Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2451.

Solve : avg 8.0 help?

Answer»

when i run avg it comes back nothing found , but with 135 warnings , i have tried to get into avg to find out what they are but i can't get in to it135 warnings. Most likely that's just TRACKING cookies are ad related stuff that are just low threat to your SYSTEM.

I would .... Clean your system with your ccleaner (remove cookies option enabled) and retry AVG scan BUT removing cookies may remove saved website settings so have ccleaner save all cookies you want to keep.

ok , but you cannot get into avg8.0 the way you could with 7.5 and it is very slowYou can configure AVG 8.0 from Tools -> Advanced.

thank you is there no way to make it faster or should i ask that on the avg forumSlow?

What are your computer specs?
(RAM, Processor Speed, Free Hard Drive Space, Hard Drive Capacity, Operating System)Quote from: harry 48 on December 20, 2008, 11:18:08 AM

thank you is there no way to make it faster or should i ask that on the avg forum

You can set scanning to 'slow', 'automatic' (Recommended) and 'fast'

If you set it to fast, you won't be able to do much else on your computer. processor speed , x86 family 15 MODEL 3 stepping 3 genuine , 2412 mhz
windows XP home
total physical memory 1,280.00 mb
avaiable "" "" 852.32 mb
total virtual memory 2.oo gb
avaiable "" "" 1.96 gb
page file space 1.41 gb

i have a feeling this is wrong above

there is a file below as well Quote from: Carbon Dudeoxide on December 20, 2008, 07:58:40 PM
Slow?

What are your computer specs?
(RAM, Processor Speed, Free Hard Drive Space, Hard Drive Capacity, Operating System)
Well, a virus scanner demands a lot of hard drive access so your system will slow down. Only the slow-, automatic- and fast slider will allow you to either slow things or down or speed htem up. have a look at this file it might give you more imforationQuote from: Carbon Dudeoxide on December 20, 2008, 07:58:40 PM
Slow?

What are your computer specs?
(RAM, Processor Speed, Free Hard Drive Space, Hard Drive Capacity, Operating System)

[attachment deleted by admin]Sorry, I'm not exactly sure what you're asking of us anymore.. carbon asked for my pc specs this is all i can find

i am going to leave avg speed as it is as your said the faster it GOES it will slow the work on the pc downYeah, I'd just leave it at 'automatic'. I think it keeps track of what you're doing and tries to adjust to that.

ok thank you
2452.

Solve : start up to windows message occurred...?

Answer» EVERYTIME i open my computer when starts window a message was display...
Message:
Windows Script Host
Can not find script file "C:\WINDOWS\auto.vbs".

said of my friend it is a VIRUS, a new virus, that only AVG can detect that kind of virus...
OS: Windows XP Professional
PROCESSOR: INTEL R pentium R dual CPU E2140 @ 1.60 GHz
MEMORY: 1024 RAM


2453.

Solve : Can't get access to programs?

Answer»
I get this when I try to open GIMP, bittorrent, or foobar. I have full admin access. What can I do? Can't read that. Can you type it out please?

Also do you think this is a malware issue?Not sure what it is. I just reinstalled windows today.

It GIVES me that when I try to open Foobar, gimp or avg too. Read this carefully and rename the tool before running it.

Download Deckard's Association File Tool (DAFT) and save it to your desktop.
  • Rename daft.exe to daft.com and double click on it to run.
  • Read the disclaimer and click OK.
  • Click on the Scan button.
  • If it finds faulty file associations, they will appear in red beside a checkbox. If this occurs, just place a checkmark (tick) in the boxes in question.
  • Click the Fix button.
.

How is everything now?It says everthing is ok. Is this a LEGAL copy of Windows?.......NOTHERE isn't much we can do then. Helping you get an illegal copy of Windows to work would make this web site liable. Thank you for your honesty though.

Note that Microsoft has recently started taking new measures that is making it HARDER and harder for an unregistered copy of Windows to run. Your best bet is to contact MS and get is registered. Then you won't have to worry about things like this happening. Go to the link for more information. http://www.microsoft.com/genuine/downloads/Validate.aspxIt says that it is validate? It's there any way I can delete the PROGRAMS using a program? Then reinstall But you know it isn't actually valid.

Please do the following:

1. Download this diagnostics tool MGADiag.exe and save this to your Desktop.
2. Double-click on MGADiag.exe and click Continue
3. When the program has finished, click on Copy
4. Post the results in your next reply.Diagnostic Report (1.7.0110.1):
-----------------------------------------
WGA Data-->
Validation Status: Validation Control not Installed
Validation Code: 0
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-3R89F-D2KXW-VPK3J
Windows Product Key Hash: Ro/Y7HENE9CfW7lW+QtlNbYQEE8=
Windows Product ID: 55274-640-8365391-23693
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.2.0.pro
ID: {BFBC335D-5C6B-40DA-B9B4-2B2771B3B85E}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1
Resolution Status: N/A

WgaER Data-->
ThreatID(s): N/A
Version: N/A

WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-648-80070002_025D1FF3-171-1_FA827CE6-153-8007007e_FA827CE6-180-8007007e

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\PROGRA~1\MOZILL~1\FIREFOX.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: {BFBC335D-5C6B-40DA-B9B4-2B2771B3B85E}1.7.0110.15.1.2600.2.00010100.2.0.prox32*****-*****-*****-*****-VPK3J55274-640-8365391-236931S-1-5-21-583907252-1202660629-682003330HP Pavilion 061DM181A-ABA a305w 3.21 20030716000000.000000+000116D3C3F0184207204090409Pacific Standard Time(GMT-08:00)03 109

Licensing Data-->
N/A

HWID Data-->
N/A

OEM Activation 1.0 Data-->
BIOS string matches: yes
Marker string from BIOS: 12E2B:Hewlett-Packard Company|C191:HITACHI, Ltd|C191:HITACHI, Ltd|C191:HITACHI, Ltd|40A0:TriGem Computer Inc
Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005

OEM Activation 2.0 Data-->
N/A

Quote
Validation Status: Validation Control not Installed

It's not legal. Get a legal copy and install that. Problem solved.
2454.

Solve : CARNIVOR?

Answer»

Here is a possibility to FIGHT Carnivor or DCS-1000, Echelon, or what ever they called this thing. The spyware is reaching your computer on its own frequency, different from dial-up, DSL or cable. It could be filtered out by relatively simple electronic devices, but the Big Brothers do not allow selling these filters, so you have to make them for your self. The simplest one is just a capacitor 0.01-0.03 uF range, like this in RadioShack store: 0.01µF 500V 20% Hi-Q Ceramic Disc Capacitor Pk/2 Model: 272-131 | Catalog #: 272-131.

Connect red and green wires in your phone socket with this capacitor. Your computer also can be reached through the AC power line by one of dear neighbor terminal operators, so protect your power divider. Open its cover and use three of these capacitors to connect plus and minus, minus and ground, plus and ground pairs of wires in the AC divider. Disconnect from the PC any radio frequency devices, like Wi-Fi adaptor, Wireless router, cordless phone,etc.

Now the spyware will have a substantial interference in getting you information. Nothing will happen first, but after a while your Internet will going slow, sometimes very slow. This thing is going to use your Internet channel to intercept your activities. And it needs a lot of traffic, much more than the target computer uses for itself.

Verizon on-line traffic analyzer used to show that my ”traffic is used by unknown application.” When I started to ask questions to tech support on slowing my Internet, they SIMPLY removed this option from their speed report. They blamed wires, my WLAN card, my software and possible virus infections. They played a fool. I have spent many hours talking to my ISP tech support. But I have saved the speed reports for one year and I can go to the court. They have a right to spy on me, but I am STILL not obligated to pay for this from my pocket.



This sounds a bit more like a RANT rather than anything else. "Policeware" is nothing new (thank the Clinton administration) and the average joe has nothing to fear of it. Unless you are breaking the law, but then why would you log your criminal activities by using your PC?

http://en.wikipedia.org/wiki/Carnivore_(software)Echelon cannot be stopped...
Even by tin-foil hats.

Quote from: patio on December 20, 2008, 07:43:05 PM

Echelon cannot be stopped...

LMAO. A new twist to the plot. Nice article!! I can't help but wonder if this is somehow related to the grain conspiracy...Shhhhhhhh.........Of course you can stop it. If you prove yourself worthy, I'll let you join the revolution.

Oh, bring kool-aid.
2455.

Solve : Hijack this logfile help please.?

Answer»

I have a logfile here.
My laptop is slow and freezing up atm and I can't scan in safe mode.
this did WORK though.
Is there anything wrong here?

Quote

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:42:23, on 22-12-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\acer\epm\epm-dm.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\WINDOWS\system32\CmWatch.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lunabar\Lunabar.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.evolution-events.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [CmCardRun] C:\WINDOWS\system32\CmWatch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FFTI] C:\Documents and Settings\Ko\Application Data\Mozilla\Firefox\Profiles\1gd2j3ym.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FFTI] C:\Documents and Settings\Ko\Application Data\Mozilla\Firefox\Profiles\1gd2j3ym.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - Startup: Lunabar Taskbar Icon.lnk = C:\Program Files\Lunabar\Lunabar.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JAVA\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation TOOL) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 6758 bytes
2456.

Solve : Trojan help - please?

Answer»

Hi - I have followed some of the threads on here and I think I have the same Trojan virus that others have suffered with over the last couple of days.

I have learnt from some of the other threads re: scanning and logging the results. I will attach these below, from Malware & HijackThis.

If someone could tell me what to do now, I'd be extremely grateful!

Logs:

Malware:

Malwarebytes' Anti-Malware 1.31
Database version: 1524
Windows 5.1.2600 Service Pack 3

20/12/2008 05:38:08
mbam-log-2008-12-20 (05-38-08).txt

Scan type: Full Scan (C:\|F:\|)
Objects scanned: 120174
Time elapsed: 36 minute(s), 45 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 1
Registry Keys Infected: 26
Registry Values Infected: 8
Registry Data Items Infected: 1
Folders Infected: 6
Files Infected: 38

Memory Processes Infected:
C:\Documents and Settings\Adam Turner\Application Data\gadcom\gadcom.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\services.exe (Backdoor.ProRat) -> Unloaded process successfully.

