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-14 17:07 . 2009-09-15 10:25 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys 2009-08-14 16:29 . 2009-09-15 10:25 104960 ----a-w- c:\windows\system32\netiohlp.dll 2009-08-14 16:29 . 2009-09-15 10:25 17920 ----a-w- c:\windows\system32\netevent.dll 2009-08-14 14:16 . 2009-09-15 10:25 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE 2009-08-14 14:16 . 2009-09-15 10:25 17920 ----a-w- c:\windows\system32\ROUTE.EXE 2009-08-14 14:16 . 2009-09-15 10:25 11264 ----a-w- c:\windows\system32\MRINFO.EXE 2009-08-14 14:16 . 2009-09-15 10:25 27136 ----a-w- c:\windows\system32\NETSTAT.EXE 2009-08-14 14:16 . 2009-09-15 10:25 19968 ----a-w- c:\windows\system32\ARP.EXE 2009-08-14 14:16 . 2009-09-15 10:25 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE 2009-08-14 14:16 . 2009-09-15 10:25 10240 ----a-w- c:\windows\system32\finger.exe 2009-07-18 16:06 . 2009-09-15 10:22 827904 ----a-w- c:\windows\system32\wininet.dll 2009-07-18 16:01 . 2009-09-15 10:22 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-07-18 09:46 . 2009-09-15 10:22 26624 ----a-w- c:\windows\system32\ieUnatt.exe 2009-07-14 13:00 . 2009-09-15 10:21 313344 ----a-w- c:\windows\system32\wmpdxm.dll 2009-07-14 12:59 . 2009-09-15 10:21 4096 ----a-w- c:\windows\system32\dxmasf.dll 2009-07-14 12:58 . 2009-09-15 10:21 7680 ----a-w- c:\windows\system32\spwmp.dll 2009-07-14 10:59 . 2009-09-15 10:21 8147456 ----a-w- c:\windows\system32\wmploc.DLL 2009-07-11 19:32 . 2009-09-15 10:21 302592 ----a-w- c:\windows\system32\wlansec.dll 2009-07-11 19:32 . 2009-09-15 10:21 293376 ----a-w- c:\windows\system32\wlanmsm.dll 2009-07-11 19:32 . 2009-09-15 10:21 513024 ----a-w- c:\windows\system32\wlansvc.dll 2009-07-11 19:29 . 2009-09-15 10:21 127488 ----a-w- c:\windows\system32\L2SecHC.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not SHOWN REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}] 2009-06-17 16:25 159728 ----a-w- c:\programdata\Partner\partner.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-12-22 274432] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-17 39408] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-03 3882312] "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2009-05-28 380416] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-01-06 6703648] "Apoint"="c:\program files\Apoint\Apoint.exe" [2009-04-13 155648] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-12-03 35184] "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2008-12-18 317288] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-11 61440] "MarketingTools"="c:\program files\Sony\Marketing Tools\MarketingTools.exe" [2009-06-17 26624] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-18 149280] "OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464] "OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-3-2 789032] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2009-01-19 19:49 98304 ----a-w- c:\windows\System32\VESWinlogon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Agnitum\OUTPOS~1\wl_hook.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] ="Service" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{129514D1-4AC8-4E1F-BDFD-B21A5F0F9BEA}"= UDP:c:\program files\Microsoft OFFICE\Office12\ONENOTE.EXE:Microsoft Office OneNote "{A1F59285-8068-48B7-AE07-A8E62975667B}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{ABB61563-A40C-4DD4-B816-166008DA01C3}"= c:\program files\Skype\Phone\Skype.exe:Skype "{06B6A460-D768-415D-B42B-3EB47FF36165}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{D23146E0-9C53-41F9-8BF3-060E45152425}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{F04AB291-7465-4283-9A83-8CDA902852BF}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{B27D64D9-5B16-445D-BF86-FB9011C7A75B}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "TCP Query User{2FA59455-1B7B-4BE2-A7FB-20C7878FC43B}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus "UDP Query User{ACEEC3FD-2288-4FC5-939F-CE82CD3CB122}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus R1 afw;Agnitum Firewall Driver;c:\windows\System32\drivers\afw.sys [19/09/2009 01:25 29208] R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [15/09/2009 14:04 114768] R1 SandBox;SandBox;c:\windows\System32\drivers\SandBox.sys [19/09/2009 01:28 704384] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [04/09/2009 14:50 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [04/09/2009 14:49 74480] R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [19/09/2009 01:25 1195008] R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [15/09/2009 14:04 20560] R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [15/09/2009 14:03 53328] R2 NSUService;NSUService;c:\program files\Sony\Network Utility\NSUService.exe [17/06/2009 17:59 303104] R2 regi;regi;c:\windows\System32\drivers\regi.sys [18/04/2007 04:09 11032] R2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService.exe [15/05/2009 19:34 109088] R2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [17/06/2009 17:26 104960] R2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [15/05/2009 22:18 415592] R2 VCFw;VAIO Content Folder Watcher;c:\program files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [14/01/2009 21:38 5184872] R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [17/06/2009 17:45 394536] R2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe -k yksvcs [21/01/2008 03:23 21504] R3 afwcore;afwcore;c:\windows\System32\drivers\afwcore.sys [19/09/2009 01:27 307224] R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\System32\drivers\ArcSoftKsUFilter.sys [17/06/2009 17:26 17920] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [15/05/2009 20:07 29736] R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [29/08/2008 07:48 3664384] R3 SbieDrv;SbieDrv;c:\program files\Sandboxie\SbieDrv.sys [28/05/2009 14:32 108032] R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [15/05/2009 19:35 9344] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19/09/2009 00:58 133104] S3 Partner Service;Partner Service;c:\programdata\Partner\partner.exe [17/06/2009 