Memory Modules Infected:
C:\WINDOWS\system32\tyshb36rfjdf.dll (Trojan.Fakealert) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\{5222008a-dd62-49c7-a735-7bd18ecc7350} (Rogue.VirusRemover) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\{5222008a-dd62-49c7-a735-7bd18ecc7350} (Rogue.VirusRemover) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\virusremover2008 (Rogue.VirusRemove) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\virusremover2008 (Rogue.VirusRemove) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\antiviruspro2009 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS TRACK System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gadcom (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus PRO 2009 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\Adam Turner\Application Data\gadcom (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\data (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\Mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Start Menu\Programs\AntivirusPro2009 (Rogue.AntivirusPro2009) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\tyshb36rfjdf.dll (Trojan.Zlob.H) -> Delete on reboot.
C:\WINDOWS\services.exe (Trojan.FakeAlert.H) -> Delete on reboot.
C:\Documents and Settings\Adam Turner\Application Data\gadcom\gadcom.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Mjcore\Mjcore.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Local Settings\Temp\eorsaxmwnc.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Local Settings\Temp\TDSSc0ab.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Local Settings\Temp\csrssc.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\htmlayout.dll (Rogue.AntivirusPro2009) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0592F669-3B54-4F29-BEFA-0D709E958FE2}\RP735\A0446919.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0592F669-3B54-4F29-BEFA-0D709E958FE2}\RP735\A0446920.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0592F669-3B54-4F29-BEFA-0D709E958FE2}\RP735\A0446921.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0592F669-3B54-4F29-BEFA-0D709E958FE2}\RP735\A0446922.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0592F669-3B54-4F29-BEFA-0D709E958FE2}\RP735\A0446923.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\opnlMdBT.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmnljKAQ.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSarxx.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSoitt.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSvoqm.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\buewamjg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\TDSSmxst.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
F:\-- UTILS --\Winamp Pro v5.0\CORE10k.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\AntivirusPro2009.cfg (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\pthreadVC2.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\data\daily.cvd (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT\msvcm80.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT\msvcp80.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT\msvcr80.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Start Menu\Programs\AntivirusPro2009\AntivirusPro2009.lnk (Rogue.AntivirusPro2009) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Start Menu\Programs\AntivirusPro2009\Uninstall.lnk (Rogue.AntivirusPro2009) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Application Data\addon.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcBQigE.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Local Settings\Temp\wrdwn4 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Local Settings\Temp\wrdwn5 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Local Settings\Temp\wrdwn7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Adam Turner\Local Settings\Temp\TDSSc09c.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSdxcp.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSkkai.log (Trojan.TDSS) -> Quarantined and deleted successfully.

HijackThis log to follow...
HijackThis log:

Logfile of TREND Micro HijackThis v2.0.2
Scan saved at 05:41:18, on 20/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.molineuxmix.co.uk/vb/forumdisplay.php?f=2
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [jsf8j34rgfght] C:\DOCUME~1\ADAMTU~1\LOCALS~1\Temp\winloggn.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: *.beatport.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O20 - AppInit_DLLs: ifvmru.dll
O20 - Winlogon Notify: ddcCuTnN - ddcCuTnN.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\ADAMTU~1\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--

Could someone please let me know what to do now!

ThanksPlease print these instructions as they will be needed later when Internet access is not available.

Download SDFix by AndyManchesta and save it to your desktop. http://rapidshare.com/files/151585130/SDFix.exe.html

When using this tool, you must use the Administrator's account or an account with Administrative rights

  • Double click SDFix.exe and it will extract the files to %systemdrive%
  • (this is the drive that contains the Windows Directory, typically C:\SDFix).
  • DO NOT use it just yet.
.Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Copy and paste the contents of the results file Report.txt in your NEXT reply.
2457.

Solve : My computer is sick and needs CPR! Windows XP?

Answer»

Windows XP home SP2 (had SP3 but installed because of problems) on a home wireless network

Well, Its infected with spyware etc, spybot S&D and adaware couldnt remove it, I tried restarting in safe mode and manually deleting some of the files to no avail. Only get popups when I am surfing the web. The thing that got me is that I think it is preventing me from PERFORMING windows update, updating windows defender, and preventing me from TURNING the windows firewall on. It says its controlled by group policy and I havent set up a group policy. Tried to find solutions and went run/services.msc and there wasnt anything there about the group policy. Tried turning updates, firewall and security center on from services and WOULD automatically stop them after I started them.

After running the steps, I havent had a pop up.... yet, but am still not able to run windowns firewall

[attachment deleted by admin]Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop.

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this LINK to see a list of security programs that should be disabled and how to disable them.

Double-click combofix.exe and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.here are the new logs, btw thanks for ur help!

[attachment deleted by admin]Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
c:\windows\system32\g35.exe
c:\windows\system32\nigoyeje.exe
c:\windows\system32\kxrpviwu.ini
c:\windows\system32\sfhayogk.ini

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. NAME the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not click ComboFix's window while it is running. That may cause your system to freezethe newest logs

[attachment deleted by admin]Well, I don't see a firewall, which needs to be corrected. Unless you have a suite package of Avast (not just anti-virus), then you need to get a good firewall on your computer. I suggest Comodo, ZoneAlarm, or Kerio Sunbelt. Download one, disconnect from the internet, disable Windows Firewall, install your new one, and restart.

Other than that, things appear to be okay. How is everything running now? Are you still experiencing problems?Things are running much much smoother now.... thanks for you help man, and Ill get that firewall downloadedGreat, and while you're at it, go ahead and uninstall ComboFix. To this, simply go to Start > Run and type in combofix /u (note the space) and click OK.

You should also clear out your System Restore points by turning it off and then turning it back on...
http://support.microsoft.com/kb/310405

2458.

Solve : Got something, logs included...?

Answer»

I have something because I keep GETTING those stupid Antivirus popups. I have included the logs in the attachments. Thanks!!!!

[attachment deleted by admin]Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop.

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Close any open WEB browsers (Firefox, Internet EXPLORER, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a SCAN. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click combofix.exe and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's WINDOW while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.

2459.

Solve : Spyware guard 2008 keep coming up.?

Answer»

My computer got virus. (That's keep coming up with spyware guard 2008.)
I am using windows XP.

I followed to the "Topic: Read this before requesting malware removal help".

I went to add or remove program and I am not sure about these programs that I should remove or not :-

- Ad-Aware
- Apple Mobile Device Support
- Apple software update
- Bluetooth Stack for Windows by Toshiba
- Bonjour
- Capicom
- Security Update for CAPICOM (KB931906)
- CD/DVD Drive Acoustic Silencer
- DVD-RAM Drive
- High Definition Audio Driver Package - KB888111
- Hotfix for Windows Media Format 11 SDK (KB929399)
- J2SE Runtime Environment 5.0 Update 4
- Intel(R) Proset/Wireless Software
- Intel (R) PRO Network Connections Drivers
- MICROSOFT .NET Framework 1.1
- Microsoft COMPRESSION Client Pack 1.0 for Windows XP
- Microsoft Learning _ SOFT ware Updates
- Security Update for Step by Step Interactive Training (KB898458)
- Security Update for Step by Step Interactive Training (KB923723)
- Microsoft Office 2003 WEB Components
- Office 2003 Service Pack 3 (SP3) : OWC11SP3
- Microsoft Office OneNote 2003
- OneNote 2003 Service Pack 3 (SP3): ONENOTESP3
- Security Update for Office 2003 (KB921598): GPFILT
- Security Update for Office 2003 (KB953404): MSO
- Security Update for Office 2003 (KB954478): GDIPLUS
- Security Update for office 2003 (KB951535): MSXML5
- Microsoft Office Professional Edition 2003
and hole bunch of update and security update for office.
(Please tell me later if you think you have to know.)
- Microsoft SQL Server 2005 Compact Edition [ENU]
- Microsoft User-Mode Driver Framework Feature Pack 1.0
- Microsoft Visual C++ 2005 Redistributable
- NVIDIA Drivers
- Realtek High Definition Audio Driver
- SD Secure Module
- Security Update for Windows Media Player 11 (KB936782)
- Signature995
- Synaptics Pointing Device Driver
- Texas Instruments PCIxx21/x515/xx12 drivers.
- WinSCP 4.1 beta
- Windows Media Format 11 runtime.
- Windows XP - Software Updates
- hole bunch of security update and hotfix for windows Media player 11 (KB939683)


I attached all of the logs that need with this since my message exceeds the maximum allowed length (20000 characters).


Until now spyware guard 2008 stopped coming up.
I don't know it's all done or still have some virus hiding.
Please give me advise what should I do after this.
Thank you very much.

[attachment deleted by admin]

2460.

Solve : Having ctxfihlp mfc error probs might be from malware?

Answer»

I have been having a ctxfihlp mfc error popping up. Since the ctxfihlp error I have had no sound; when checking the sounds tab in the control panel, no audio device or mixer is detected even after all the drivers have been reinstalled.

I have ran antivirus with antispyware and Malwarebytes and haven't found anything.

I have enclosed my hijackthis log hoping it might help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:31:25 PM, on 1/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Documents and Settings\Joan\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Joan\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link HELPER - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
O2 - BHO: Symantec INTRUSION Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
O4 - HKLM\..\RUN: [ehTray] "C:\WINDOWS\ehome\ehtray.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [DLA] "C:\WINDOWS\System32\DLA\DLACTRLW.EXE"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] "C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" /background
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Volume Panel\VolPanlu.exe" /r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [SansaDispatch] C:\Documents and Settings\Joan\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi CLASS) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1162602577793
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

--
End of file - 10652 bytes

2461.

Solve : I would REALLY love someones help :)! (A Trojan problem)?

Answer» Reset Settings in Internet Explorer 7

Follow these steps to use the Reset Internet Explorer Settings feature from Internet Explorer 7:

1. In Internet Explorer 7, click the Tools menu, and then click Internet Options.
2. On the Advanced tab, click Reset.
3. In the Reset Internet Explorer Settings dialog box, click Reset.
4. When Internet Explorer 7 finishes restoring the default settings, click Close, and then click OK two times.
5. Close Internet Explorer 7. The changes take effect the next time that you open Internet Explorer 7.

How is it now?yep that worked! cheers! Everything else seems fine! Thanks for your help. If i have anymore problems i will come back to you!

thanks for all your hard work!Glad it worked.

A few more tips to look at.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with ADBLOCK Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from MALICIOUS software

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and MALWARE
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
2462.

Solve : Unable to view videos longer than ~1 minute on internet?

Answer»

Using the following browsers I am unable to view videos (news or YouTube, etc.) longer than 1 minute. The buffering starts and the video plays until the play mode catches up to the buffer and the program stops.

Internet Explorer 7.1.6001.1800
AOL 9.1 Rev 4334.5000
Firefox version 3.0.5

Below is my HighJackThis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:22:01 PM, on 12/23/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\aol\1225590462\ee\aolsoftware.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1225590462\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (USER 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {050A3800-6C03-48A5-A6D7-14CCF18A700D} - https://cottageconnect.sbch.org/v4ica.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL CONNECTIVITY Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
O23 - Service: SessionLauncher - Unknown owner - C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro PROXY Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

--
End of file - 9999 bytes
Sorry for the long wait. We are VERY backed-up right now! This doesn't appear to be a virus issue. Have you tried updating your Flash and Java?Yes I did and it didn't seem to help.

What I did do was to RESET the Belkin Wireless G Router and for a WEEK now the internet has been great. Thanks for reviewing and responding.

Great, I'm glad to hear it.

2463.

Solve : Trojans, Gadcom.exe SHeur2.GAS csrssc.exe - Please help?

Answer»

The only steps I could complete was running CCleaner and updating Java. All of the links provided all give me the same message "Internet Explorer cannot display" message. I tried using google to get to the sites and was redirected to a random site. I was finally able to download the programs needed by using cut and paste to arrive at the sites needed. When I try to run them for install, it says "Program has encountered an error and needs to close". So I am unable to supply the logs required in steps 3, 4, and 6.

I ran a scan using AVG before finding this site, 4 infections found...

C:..\..\application data\gadcom\gadcom.exe

Trojan Horse Downloader.Generic8.HPC

C:..\..\application data\gadcom\gadcom.exe

Trojan Horse Downloader.Generic8.HPC

C:..\..\Local Settings\Temp\csrscc.exe

Trojan Horse SHeur2.gas

HKU\S-1-5-21-4064284459-4068832260-2367868486-1006\Software\Microsoft\Windows\CurrentVersion\Run\\gadcom

Found Registry key with reference to infected file

Other things of note:

I am unable to connect to AVG update.

It disabled my Windows Firewall (which I was able ENABLE afterwards)

It disabled automatic updates from windows (which I cannot enable now)

No pictures are being shown on any websites, unless I right click -> show picture.

It says AVG is running scans on my desktop toolbar at the bottom, and it is not.

I'm not sure what other information I can provide. I noticed several other ppl posting here are having the same problem.

Please advise.

Thanks.Welcome to CH.

Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

  • Scroll down to “Non-plug and Play DRIVERS” and click the plus icon to open those drivers.
  • Then search for TDSSserv.sys
  • Let me know if you find this or not.
  • If you do find it, right click on it, and select “Disable”. Do not try to uninstall it.
  • Also if this is found and you disable it.
  • Now reboot and see if you can run the other scans that would not run.
Yes it was there, now disabled.

I am now able to get updates and run my anti-virus programs.

I was also able to get MBAM to run by renaming the exe file.

I am now running SUPERAntiSpyware.

Reports to follow soon.

Thanks and I love you.Glad it worked Here are the reports.

[attachment deleted by admin]Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
- O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\SYSTEM32\CBXQIJBA.DLL (file missing)
- O2 - BHO: C:\WINDOWS\system32\tyshb36rfjdf.dll - {D5BF49A2-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\SYSTEM32\TYSHB36RFJDF.DLL (file missing)
- O2 - BHO: (no name) - {F1D26A44-CC06-47E6-908D-B4AD07C96AA2} - C:\WINDOWS\system32\xxyaxuvv.dll (file missing)
- O4 - Startup: PowerReg Scheduler V3.exe
- O20 - AppInit_DLLs: avgrsstx.dll reniix.dll
- O20 - Winlogon Notify: cbXQiJba - cbXQiJba.dll (file missing)
- O22 - SharedTaskScheduler: FGYbf743iujndsfAfsdfd - {D5BF49A2-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\SYSTEM32\TYSHB36RFJDF.DLL (file missing)


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

Run CCleaner and then restart the computer.

----------

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.

For Windows XP SYSTEMS install the Recovery Console:

- If you are using Windows XP and do not already have the Recovery Console installed, please ensure your Internet connection is active (if possible) and click Yes.
- If for some reason your Internet is not working click No.
- If you are not using Windows XP, you will not be prompted.
- When prompted to accept the EULA click OK.
- Accept Microsoft's EULA (Click Yes).
- When you are told that the RC is installed correctly click YES to continue scanning for malware.

When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.The log is attached below.

Pictures are still not showing up unless I right click -> show. Is this of any major concern or any easy fix?

Thanks.

[attachment deleted by admin]What pictures?

Download the OTMoveIt3 by OldTimer

Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As Administrator.

* Save it to your Desktop.
* Double-click OTMoveIt3.exe to run it.
* Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

Code: [Select]:Processes
explorer.exe

:files
c:\docume~1\DEVAST~1\LOCALS~1\Temp\efipsk.sys

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

* Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
* Click the red Moveit! button.
* Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTMoveIt3

Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.Quote from: evilfantasy on December 21, 2008, 10:45:28 PM
What pictures?

Any pictures on any website, the picture for your avatar for example or the pictures for any of the little smiley faces. In place of the pictures are text, if I right click -> show picture they appear as the picture and not text. Its probably something very simple, but I just dont know what it is. It started after I got the virus.

Anyway, thanks again. Log posted below.

[attachment deleted by admin]Try this.

Internet Explorer right?

Reset Web Settings & Default Security Settings

Open Internet Explorer and choose Tools > Internet Options > then the Advanced Tab and then the Reset button under Reset Internet Explorer Settings.

Restart IE and see if it is back to normal.
PERFECT!

I am now completely free of the plague that existed on my PC.

THANK YOU!!

What a wonderful service you provide here on this site. Praise be to you and the others that help troubled people and their computers. I could not be happier at this moment. I hope everyone appreciates you as much as I. I really cant thank you enough. Its so nice to have things back to normal here.

Have a happy holiday!!
    Glad it worked. Now time to clean up and secure the work you have done. Let me know if you have any questions.

    • Click START then RUN
    • Now TYPE Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    1. Double click
OTMoveIt3.exe to launch it.
If using Vista Right-Click OTMoveIt and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
  • When finished exit out of OTMoveIt3
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable THOROUGH system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
2464.

Solve : Can only boot to safe mode?

Answer»

I'm helping a friend and his pc can only boot to safe mode. In safe mode I ran Malwarebytes and pulled out two vundo trojans and REMOVED them. Ran AVG in the command mode and nothing found but several files were locked and were not checked. Ran spybot and removed another trojan. Don't remember the name of that one. W32 something. When you ask the pc to boot normal, it tries to boot, you GET the windows XP window but goes back to the menu for safe mode. If I go to the safe mode with networking, I can get on the internet. Can't run superantispyware remover because I can't install it int the safe mode. He's running on Win XP SP3. Ran HJT. Log attached.

Not sure if I should be here or in the spyware,virus, malware forum. Should I open a thread in each forum?


[attachment deleted by admin]Moved to Malware forum

Quote from: cojack on JANUARY 05, 2009, 02:20:46 PM

Not sure if I should be here or in the spyware,virus, malware forum. Should I open a thread in each forum?
Nope, you just put it in one board : )
More than one is against the rules, a lot of people do that anyways... we just lock them. THANKS! I don't see it in the other forum. Does it take awhile to transfer there?Quote from: cojack on January 05, 2009, 04:11:04 PM
Thanks! I don't see it in the other forum. Does it take awhile to transfer there?
Stupid me : )
I forgot to move it *slaps self on HEAD*
2465.

Solve : BOOT UP from other forum?

Answer»

Ok I posted this topic under software a couple of days ago and was reruted to this forum by broni. Broni had me do somwthings and post a Hijack this log and then found out my laptop was infected.

Now I went throught the steps to REMOVE malware and have just finished with the superantispyware and here is the log, also my pc info is below. Thanks for the help in advance.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/01/2009 at 02:58 PM

Application Version : 4.24.1004

Core Rules Database Version : 3693
Trace Rules Database Version: 1669

Scan type : Custom Scan
Total Scan Time : 01:00:32

Memory items scanned : 431
Memory threats detected : 0
Registry items scanned : 6734
Registry threats detected : 34
File items scanned : 54102
File threats detected : 2

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\InprocServer32
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\InprocServer32#InprocServer32
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\InprocServer32#ThreadingModel
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\ProgID
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\Programmable
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\TypeLib
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\VersionIndependentProgID
HKCR\SearchSettings.BHO.1
HKCR\SearchSettings.BHO.1\CLSID
HKCR\SearchSettings.BHO
HKCR\SearchSettings.BHO\CLSID
HKCR\SearchSettings.BHO\CurVer
HKCR\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
HKCR\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}\1.0
HKCR\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}\1.0\0
HKCR\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}\1.0\0\win32
HKCR\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}\1.0\FLAGS
HKCR\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}\1.0\HELPDIR
C:\PROGRAM FILES\SEARCH SETTINGS\KB127\SEARCHSETTINGS.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKU\S-1-5-21-1454471165-1647877149-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKU\S-1-5-21-1454471165-1647877149-839522115-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKU\S-1-5-21-1454471165-1647877149-839522115-1003\Software\Microsoft\Internet Explorer\URLSearchHooks#{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKU\S-1-5-21-1454471165-1647877149-839522115-1006\Software\Microsoft\Internet Explorer\URLSearchHooks#{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKCR\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
HKCR\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}\ProxyStubClsid
HKCR\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}\ProxyStubClsid32
HKCR\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}\TypeLib
HKCR\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}\TypeLib#Version

Trojan.Media-Codec/V4
C:\Program Files\Video Add-on
HKU\S-1-5-21-1454471165-1647877149-839522115-1003\Software\Online Add-on
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Information Center
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Information Center#DisplayName






Field Value
Computer
Operating System Microsoft Windows XP Professional
OS Service Pack Service Pack 3
DirectX 4.09.00.0904 (DirectX 9.0c)


Motherboard
CPU Type Mobile AMD Turion 64 ML-34, 1800 MHz (9 x 200)
Motherboard Name Hewlett-Packard Presario V2000 (EP379UA#ABA)
Motherboard Chipset ATI Radeon Xpress 200M, AMD Hammer
System Memory 896 MB (PC2700 DDR SDRAM)
BIOS Type Phoenix (08/30/06)

Display
Video Adapter ATI RADEON XPRESS 200M (128 MB)
Video Adapter ATI RADEON XPRESS 200M (128 MB)
3D Accelerator ATI Radeon Xpress 200M (RS480M)
Monitor Plug and Play Monitor
Monitor Generic Television

Multimedia
Audio Adapter ATI SB400 - AC'97 Audio Controller

Storage
IDE Controller Standard Dual Channel PCI IDE Controller
IDE Controller Texas Instruments PCIxx21 Integrated FlashMedia Controller
Disk Drive ST9100822A (100 GB, 5400 RPM, Ultra-ATA/100)
Optical Drive TSSTcorp CD/DVDW TS-L532M (DVD+R9:2.4x, DVD+RW:8x/4x, DVD-RW:8x/4x, DVD-ROM:8x, CD:24x/10x/24x DVD+RW/DVD-RW)
SMART Hard Disks Status OK

Partitions
C: (NTFS) 95385 MB (48291 MB free)

Input
Keyboard Quick Launch Buttons
Mouse Synaptics PS/2 Port TouchPad

Network
Network Adapter Realtek RTL8139/810x Family Fast Ethernet NIC (10.5.12.93)
Modem AC97 Data Fax SoftModem with SmartCP

Peripherals
USB1 Controller ATI SB400 - USB Controller
USB1 Controller ATI SB400 - USB Controller
USB2 Controller ATI SB400 - USB 2.0 Controller
Battery Microsoft AC Adapter
Battery Microsoft ACPI-Compliant Control Method Battery
Ok, I have finished ALL of the insructoins listed and have attached the files to the post instead of having a 300 PAGE to look at.

Again thanks for the help and I look foward from reading everyones posts.

[attachment deleted by admin]Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop.

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Close any open web browsers (FIREFOX, Internet Explorer, etc) before starting ComboFix.

Temporarily DISABLE your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click combofix.exe and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.Ok, I have done the combofix and hijackthis again and they are attached. Thanks for the further assistance. I look foward to the next step in this process.

[attachment deleted by admin]I don't see anymore infections. How are things running now?

2466.

Solve : Malware/Spyware Problems?

Answer»

Hi,

Firstly, I hope CREATING a new topic was the correct thing to do as I couldn't see a topic that looked like I should post it there.

I followed all the instructions and here are the logs and things

Things I wasn't sure of in Add/Remove

ATKOSD2
Favorit
getPlus®_ocx
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 Sp2 (KB954430)
P4P

I also notice that there seem to be an awful lot of processes running in task manager which is lucky in a way because a search for one of them led me here.

This is the list of processes I am UNSURE of

MOM.EXE
ctfmon.exe
WDC.exe
SynTPEnh.exe
KBFiltr.exe
HiYo.exe
Acrotray.exe
ATKOSD.exe
ACEngSvr.exe
FNPLicensingService.exe
ACMON.exe
ACU.exe
ASScrPro.exe
HControl.exe
DMedia.exe
avgtray.exe
PDVDServ.exe
wcourier.exe
CCC.exe
WLLoginProxy.exe

And another one which is strange is
SVCHOST.exe
At the time of posting there are 4 copies running that say SYSTEM, 2 copies that say NETWORK SERVICE and 1 copy that says LOCAL SERVICE



I don't think I have missed anything but will obviously post anything else you need.