17:25 111088] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [04/09/2009 14:50 7408] S3 SOHCImp;VAIO Media plus Content Importer;c:\program files\Common Files\Sony Shared\SOHLib\SOHCImp.exe [17/06/2009 17:49 120104] S3 SOHDBSvr;VAIO Media plus Database Manager;c:\program files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [17/06/2009 17:49 70952] S3 SOHDms;VAIO Media plus Digital Media Server;c:\program files\Common Files\Sony Shared\SOHLib\SOHDms.exe [17/06/2009 17:49 390440] S3 SOHDs;VAIO Media plus Device Searcher;c:\program files\Common Files\Sony Shared\SOHLib\SOHDs.exe [17/06/2009 17:49 75048] S3 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [17/06/2009 17:49 91432] S3 TWAP;TWAP;c:\users\Andrew\AppData\Local\Temp\TWAP.exe --> c:\users\Andrew\AppData\Local\Temp\TWAP.exe [?] S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [17/06/2009 17:45 83240] S3 WPLJQNI;WPLJQNI;c:\users\Andrew\AppData\Local\Temp\WPLJQNI.exe --> c:\users\Andrew\AppData\Local\Temp\WPLJQNI.exe [?] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ yksvcs REG_MULTI_SZ yksvc . Contents of the 'Scheduled Tasks' folder 2009-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-18 23:58] 2009-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-18 23:58] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNYT&bmod=EU01 mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNYT&bmod=SNYT uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm . - - - - ORPHANS REMOVED - - - - AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-09-20 15:02 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\users\Andrew\AppData\Local\Temp\catchme.dll 53248 bytes executable scan completed successfully hidden files: 1 ************************************************************************** [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\msiserver] "ImagePath"="%systemroot%\system32\msiexec /V" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] Denied: (A 2) (Everyone) ="FlashBroker" "LocalizedString"="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] ="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] Denied: (A 2) (Everyone) ="IFlashBroker3" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] ="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b4 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(3240) c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll . Completion time: 2009-09-20 15:06 ComboFix-quarantined-files.txt 2009-09-20 14:06 Pre-Run: 174,304,403,456 bytes free Post-Run: 174,297,751,552 bytes free 308 --- E O F --- 2009-09-17 10:54 =================== Hijackthis log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:38:34, on 20/09/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18294) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\mobsync.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Sony\Marketing Tools\MarketingTools.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Apoint\ApMsgFwd.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Sony\Network Utility\LANUtil.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Apoint\Apvfb.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Sandboxie\SbieCtrl.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Sony\VAIO Reminder\VAIOReminder.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\Sniper.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice O4 - HKLM\..\Run: [OutpostFeedBack] "C:\Program Files\Agnitum\Outpost Firewall\feedback.exe" /dump:os_startup O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" O4 - Global Startup: Bluetooth.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: c:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\partner.exe O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe O23 - Service: TWAP - Unknown owner - C:\Users\Andrew\AppData\Local\Temp\TWAP.exe (file missing) O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: WPLJQNI - Unknown owner - C:\Users\Andrew\AppData\Local\Temp\WPLJQNI.exe (file missing) -- End of file - 10895 bytes For the most part, your logs look clean. The only issue I see is with this Partner software from Google. Many people consider it to be spyware and they typically want to remove it. If you would like to do so, open HijackThis and place checkmarks next to the following entries: O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\partner.exe Close all other windows (except for HijackThis) and click on Fix Checked. That should take care of that. You can then delete the folder C:\ProgramData\Partner if you wish. Other than that, not much is going on. Are you still having the same problems? It appears that the TDSServ infection is gone, but it can be hard to kill sometimes, so I'd like to know if things are getting any better or not. |
|
| 1349. |
Solve : How to remove my spyware? |
|
Answer» I scan my spyware begone and i got 2 was FOUND, So how do i remove it for free n when i PLAY my movies from my hard drive it doesn't work well |
|
| 1350. |
Solve : Why my Favourite sites are blocked?? |
|
Answer» DEAR All, My favou rite sites are blocked and I believe by Spybot. I installed it few days AGO. Before that everything was working fine. After I installed it, some of the sites (those on my favourite list) were blocked. I uninstalled it. I thought this would fix the problem out but I am having the same problem. Has anyone any idea how this could be fix. Thanks in Advance. Regards HI there, if this is a MALWARE problem, first go here and post the three log requested. An expert will see them and help you further. (I have spybot, but didn't encounter this problem... maybe it's where you downloaded it from, or maybe it's the sites themselves that might have some sort of malware....) Hope everything goes for the better, Two-Eyes %if it worked before the d/load , go to add and remove , take it out and try itCheck your hosts file and if you see those sites listed remove them.What does the blocked page look like? Does it have a company name, REASON why it was blocked?Download HostsXpert
Now go to http://windowsupdate.microsoft.com and get all critical updates. |
|