Many thanks for any assistance you can offer

[attachment deleted by admin]SORRY for the long wait. We are VERY backed-up right now! You had a couple of SMALL infections, but nothing to worry about. You should uninstall Wanadoo, however. If you STILL require assistance, please post new logs and we'll see what we can do.Quote from: CBMatt on January 04, 2009, 03:23:53 PM

Sorry for the long wait. We are VERY backed-up right now! You had a couple of small infections, but nothing to worry about. You should uninstall Wanadoo, however. If you still require assistance, please post new logs and we'll see what we can do.

Hi Matt,

Thanks for the reply, no worries on the timescale as it's not exactly the best time of year for such things is it. I am wary of uninstalling Wanadoo as this was the only way I could get my laptop to connect to the wireless box. I am happy to do it if you can advise a way of doing it without losing my wireless connection as I would then be totally helpless without a connection to come back on here for further instructions.

Many thanks
RalphGood thing you didn't listen to me! Heh. I'm sorry, but I made a small error in my previous post. I meant that you should uninstall the Wanadoo Toolbar, not Wanadoo itself. The toolbar isn't necessarily malicious, but it can be a pain for some people and I think you're better off without it. Of course, it's your decision entirely.
2467.

Solve : win32:patched-ck just can't get rid of it!!?

Answer»

I know this thread is old, but I know what happened here because it just happened to me. Explorer.exe got deleted and it's hung because it doesnt have a shell to load. If you GO into safe mode and do the crtl-shift-esc (I think thats it...it MAY be crtl-alt-esc) to pull up the taskmgr.exe the FILE explorer.exe is gone.

I OPENED taskmgr and expanded explorer.exe from the xpsp2 directory (explorer.ex_).

After that I loaded the file I just expanded (explorer.exe) and the system is fine now.

2468.

Solve : Help needed - Rootkit?

Answer»

'The Problem started a week ago, I got many Norton Anti-Virus 'email failure notification'
I uninstalled norton and got AVG, NOD32 & spyware doctor, but the problem is still here.
From time to time the AVG prompts a 'trojan horse rootkit.av' message.

The logs requested are enclosed.
Thanks in advance
Yoav

[attachment deleted by admin]ok, I just had avg 'threat detected': Trojan Horse Rootkit-Agent.av
file name: c:\windows\system32\drivers\ati3fbxx
process name:c:\ windows\temp\bn3cd.tmp
OS : XP

I could really use your help..
thanksDownload ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.

For Windows XP Systems install the Recovery Console:

- If you are USING Windows XP and do not already have the Recovery Console installed, please ensure your Internet connection is ACTIVE (if possible) and click Yes.
- If for some reason your Internet is not working click No.
- If you are not using Windows XP, you will not be prompted.
- When prompted to accept the EULA click OK.
- Accept Microsoft's EULA (Click Yes).
- When you are told that the RC is installed correctly click YES to CONTINUE scanning for malware.

When finished ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.The logs are enclosed, but I'm not sure that the AVG was closed (I kept on getting an error message while uninstalling). I think i have the RC (although it says I don't in the combofix log, but I hadn't have this option anyway while running combofix.

once again, thanks!

[attachment deleted by admin]You have two antivirus installed. Eset and AVG. You should only run one at a time so it's best to pick one and uninstall the other now.

Run the Kaspersky Online Scanner

In Microsoft Windows VISTA, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

  • Click on SCAN NOW
  • Click Accept.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or something similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
After encountering some problems, here is the log.

Yoav

[attachment deleted by admin]Do you know what that is?

_ati3fbxx_.sys.zipA search for a file under that name got the results as written in the log:
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_ati3fbxx_.sys.zip

One of the AVG notification showed an infection in a file called ati3fbxx.
By the way, I just had another AVG infection notice about another file.


    Yea sorry, I noticed it's already quarantined after I posted that.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    ----------

    Download
ATF Cleaner by Atribune to your Desktop.

Alternate download link

Note: Vista users must use Run As Administrator
  • Under Main: Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • Click Exit on the Main menu to close the program.
Note that your system will run slower for a reboot or two after having USED this tool so don't panic.

----------

Download OTCleanIt.exe and save it to your Desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
Important: Restart the computer before continuing.

----------


Let the computer run for a bit and let me know how it is running now. Any virus alerts please note the file location and post it here.
2469.

Solve : Getting my logs to you?

Answer»

I see it running in the Service but I don't see it in the Processes, and it should be.

Two logs will be produced with this scan. Please post (copy/paste) both of them. You might need two posts to get all of the text in.

Download random's system information tool (RSIT) by random/random from and save it to your Desktop.

  • Double click on RSIT.exe to run.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open.
  • log.txt <will be maximized and info.txt <will be minimized
  • Please post the contents of both logs in the next reply.
I'm sorry, I had to stop yesterday, my grandmother was put in the hospital-had to go to Ga. I just tried the Hijack stuff you said and an error message came up. I am going to try to copy and paste it to you. After the message-it connected me with a site with questions and answers-I didn't even know my question. I'm SENDING you the error message now. I know it's early where you are-I'm sorry- but you don't know how much I REALLY THANK-YOU FOR ALL YOUR HELP AND PATIENCE!!!!!!!!!!
DonnaIt's me again, I just went back to Hijack this and the things (only a couple were on there in the first place that you told me to check-well they are not on there now, so I am sending you what is on there now. Do I go ahead and do the next stuff you said to do or wait until I hear from you? I'll wait.
Donna
I can't send it to you-it won't let me highlight it.;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys [2006-12-07 76584]
R3 GEARAspiWDM;GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2008-01-29 16168]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\Windows\system32\drivers\mfeavfk.sys [2007-11-22 79304]
R3 mfebopk;McAfee Inc. mfebopk; C:\Windows\system32\drivers\mfebopk.sys [2007-11-22 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\Windows\system32\drivers\mfesmfk.sys [2007-12-02 40488]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2006-12-14 6144]
R3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2007-01-15 9728]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-06-19 7468128]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point32k.sys [2006-11-08 24064]
R3 rt61x86;Linksys Wireless-G PCI ADAPTER Driver; C:\Windows\system32\DRIVERS\WMP54Gv41x86.sys [2007-03-12 286208]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 298496]
S1 DTC328X;DTC328X; C:\Windows\System32\drivers\DTC328X.SYS []
S1 EPPSCSIx;EPPSCSIx; C:\Windows\System32\drivers\EPPSCSI.SYS []
S3 BEFCMU10V4XP;Linksys BEFCMU10 ver. 4 Cable Modem; C:\Windows\system32\DRIVERS\BEFCMU10V4XP.sys [2004-07-05 14336]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys []
S3 mferkdk;McAfee Inc. mferkdk; C:\Windows\system32\drivers\mferkdk.sys [2007-11-22 33832]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 UNDPX2A;UNDPX2A; \??\C:\Windows\system32\drivers\UNDPX2A.SYS []
S3 USBCM;Scientific-Atlanta USB Cable Modem Driver; C:\Windows\system32\DRIVERS\Sacm2A.sys [2004-06-09 15429]
S3 WSVD;WSVD; \??\C:\Windows\system32\drivers\WSVD.sys [2006-09-19 80744]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-02-18 110592]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2007-07-24 229376]
R2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2006-12-08 45056]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440]
R2 lxdc_device;lxdc_device; C:\Windows\system32\lxdccoms.exe [2007-05-25 537520]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-01-09 767976]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-01-25 2458128]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2007-08-15 359248]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2007-07-24 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2007-07-18 856864]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-06-19 118784]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-03-30 504104]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2007-12-05 695624]
S2 lxdcCATSCustConnectService;lxdcCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdcserv.exe [2007-05-25 99248]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2007-11-07 378184]

-----------------EOF-----------------
xt LOGFILE of random's system information tool 1.05 2008-12-23 09:03:48

======Uninstall list======

-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
AC3Filter (remove only)-->C:\Program Files\AC3Filter\uninstall.exe
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}
Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Media Player-->msiexec /qb /x {1EBB57D4-63FF-87CC-A0F0-D73982CF6008}
Adobe Media Player-->MsiExec.exe /I{1EBB57D4-63FF-87CC-A0F0-D73982CF6008}
Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Comcast High-Speed Internet Install Wizard-->C:\Program Files\support.com\uninstall\chsi_uninstaller.exe
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
ebgcInfra-->MsiExec.exe /X{39B1BD87-561E-4762-AED9-7C5213B06C24}
ebgcRes-->MsiExec.exe /X{5380B111-5047-413D-A6E5-70D69391D08E}
ebgcSDK-->MsiExec.exe /X{13AD768A-9E04-499D-AE80-967A65DCCBA5}
Graboid Video 1.3-->C:\Program Files\Graboid\uninst.exe
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
iTunes-->MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Lexmark 1300 Series-->C:\Program Files\Lexmark 1300 Series\Install\x86\Uninst.exe
Linksys Wireless-G PCI Adapter-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4DDC3BED-CC68-44AA-B435-D727B620CA5B}\setup.exe" -l0x9
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter-->C:\Program Files\McAfee\MSC\mcuninst.exe
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Mozilla ActiveX Control v1.7.12-->C:\Program Files\Mozilla ActiveX Control v1.7.12\uninst.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Rhapsody Player Engine-->MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
Scientific-Atlanta WebSTAR 2000 series Cable Modem-->UNDPX2A.EXE
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
VeohTV BETA-->C:\Program Files\InstallShield Installation Information\{0405E51E-9582-4207-8F38-AC44201D3808}\setup.exe -runfromtemp -l0x0409
VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Vista Upgrade Advisor-->MsiExec.exe /I{C6AA3FB7-804F-4808-AD91-B62D6ED9B788}
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\common\unyt.exe
YOU DON'T KNOW JACK Volume 3-->c:\windows\ydkjv3\unwise.exe c:\windows\ydkjv3\jack3.log

=====HijackThis Backups=====

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKUS\.DEFAULT\..\RunOnce: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q C:\Users\Donna\AppData\Local\Temp\Low\~DFF343.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFF22A.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF156E.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF12A2.tmp C:\Users\Donna\AppData\Local\Temp\HSPERF~1.SH! C:\Users\Donna\AppData\Local\Temp\Low\~DFBD71.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFBD5A.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFADDA.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFAD2C.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF5B72.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF5B68.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF28F8.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF2789.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFD81.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF6E8F.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF63B0.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF4C7F.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF4C72.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF3A
O4 - HKUS\S-1-5-18\..\RunOnce: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q C:\Users\Donna\AppData\Local\Temp\Low\~DFF343.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFF22A.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF156E.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF12A2.tmp C:\Users\Donna\AppData\Local\Temp\HSPERF~1.SH! C:\Users\Donna\AppData\Local\Temp\Low\~DFBD71.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFBD5A.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFADDA.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFAD2C.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF5B72.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF5B68.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF28F8.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF2789.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFD81.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF6E8F.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF63B0.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF4C7F.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF4C72.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF3A
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKUS\.DEFAULT\..\RunOnce: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q C:\Users\Donna\AppData\Local\Temp\Low\~DFF343.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFF22A.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF156E.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF12A2.tmp C:\Users\Donna\AppData\Local\Temp\HSPERF~1.SH! C:\Users\Donna\AppData\Local\Temp\Low\~DFBD71.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFBD5A.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFADDA.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFAD2C.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF5B72.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF5B68.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF28F8.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF2789.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFD81.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF6E8F.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF63B0.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF4C7F.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF4C72.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF3A
O4 - HKUS\S-1-5-18\..\RunOnce: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q C:\Users\Donna\AppData\Local\Temp\Low\~DFF343.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFF22A.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF156E.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF12A2.tmp C:\Users\Donna\AppData\Local\Temp\HSPERF~1.SH! C:\Users\Donna\AppData\Local\Temp\Low\~DFBD71.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFBD5A.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFADDA.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFAD2C.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF5B72.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF5B68.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF28F8.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF2789.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DFD81.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF6E8F.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF63B0.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF4C7F.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF4C72.tmp C:\Users\Donna\AppData\Local\Temp\Low\~DF3A
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

======Security center information======

AS: Windows Defender

System event log

Computer Name: Bruce
Event Code: 7036
Message: The TPM Base Services service entered the stopped state.
Record Number: 284478
Source Name: Service Control Manager
Time Written: 20081223135150.000000-000
Event Type: Information
User:

Computer Name: Bruce
Event Code: 537
Message: A compatible Trusted Platform Module (TPM) Security Device cannot be found on this computer. TBS could not be started.
Record Number: 284479
Source Name: Microsoft-Windows-TBS
Time Written: 20081223135150.174147-000
Event Type: Information
User: NT AUTHORITY\LOCAL SERVICE

Computer Name: Bruce
Event Code: 7036
Message: The Security Center service entered the running state.
Record Number: 284480
Source Name: Service Control Manager
Time Written: 20081223135204.000000-000
Event Type: Information
User:

Computer Name: Bruce
Event Code: 7036
Message: The Windows Update service entered the running state.
Record Number: 284481
Source Name: Service Control Manager
Time Written: 20081223135259.000000-000
Event Type: Information
User:

Computer Name: Bruce
Event Code: 18
Message: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Wednesday, ?December ?24, ?2008 at 3:00 AM:
- Security Update for Internet Explorer 7 in Windows Vista (KB960714)
Record Number: 284482
Source Name: Microsoft-Windows-WindowsUpdateClient
Time Written: 20081223135346.148147-000
Event Type: Information
User: NT AUTHORITY\SYSTEM

Application event log

Computer Name: Bruce
Event Code: 302
Message: Windows (2388) Windows: The database engine has successfully completed recovery steps.
Record Number: 110490
Source Name: ESENT
Time Written: 20081223134958.000000-000
Event Type: Information
User:

Computer Name: Bruce
Event Code: 0
Message:
Record Number: 110491
Source Name: iPod Service
Time Written: 20081223135003.000000-000
Event Type: Information
User:

Computer Name: Bruce
Event Code: 1003
Message: The Windows Search Service started.

Record Number: 110492
Source Name: Microsoft-Windows-Search
Time Written: 20081223135113.000000-000
Event Type: Information
User:

Computer Name: Bruce
Event Code: 1
Message: The Windows Security Center Service has started.
Record Number: 110493
Source Name: SecurityCenter
Time Written: 20081223135209.000000-000
Event Type: Information
User:

Computer Name: Bruce
Event Code: 5
Message: Unsupported service control request (see data below)
Record Number: 110494
Source Name: LightScribeService
Time Written: 20081223140344.000000-000
Event Type: Information
User:

Security event log

Computer Name: Bruce
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name:\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 87849
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081223140334.462147-000
Event Type: Audit Failure
User:

Computer Name: Bruce
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name:\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 87850
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081223140334.561147-000
Event Type: Audit Failure
User:

Computer Name: Bruce
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name:\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 87851
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081223140334.639147-000
Event Type: Audit Failure
User:

Computer Name: Bruce
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name:\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 87852
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081223140334.719147-000
Event Type: Audit Failure
User:

Computer Name: Bruce
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name:\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 87853
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081223140334.782147-000
Event Type: Audit Failure
User:

======Environment VARIABLES======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 95 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=5f02
"NUMBER_OF_PROCESSORS"=1
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip

-----------------EOF-----------------
DID I DO IT RIGHT??
DonnaHello----Did I do it right? I'm sorry I could not do it right away-but my grandmother was put in the hospital. So I did it today. Is that O.K.??
DonnaYour Java is out of date.

Older versions have vulnerabilities that MALICIOUS sites can use to infect your system.

First install the new Sun Java Runtime Environment

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

Download JavaRa
  • Unzip the file and open the JavaRa.exe
  • Click Remove Older Versions
  • JavaRa will search for and remove any outdated version of Java and remove any that are found.
  • Click Additional Tasks
  • Place a check next to Remove Useless JRE Files and click Go
  • Exit JavaRa
  • Delete the JavaRa files from the Desktop
----------

I don't think that McAfee is installed right. It's not showing in the Security Center. Do you have a disk so you can re-install it?don't have a disk to re-install McAfee. Like I said it came with comcast and I just downloaded it from the web-site as best as I can remember.
Thank-you.
Now what?
DonnaIf it's provided by your ISP then I would contact them. They will either send a disk or let you know how to re-install it.
2470.

Solve : Spyhunter??

Answer»

Hello. I have an AMD athalon, xp sp3 with a 100 gig + 200 gig+200 gig drives.
The 100 is partitioned into 20 and 80 gig, with the 20 being designated to being the C: Drive. I CURRENTLY run AVG for virus control.

So I have two questions. (and maybe some others relative to the C: Drive size).
1. Because of low disk space I looked AROUND to see if I can free up some space and FOUND a folder with spyhunter in it, so Im thinking why do I have that anyway I'm using AVG. Is Spyhunter any good?
2 Can I just DELETE it (if its no good) or do I have to uninstall it?

About the C:, Most of the programs are loaded there by default (and yes I know I can set it to load elsewhere), so, Can I increase the size of the drive partition without affecting the the programs?

Thank you for looking at my post.
Id like to WISH everyone a Happy and Safe Christmas break and a Great New Year. If you have the name right "SpyHunter" then no it isn't a trusted program and should be uninstalled.

Quote

About the C:, Most of the programs are loaded there by default (and yes I know I can set it to load elsewhere), so, Can I increase the size of the drive partition without affecting the the programs?

You will be best off asking that in the Windows forum.
2471.

Solve : am I good to go??

Answer»

My goodness gracious. It has been a maddening past few days trying to figure out what is wrong with my poor laptop, and I am so thankful to have come across your "read this before asking for malware removal help" thread.

I've heard that Trojans are not viruses and so they don't duplicate, and if that is the case then I really have no idea what this was. I was getting the pop-ups, and then I NOTICED some FUNNY business at my Windows log-on screen, my computer wouldn't go in to sleep mode, etc. I downloaded a few different anti-viral/spyware/adware programs and ran them, but frequently when I elected to remove the bad stuff it came up with (which was increasingly more and more INFECTED items, so I knew it wasn't just a Trojan), the program claimed "could not find specified pathway" or "some files could not be healed" . But after running through your steps I think I may be fine now. No pop-ups have harangued me, my long-on screen was clear the past 2 re-boots.

So here are the logs from the scans. Do I need to clear out any of the HijackThis items?



[attachment deleted by admin]O2 - BHO: WormRadar.com IESiteBlocker.NavFilter..etc



O2 - BHO: (no name) - {A60AF806-B725-4169-A962-77AA35B1E84A} ...

those 2 are bad, and I know that for sure.

I had those 2, and i was asked to remove them.

May help. but not that much.Trojans are a type of virus. In terms of biology, think of a virus as a genus and a trojan as a species. It's not a perfect comparison, but bare with me. Trojans, keyloggers, worms, rootkits, etc. are different virus types. They have different names because they do different things, but they are all viruses.

With that said...your scans picked up quite a bit, but you should do the following just to be safe...

Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop.

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily DISABLE your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click combofix.exe and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.





Quote from: Zain on December 27, 2008, 10:56:56 PM

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter..etc



O2 - BHO: (no name) - {A60AF806-B725-4169-A962-77AA35B1E84A} ...

those 2 are bad, and I know that for sure.

I had those 2, and i was asked to remove them.

May help. but not that much.
Your desire to help is appreciated, but please refrain from assisting in the removal of HijackThis entries unless you have received proper training. Thank you.
2472.

Solve : Anti - Spyware/Trojan/Worm/Virus...?

Answer»

Before asking people to SPEND time answering my personal Trojan/Worm issues, I was wondering if you could point me towards the best Anti- Spyware/Trojan/Worm/Virus... programme. I've installed Kaspersky recently but it seems unable to get rid off some of them (trojan csrssc.exe, HEUR.worm, trojan clicker, backdoor.win32.tdss.atb etc etc...) so was wondering if there was ANYTHING better available (prior to Kaspersky, tried Norton but was unable to COMPLETE installation....)
Your suggestions would be much appreciated

As you might have guessed I'm not too good with non-basic computer skills so would prefer one software to clean the whole thing up rather than the ten steps/ten hours VERSION (acknowledging that I might have to COME to it though !)

Thanks a lot for your suggestionsAVG: http://free.avg.com/
Avira: http://www.free-av.com/
SuperAntiSpyware: http://www.superantispyware.com/

Remember to have only one antivirus program running at any one time.

2473.

Solve : YIKES & now what?

Answer»

I have followed the instructions in the FORUM except for Step #2 as the following error came up: Ccleaner.exe-corrupt file/$mft. Broni was helping me (very patient) with some other folks and told me to uninstall and try again. I did and the same thing happened. I went to Step#3 and followed the rest. Now when I restart my comuter I get:

Blue Box: ASSERT
Assert Failed/Porjects/wKernel/src/Win32/cm/core/cmCodeModule.cpp:90_mCodeHandle !=NULL

then I get another Blue Box: ddcmigrateexe.application error
The Application failed to initalize properly(0x8000003).Clik OK to term application.

When I hit OK I had to hit it again and then the screen went back to the first blue box. When I got that cleared, it went back to the second error and I had to hit it twice to go away.
had to be done twice.

Here is System Info:

Hewlett-Packard Pavillon
AMD Athlon(tm)XP 300+
2.10 GH2 448 MB of Ram

File System NTFS
Capacity 144 GB
Free Space 102 GB
% Free 70%

I had to use Attach files for logs.

[attachment DELETED by admin]Sorry I forgot to ad the Hijack log.

[attachment deleted by admin]Download ComboFix by sUBs from one of the below links. Be sure to SAVE it to the Desktop.

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a SCAN. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click combofix.exe and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.

2474.

Solve : Possible virus with Task bar?

Answer»

Hi

I'm using a Toshiba Satellite Pro laptop with Windows XP Professional. My antivirus software is the latest free version of Avast.

My problem at the minute is quite strange. I was using Bittorrent and any time i TRIED to open it, it appeared on the taskbar but i couldn't open it. The same problem happens with FIREFOX when i close it. I can open firefox and then when closing it down a tab for clear browser history appears on the taskbar but i can't open it. I click on it but it wont enlarge. There are a few other programs which also have this problem such as msn messenger. I can open the program but cant open any messages, they appear on the task bar but there is nothing i can do to open them. I'm not SURE if this is related to a virus or could it be related to a RAM problem?

I've attached the required log files for your attention and I really appreciate any help you can offer.


You guys do amazing work! THANKS so much.

02/01/09

Hi again, anyone got any ideas? How about the log files, are they at least clean? Could it be a problem with some settings? I've also tried to use TVU and spocast (TV software) and they will open but i always get the error message "An error has occurred in the script of this page" - "Do you want to continue running SCRIPTS on this page - yes or no" Clicking yes doesn't work

Thanks again

[attachment deleted by admin]Sorry for the long wait. We are VERY backed-up right now! I don't see much in your logs, but if you still require assistance, please post new logs and we'll see what we can do. If we have updated logs, we can see if any changes have been made.

2475.

Solve : fails to boot after infection?

Answer»

Hey guys, i'm in a bit of a pickle,

I have a new toshiba satellite LAPTOP with vista 32.

I did something very silly today and downloaded an exe file from dailykeys.com where every file contains a trojan - afterwards my avg and windows defender attempted to stop the onslaught but I knew there was still things lurking. I then ran malwarebytes anti-malware, it said it has to finish deleting the infected files on REBOOT but on that reboot something went very wrong. Now nothing happens after the toshiba screen is loading and it goes to a black screen and hangs forever with no sign of windows. Can't go into safemode and can't boot from cd.

I downloaded and burnt the Vista_Recovery_Disc.iso but my laptop won't boot from cd now for some reason - i'm guessing the malware that is on the hdd is stopping this.

I know my dvd drive is fine because when I disable the hdd my recovery disc starts working.

So at the moment I can only access bios with the hdd enabled.

I'm thinking the only thing I can do is buy another hdd and xp disc (my laptop didnt come with vista install). This way I can access my files externally and format the infected vista partition.

Unless there is any way to clean the partition externally whilst I am in XP?

thanks guys.You have to set your Boot Orde (In the BIOS) to have it boot from the CD Drive first.
From what you have told us, it seems that when the computer cannot find the Hard Drive, it boots from the CD/DVD.

Do you have the Windows Vista DVD?
If so, you need to perform a Repair Install. This way you can repair your OS without having to reinstall.Thanks for your reply - i've ALREADY tried setting cd to boot first - but somehow the cd does not work with the hdd still connected, only when it is disconnected. I think the malware is controlling this.Although I'm not a Malware Specialist, I highly doubt this is possible.
A VIRUS cannot control how the computer boots.

Can you try another CD/DVD Drive?

Otherwise, do you have access to another computer?I have access to another computer and as the one infected is a laptop, i have ordered an external ENCLOSURE so I can hook up my laptop hdd to this other computer and use it's cd drive to try Vista Recovery. Or if I use my toshiba vista cd, will going back to factory settings get rid of the malware completely?Reformatting (or "going back to factory settings") will get rid of your infection, but it will also get rid of all of your personal data. But if you can't run any scans on the computer, then you may have no other choice. This is what messing with warez can do to your computer...

2476.

Solve : need virus help?

Answer»

picked up trojan horse that I thought I had cleaned off but obviously not fast enough.

computer would boot FINE, but at XP log-in screen, you can SELECT a user and type password, then it takes you right back to log-in screen.

booted the machine in safety mode and ran eTrust with week old data file. found bad files, deleted those...but also identified userinit.exe file as corrupted without being able to identify a fix or the virus. left those files in quarantine.

now, can not log in even in safety mode...any suggestions other than rebuilding?Do you have the Windows CD?Will have on Sunday when I return homeOk. When you can, perform a Repair Install.
http://www.michaelstevenstech.com/XPrepairinstall.htm

(None of your files will be lost)Okay...FOLLOWED instructions as WRITTEN for repair install. Everything seemed to work fine, but when completed still have same problem. Get to login screen, let's me enter password and then says logging off. Any other ideas?
You've performed a repair install yet you still cannot log in?

What about Safe Mode?

2477.

Solve : System32 Virus Suspected?

Answer»

Hey again,

I'm suspecting there is a system32 virus on my WIN XP PC. Automatic Updates are being turned off and i get the security center alert in the notification bar. SUPERANTISPYWARE seems to pick up the same 4 files every time i run it, along with a number of registry ENTRIES. Adn what ever this is, it keeps trying to open an internet page. The "Cannot connect to Internet, Connect or Try Again" box keeps popping up. I've disconnected it from my home network so it can't re-download files as it's weeded out. I've gone into MSCONFIG and disabled a startup process named xftbolwc.dll in System32.

I've run an Avira Anti virus scan, no hits.

SUPERAntiSpyware log attached.

MBAM log attached.

No java installed. (I re-formatted last week).

HijackThis log attached.



[attachment deleted by admin]Hm, it seems whatever was messing with security center was was caught by MBAM. Everything works as it should. But there are still viruses found in further scans.

EDIT: Still infected. with a nnzllu.dll, when i try to nuetralize it in SUPERAntiSpyware, windows logon services crashes and i get a blue screen SAYING that it crashed.
I got it. Had to disable neutralize memory items before quarantining.

2478.

Solve : Task Manager, Registry Editor, msconfig and DVD Combo not working!?

Answer»

My Computer is seriously infected.

I am unable to OPEN Task Manager, Registry Editor, msconfig.
My DVD Combo is also unable to read from CD/DVD.

Ante-Virus = AVG Free Edition

Hijack this and Malwarebytes' Anti-Malware's Logs are attached!
I've also performed SUPERAntiSpyware Free Edition (Complete SCAN).

[ATTACHMENT deleted by admin]I SCANNED my PC today with AVG-Free Edition, Malwarebytes' Anti-Malware and SUPERAntiSpyware Free Edition.
Task Manager, Registry Editor and Microsoft System Configuration Utility (msconfig) is now working....

But DVD Combo is still not working......

Any help.....No replies...

2479.

Solve : Virus Help Needed - Trojans and other problems?

Answer»

I really hope you guys will be able to help me out. I'm not sure how I got infected, I've had malware/virus problems in the past few months but since I recently re-formated my laptop over the break I've tried to be really careful. Anyhow, the infections appeared after I rebooted my computer and my boyfriend was using my laptop last Friday. I have no idea what websites he went to, but a whole slew of infections have shown up and I'm not sure what to do.

Generally, it is just a lot of pop-ups. It seems to be more problematic in Internet Explorer so I do not use it. While RUNNING Mozilla Firefox, I get pop-ups of random websites EVERY so often, which I just close right away. I've been using Avast as my virus protection and it warns me every so often of all the infections. My laptop is a Compaq Presario R4000, running Windows XP.

I tried to do a System Restore to last Thursday (where it says it is the "Last Known Good Configuration"), but after my system reboot, it said that the restore was incomplete and could not be done. All the other available dates were after the infections appeared.

I followed all the steps in the instruction post, and LOGS are posted. When I did the SUPERAntispyware Scan, the scan finished, but the program crashed and my system reboot before it could remove the problems. Let me know if there are any other details I can include. Thank you!!



[attachment deleted by admin]well the first step is always a systems restore. it returns you setting back to an earlyer time windows makes backup files so to speak. to do this

go to start menu select my documents / at top of my documents screen there should be a help drop down menu option. in the menu is the help and support option. in this menu half way down the page is the system resore option resore my computer to an earlier time.

choose from the calandar a date before the infection happened where there is a restore point usally a system chk point.http://support.microsoft.com/kb/306084

here is the link

this expalins it better than meThanks for the advice. I MENTIONED in my post that I have already tried doing a system restore.

There was only ONE checkpoint available before my infection. When my system attempted to restore to this date, it said that the system restore was incomplete and no changes were made.You say that SuperAntiSpyware crashed- can you run it again?

2480.

Solve : Anti-Virus Problem and Computer Suddenly running about 10 times slow?

Answer»

It still loads really slow, but the Personal Firewall problem is fixed again.You might want to Defrag the computer. There may be a lot of fragmented sections on the drive after cleaning the malware.

You can use the built in Windows Defrag or a faster FREE program. Defraggler is very EFFECTIVE and easy to use. Be sure to clean out temp files and RESTART the computer just before using this.That seems to have fixed most of the problem. Still loads kind of slow, but the sound issues seem to be fixed and the load times of much more tolerable.Try Dial-a-FIX. Other than that I'm not sure what's going on.

Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

  • Open the folder and run Dial-a-fix.exe
  • 2 windows will open. Close the ONE in the background labeled Restrictive Policies
  • Check the box in section 1, Empty temp folders.
  • Check the box in section 2, Fix Windows Installer.
  • Check the box in section 3, Fix Windows Update.
  • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
  • Check all boxes in section 5, labeled Registration Center.
  • Click Go
  • OK any error messages if received, but write them down and post them here.
  • Restart the computer when done.
Dial-a-Fix didn't really solve anything. The sound problem has just worsened and affects all sound. It takes the computer about 10 minutes to load and 10 minutes to start-up.

I figured out what the problem with the Personal Firewall is. Mozilla Firefox and TREND Micro do not agree with each other for what ever reason and by having Mozilla on the computer, Trend Micro disables the Personal Firewall. I do not know why. I do know that I need Mozilla for a class I'm taking.
2481.

Solve : re occuringpop ups hijack this?

Answer»

Hi hope you can help i downloaded hijack this did a system scan and saved LOG file as follows.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:43:22, on 19/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\LEXMARK X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\PieAutoUpdater\PieAutoUpdater.exe
C:\Program Files\JAVA\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\PieAutoUpdater\pglite.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Yahoo!\SEARCH Protection\SearchProtection.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\documents and settings\kevin\local settings\application data\fcdarpp.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 209.216.253.186 www.winmx.com err.winmx.com
O1 - Hosts: 65.75.216.6 cache0.winmx.com test3201.winmx.com test3206.winmx.com
O1 - Hosts: 65.75.216.7 cache1.winmx.com test3202.winmx.com test3207.winmx.com
O1 - Hosts: 82.43.229.238 cache2.winmx.com test3203.winmx.com test3208.winmx.com
O1 - Hosts: 205.238.40.1 cache3.winmx.com test3204.winmx.com
O1 - Hosts: 205.238.40.2 cache4.winmx.com test3205.winmx.com
O1 - Hosts: 65.75.216.6 c3310.z1301.winmx.com c3310.z1302.winmx.com c3310.z1303.winmx.com c3310.z1304.winmx.com c3310.z1305.winmx.com c3310.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3311.z1301.winmx.com c3311.z1302.winmx.com c3311.z1303.winmx.com c3311.z1304.winmx.com c3311.z1305.winmx.com c3311.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3312.z1301.winmx.com c3312.z1302.winmx.com c3312.z1303.winmx.com c3312.z1304.winmx.com c3312.z1305.winmx.com c3312.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3313.z1301.winmx.com c3313.z1302.winmx.com c3313.z1303.winmx.com c3313.z1304.winmx.com c3313.z1305.winmx.com c3313.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3314.z1301.winmx.com c3314.z1302.winmx.com c3314.z1303.winmx.com c3314.z1304.winmx.com c3314.z1305.winmx.com c3314.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3315.z1301.winmx.com c3315.z1302.winmx.com c3315.z1303.winmx.com c3315.z1304.winmx.com c3315.z1305.winmx.com c3315.z1306.winmx.com
O1 - Hosts: 82.43.229.238 c3316.z1301.winmx.com c3316.z1302.winmx.com c3316.z1303.winmx.com c3316.z1304.winmx.com c3316.z1305.winmx.com c3316.z1306.winmx.com
O1 - Hosts: 82.43.229.238 c3317.z1301.winmx.com c3317.z1302.winmx.com c3317.z1303.winmx.com c3317.z1304.winmx.com c3317.z1305.winmx.com c3317.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3318.z1301.winmx.com c3318.z1302.winmx.com c3318.z1303.winmx.com c3318.z1304.winmx.com c3318.z1305.winmx.com c3318.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3319.z1301.winmx.com c3319.z1302.winmx.com c3319.z1303.winmx.com c3319.z1304.winmx.com c3319.z1305.winmx.com c3319.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3520.z1301.winmx.com c3520.z1302.winmx.com c3520.z1303.winmx.com c3520.z1304.winmx.com c3520.z1305.winmx.com c3520.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3521.z1301.winmx.com c3521.z1302.winmx.com c3521.z1303.winmx.com c3521.z1304.winmx.com c3521.z1305.winmx.com c3521.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3522.z1301.winmx.com c3522.z1302.winmx.com c3522.z1303.winmx.com c3522.z1304.winmx.com c3522.z1305.winmx.com c3522.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3523.z1301.winmx.com c3523.z1302.winmx.com c3523.z1303.winmx.com c3523.z1304.winmx.com c3523.z1305.winmx.com c3523.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3524.z1301.winmx.com c3524.z1302.winmx.com c3524.z1303.winmx.com c3524.z1304.winmx.com c3524.z1305.winmx.com c3524.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3525.z1301.winmx.com c3525.z1302.winmx.com c3525.z1303.winmx.com c3525.z1304.winmx.com c3525.z1305.winmx.com c3525.z1306.winmx.com
O1 - Hosts: 82.43.229.238 c3526.z1301.winmx.com c3526.z1302.winmx.com c3526.z1303.winmx.com c3526.z1304.winmx.com c3526.z1305.winmx.com c3526.z1306.winmx.com
O1 - Hosts: 82.43.229.238 c3527.z1301.winmx.com c3527.z1302.winmx.com c3527.z1303.winmx.com c3527.z1304.winmx.com c3527.z1305.winmx.com c3527.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3528.z1301.winmx.com c3528.z1302.winmx.com c3528.z1303.winmx.com c3528.z1304.winmx.com c3528.z1305.winmx.com c3528.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3529.z1301.winmx.com c3529.z1302.winmx.com c3529.z1303.winmx.com c3529.z1304.winmx.com c3529.z1305.winmx.com c3529.z1306.winmx.com
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Pie Auto Updater] "C:\Program Files\PieAutoUpdater\PieAutoUpdater.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [AOL_Demo] C:\Applications\Tool\AOL Demo\DSGDemo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [fcdarpp] "c:\documents and settings\kevin\local settings\application data\fcdarpp.exe" fcdarpp
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O24 - Desktop Component 0: (no name) - http://ly.lygo.com/ly/lmail/img/the_paper_clip.png

--
End of file - 10965 bytes

I previously deleted r3,02 help ,o2 ie help,04 aol demo,09 extra buttx4,09extra tools,016 all,024 desktop comp(n0 name) and the pop ups still showed up so i restored from back up to original as shown above ,what do you think i should delete that may be causing the pop ups .help;

2482.

Solve : Trojan.Smitfraud Variant-Gen/Bensorty?

Answer»

Been having a bit of trouble ridding myself of this. I've run all types of spyware/virus cleaners and it seems to get rid of it, until I reboot. I'm UNABLE to find what is re-installing it. Here are requested logs.

---------------------------------------------------------
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/24/2008 at 11:02 PM

Application Version : 4.23.1006

Core Rules Database Version : 3685
Trace Rules Database Version: 1662

Scan TYPE : Complete Scan
Total Scan Time : 00:29:18

Memory items scanned : 354
Memory threats detected : 0
Registry items scanned : 4708
Registry threats detected : 6
File items scanned : 37695
File threats detected : 0

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}\InprocServer32

Trojan.Smitfraud Variant-Gen/Bensorty
HKLM\Software\Classes\CLSID\{D5BF49A2-94F1-42BD-F434-3604812C807D}
HKCR\CLSID\{D5BF49A2-94F1-42BD-F434-3604812C807D}
HKCR\CLSID\{D5BF49A2-94F1-42BD-F434-3604812C807D}\InProcServer32

---------------------------------------------------------

Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 5.1.2600 Service Pack 3

12/24/2008 11:09:08 PM
mbam-log-2008-12-24 (23-09-08).txt

Scan type: Quick Scan
Objects scanned: 44930
Time elapsed: 3 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

---------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:11:10 PM, on 12/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\Sniper.exe
C:\WINDOWS\System32\svchost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search PAGE = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' MENUITEM: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QUICKTIME Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 3678 bytes

---------------------------------------------------------

Any help would be greatly appreciated. thxSorry for the long wait. We are VERY backed-up right now! If you still require assistance, please post new logs and we'll see what we can do.

2483.

Solve : YEA IT WORKED?

Answer»

I just finished doing all the steps for REMOVING spyware/malware and my computer is free! Thank you for your HELP.

I am now off to read about how to make computer RUN smoother!

If you want, we can help make sure your computer is completely healthy if you POST the logs.Thank you very much! I sincerely APPRECIATE all the help and patience I've been given. You folks are awesome!

I have attached the most recent logs.

[attachment deleted by admin]

2484.

Solve : Re: Trojans, Gadcom.exe SHeur2.GAS csrssc.exe - Please help?

Answer»

I'm trying to run through the STEPS to get rid of this virus but most of the NAMES in my log don't match. I've attached a copy of the log. Which ones am I supposed to check off to get rid of it? Thank you for your help.

[attachment deleted by admin]Sorry for the long wait. We are VERY backed-up RIGHT now! I don't see MUCH in your log. What exactly is your PROBLEM? I don't know what you mean by "most of the names in my log don't match".

2485.

Solve : SHeur2.GAS?

Answer»

my internet is going pretty CRAZY. i keep getting random popups, even when IM not surfing the web, and i get randomley redirected to sites for virus protection software and other things. also, AVG has found a whole slew of viruses, most prominently SHeur2.GAS, which KEEPS coming up as csrssc.exe, as well as a bunh of other trojan horses. spybot wont run, and this virus kept redirecting me to a different page when i tried to download the recommended software. i disabled TDSSserv.sys, and that seemed to fix that problem, so i downloaded and ran all of the scans, and ATTACHED the logs.

[attachment deleted by admin]Sorry for the long wait. We are VERY backed-up right now! If you still require assistance, please post new logs and we'll see what we can do.

2486.

Solve : radz services still on internet explorer?

Answer»

i followed the instructions given in this THREAD after finding a radz virus. i completed it up to the last step. i saw on the AVAST report that radz was ALREADY dealt with. im not sure if it has really been fixed but everytime i open my internet explorer, "Radz Services and Internet Cafe" STILL appears.
and thanks for the help! i didnt know there were pro bono solutions from EXPERTS in the net. wish i had learned this earlier.

[attachment deleted by admin]Sorry for the long wait. We are VERY backed-up right now! Your log still shows an infection, so if you still require assistance, please post new logs and we'll see what we can do.

2487.

Solve : Internet Properties Cookies Reset?

Answer» NEVERMIND, I MANAGED to FIX the PROBLEM myself.
2488.

Solve : removing avg8?

Answer»

Hello
A freind of mine who had tryed to download AVG8 , but thought she had not done it properly,or it had not been installed, then WENT out and bought a new antivirus, and tryed to install that, but it now SAYS that agv8 is already installed.

But it was not in ADD or remove programs, nor was it in all programs, so she had done a SEARCH and found some avg8 files so she had deleted them, but it is still saying that avg8 is installed.
She has a windows xp pro edition

Any ideas on how to completly remove it, i myself have some knowledge of the registry, if you have to go in there, but i do not know why its still saying it is still installed.

Thanks for any of your replys.Download AVG and then Install it. (yes, install it again)
Once installed, restart the computer and run the installer again. However, this time, once you run the installer click Uninstall.

nice one, carbon dudeoxide

worked like a charm.

I did some searching myself, and found that you could delete the avg folder in the registry.
But tryed it your WAY anyway.

thanks again Glad you got it uninstalled.

Do not mess with the registry, especially when you're trying to uninstall something. It's not as simple as it seems.

Oh, one more thing, what are you using for Antivirus now?Quote from: Carbon Dudeoxide on January 02, 2009, 09:19:06 PM



Oh, one more thing, what are you using for Antivirus now?

As i mentioned this was for a freind of mine, who is now using kaspersky, the one you buy that can be installed on three computers.

I Myself, am using nortonQuote
As i mentioned this was for a freind of mine, who is now using kaspersky, the one you buy that can be installed on three computers.
Oh all right.

Quote
I Myself, am using norton
Hmmmm.....Not the best antivirus software out there to say the least....

There are a couple better free alternatives if you're interested.
2489.

Solve : Check out Open DNS VIdeo. Avoid DBS attack!?

Answer»

Instead of a virus inside YOUR computer it may be a DNS atttack!
Here is a nice video. It is EASY to do. Protect yourself from hostile sites. Over 10,00 sites out there that want to feed you false pages. Anti-virus alone is not enough. Make sure the DNS is not contaminated.
Reportedly everybody knows about this and they are going to fix it. Real Soon. So they say. When they get around to it.

Look at the video:

http://www.opendns.com/support/videos/getstarted/

dont dns attacks just slow down your internet?No. It is not a DOS attack. It is an DNS attack.
It is very FAST and you have no idea of what append. It occurs in a fraction of a second, If a hostile site gets the DNS cache from the server, it can send you to a bogus page. Like Google, eBay, or any site that you would know it will put up a clever site that looks just like the real thing. And the address bar has the right address.

About a year ago they were warned about this and nobody would believe it. There is a very tiny hole in the server software that is open to a DNS attack for a fraction of a second. Because it is near impossible to do the attack manually, most IT people could just not believe it. But the DNS attack only needs to HIT the target a few times out of a thousand attempts to rack in money, advertising, credit cards, bank accounts and whatever else.

Of course, the chance of an one person being hurt by it is very slim. Like maybe we don't really need to wear a seat belt while in an AIRPLANE. Right?

2490.

Solve : Spyware Guard 2008 blocking anti-virus software downloads?

Answer»

Scan is running and I reckon about another hour or so to completion (30% in last 25 mins).

Need to go to bed now - UK time is 12.35 a.m.

Will produce log in the morning and post the details.

Hopefully you will be around some time tomorrow to have a look.

Very many thanks for your time today and for all the GREAT guidance in getting me this far down the road to recovery.

I look forward to the next steps and thanks again.

I'll be around so no problem.

See ya....It's a bit addictive this..... Still here and have completed all actions in your instructions. Log file attached. Gonna logout now and get some sleep but will look for next stpes tomorrow. Thanks again:

Kaspersky Log:

KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, January 3, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, January 02, 2009 20:54:46
Records in database: 1549910
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Files scanned: 120299
Threat name: 2
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 01:14:24


File name / Threat name / Threats count
C:\dataInfected: Trojan-Downloader.Win32.IstBar.nh1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\2XGZ01QL\SpywareGuard2008[1].exeInfected: Trojan-Dropper.Win32.Joiner.hp1

The selected area was scanned.


Well that's not bad but it should have already been removed. Have to do it manually now...

Go to My Computer->Tools->Folder Options->View tab:

  • Under the Hidden files and folders heading:
  • Select Show hidden files and folders.
  • Uncheck Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK
.

Now go to the Content.IE5 folder and delete everything in it. It might not let you delete the items from today but that should be OK.

Double click My Computer on your desktop and then open C:\. Keep opening the folders from the file path until you get to the Content.IE5 folder.

C:>WINDOWS>system32>config>systemprofile>Local Settings>Temporary Internet Files>Content.IE5

Empty the Recycle Bin once it's deleted.

Let me know when you get that done.All these steps completed and no problems. Sounds good. As long as everything is running OK now we can finish up.

Use the Secunia Software INSPECTOR to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hi EF. Ran another K scan with one trojan remaining. Should I still follow your last instructions or something else first?

Hope you're well and ever grateful as ever....

K scan log as follows:

KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, January 3, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, January 03, 2009 16:49:04
Records in database: 1554307
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
K:\

Scan statistics:
Files scanned: 121515
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 01:14:59


File name / Threat name / Threats count
C:\dataInfected: Trojan-Downloader.Win32.IstBar.nh1

The selected area was scanned.Delete this folder

C:\data

Also look to see if any of these folders are on the computer, deleting them if found.

C:\Program Files\ISTsvc
C:\Program Files\SideFind
C:\Program Files\YourSiteBar

Then run this tool: http://majorgeeks.com/Symantec_Adware.IstbarTrojan.ISTsvc_Removal_Tool_d4784.html

----------

It's odd that that showed up like that. I think we should run another scan.

This scanner requires Internet Explorer

Scan with the BitDefender Online Scanner
Click I Agree to the license and then install the ActiveX control.
Please DO NOT change the Scanning Options.
That will make your logs huge and we don't need to see clean files.

Select Start Scan to begin.
This scan can TAKE a while so please be patient and let it complete.

Once Bitdefender completes the scan:
Click-on the Detected Problems tab.
Then select Click here to EXPORT the scan report



This will save a file named bdscan.html I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)

You will have to upload the file online. The forums will not accept HTML.

Upload the file to Savefile.com
There is no need to Register
Select Browse and locate the file.
Fill in the Title, Description and security code then click Upload
Copy the link next to Your link to the file: and post the link back here.http://www.savefile.com/files/1953087

Here ye go.....

Haven't opened it but let me know what you think.

Many thanksWell I'm pretty sure everything is gone, at least I hope so.

How is the computer running now?Everything is running really well. Have added all the software you suggested.

Do I also need to load a firewall and more general anti-virus? I keep getting a windows security box saying that I need one. Any last recommendation or do I already have all I need having loaded the "stuff" in your earlier advice?

Your website is a GODSEND and I can't thank you enough for all the excellent, specific and easy to follow guidance you have given to me. It's a huge relief to have this sorted and also to have a high performing computer again.

Live long and prosper!Yes you need to install a good antivirus. Choose one of these that are free. I personally prefer Avast.

Remember to only install one antivirus!

1) Avast! Home Free Edition
2) AVG Free Edition
3) Avira AntiVir Personal
2491.

Solve : THANK YOU!!!!?

Answer»

I was actually kind of embarassed to have to find this site!!! Im normally the one people call when they have a computer issue. I had a narley Vundo virus I was unable to catch for a while *censored* babysitters anywayz!!! But it turned my windows updates off, I could not turn them back on for nothing >< It prevented me from updating my ad aware, AVG was seeing it, but unable to remove it. It got into my system restore and deleted all the checkpoints from before i got the virus. It caused pop-ups EVERY 30 seconds when I would try to use the internet for anything. It made walking through the steps that more frustrating >< It was nasty, I have spent the last week trying to remove it. hours into it I thought i was gonna have to re-do windows Followed the steps, and it was the SUPERantispyware program that finally got rid of it It stored itself on my memory and in my registry's but its gone now, thanx to Evilfantasy's steps (almost sounds like Im in an aa meeting now, lol) Didnt want to just come in here, learn what to do, and bail without saying a word, so THANX!!!! Lots of work and very frustrating, but a good learning expierence anywayz SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/02/2009 at 01:28 PM

Application Version : 4.24.1004

Core Rules Database Version : 3694
Trace Rules Database Version: 1670

Scan type : Complete Scan
Total Scan Time : 01:03:34

Memory items scanned : 408
Memory threats detected : 3
Registry items scanned : 6662
Registry threats detected : 46
File items scanned : 81017
File threats detected : 30

Adware.Vundo/Variant
C:\WINDOWS\SYSTEM32\XHSCQO.DLL
C:\WINDOWS\SYSTEM32\XHSCQO.DLL
C:\WINDOWS\SYSTEM32\CSDEVQ.DLL
C:\WINDOWS\SYSTEM32\QGOTXV.DLL
C:\WINDOWS\SYSTEM32\YAKWNQ.DLL

Trojan.Vundo-Variant/Small
C:\WINDOWS\SYSTEM32\XXYYYYQI.DLL
C:\WINDOWS\SYSTEM32\XXYYYYQI.DLL
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\xxyyyYQI

Trojan.Vundo-Variant/Small-GEN
C:\WINDOWS\SYSTEM32\PMNLMMMD.DLL
C:\WINDOWS\SYSTEM32\PMNLMMMD.DLL


HKU\S-1-5-21-2000478354-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\

Ext\Stats\{CFDD11EC-6332-4B6F-B369-E58CC025F9F4}

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}\InprocServer32
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper

Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{6D794CB4-C7CD-4c6

f-BFDC-9B77AFBDC02C}


HKU\S-1-5-21-2000478354-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\

Ext\Stats\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}
C:\WINDOWS\SYSTEM32\XEFWFMWM.DLL

Trojan.Vundo-Variant/NextGen-Six
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper

Objects\{865c0079-4a6a-473f-93a6-7031c9cc8eb7}
HKCR\CLSID\{865C0079-4A6A-473F-93A6-7031C9CC8EB7}
HKCR\CLSID\{865C0079-4A6A-473F-93A6-7031C9CC8EB7}\InprocServer32
HKCR\CLSID\{865C0079-4A6A-473F-93A6-7031C9CC8EB7}\InprocServer32#ThreadingModel

Trojan.Vundo-Variant/NextGen
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper

Objects\{CFDD11EC-6332-4B6F-B369-E58CC025F9F4}
HKCR\CLSID\{CFDD11EC-6332-4B6F-B369-E58CC025F9F4}
HKCR\CLSID\{CFDD11EC-6332-4B6F-B369-E58CC025F9F4}\InprocServer32
HKCR\CLSID\{CFDD11EC-6332-4B6F-B369-E58CC025F9F4}\InprocServer32#ThreadingModel

Adware.Tracking Cookie
C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
.sonyonlineentertainment.112.2o7.net [ C:\Program

Files\Sony\EverQuest\mozilla\cookies.txt ]
.doubleclick.net [ C:\Program Files\Sony\EverQuest\mozilla\cookies.txt ]
.cgm.adbureau.net [ C:\Program Files\Sony\EverQuest\mozilla\cookies.txt ]
.cgm.adbureau.net [ C:\Program Files\Sony\EverQuest\mozilla\cookies.txt ]
.cgm.adbureau.net [ C:\Program Files\Sony\EverQuest\mozilla\cookies.txt ]
.sonyonlineentertainment.112.2o7.net [ C:\Program Files\Sony\EverQuest

II\mozilla\cookies.txt ]
.cgm.adbureau.net [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.cgm.adbureau.net [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.cgm.adbureau.net [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]

Unclassified.Unknown Origin
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}

Adware.Zango Toolbar/Hb
C:\Documents and Settings\Katie\Application

Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic
C:\Documents and Settings\Katie\Application Data\ZangoToolbar\v3.0\ZangoToolbar
C:\Documents and Settings\Katie\Application Data\ZangoToolbar\v3.0
C:\Documents and Settings\Katie\Application Data\ZangoToolbar\zbar.log
C:\Documents and Settings\Katie\Application Data\ZangoToolbar

Trojan.DNSChanger-Codec
HKU\S-1-5-21-2000478354-1123561945-839522115-1003\Software\GetModule
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iCheck
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iCheck#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iCheck#UninstallString

Adware.AdSponsor/ISM
C:\Program Files\GetModule
C:\Program Files\iCheck\Uninstall.exe
C:\Program Files\iCheck

Adware.Vundo Variant/Rel
HKLM\SOFTWARE\Microsoft\FCOVM
HKLM\SOFTWARE\Microsoft\RemoveRP
HKLM\SOFTWARE\Microsoft\contim
HKLM\SOFTWARE\Microsoft\contim#SysShell
HKLM\SOFTWARE\Microsoft\MS Track System
HKLM\SOFTWARE\Microsoft\MS Track System#Uid
HKLM\SOFTWARE\Microsoft\MS Track System#Shows
HKLM\SOFTWARE\Microsoft\MS Track System#Uqs
HKLM\SOFTWARE\Microsoft\rdfa
HKLM\SOFTWARE\Microsoft\rdfa#F
HKLM\SOFTWARE\Microsoft\rdfa#N

Trojan.Unclassified/C00-WL
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0063DFE
HKLM\SOFTWARE\MICROSOFT\WINDOWS

NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0063DFE#Asynchronous
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0063DFE#DllName
HKLM\SOFTWARE\MICROSOFT\WINDOWS

NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0063DFE#Impersonate
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0063DFE#Startup
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__C0063DFE#Logon

Rogue.Component/Trace
HKLM\Software\Microsoft\6CBC1F30
HKLM\Software\Microsoft\6CBC1F30#6cbc1f30
HKLM\Software\Microsoft\6CBC1F30#Version
HKLM\Software\Microsoft\6CBC1F30#6cbcb2b0
HKLM\Software\Microsoft\6CBC1F30#6cbcdb55
HKU\S-1-5-21-2000478354-1123561945-839522115-1003\Software\Microsoft\CS41275
HKU\S-1-5-21-2000478354-1123561945-839522115-1003\Software\Microsoft\FIAS4018
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:57:42 PM, on 1/2/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running PROCESSES:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\ResChanger 2005\ResChanger2005.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {033D9E79-723E-43C8-B18D-677BB46D0B3E} - C:\WINDOWS\system32\pmnlmmMD.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar NOTIFIER BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: {483e600a-3ebc-88e8-7bc4-c37535ad792b} - {b297da53-573c-4cb7-8e88-cbe3a006e384} - C:\WINDOWS\system32\qgotxv.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [ResChanger 2005] C:\Program Files\ResChanger 2005\ResChanger2005.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [GetModule32] "C:\Program Files\GetModule\GetModule32.exe"
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: D-Link AirPlus.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Resume Beyond Media Installation.lnk = E:\Beyondmedia\Setup.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab53083.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave FLASH Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll qgotxv.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
O24 - Desktop Component 0: (no name) - http://spectraleyes.com/albums/artworx/NAMESTE_HOLO_U.gif

--
End of file - 10352 bytes

2492.

Solve : Trojan, I think it's winloggn.exe??

Answer»
    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    ----------

    Download
ATF Cleaner by Atribune to your Desktop.

Alternate download link

Note: Vista users must use Run As Administrator
  • Under Main: SELECT Files to Delete choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • Click Exit on the Main menu to CLOSE the program.
Note that your system will run slower for a reboot or two after having used this tool so don't panic.

----------

Download OTCleanIt.exe and save it to your Desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
Important: Restart the computer before continuing.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider USING Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's EASY and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Everything seems to be great now, thank you for all the help. Now I know where to go whenever I get stuck on some sort of CRAPPY malware/virus :] Thank you!Your welcome.

Safe surfing...
2493.

Solve : Antiirus 2008 or 2009?

Answer»

A couple of weeks ago I got this virus. I thought I had it REMOVED by using AVG, Malwarebites, Spybot and Adaware. And maybe this problem is not related, but from time to time while on the computer some kind of error occurs. Or what I will CALL an error. The computer will make the "dong" sound just as if you were trying to click out of something that you shouldn't. It does this without my doing ANYTHING. I have no warnings actually come up.
I went through the routine for cleaning virus and malware. I have attached the log files that were requested. Any HELP would be appreciated.
Thanks, JIM

[attachment deleted by admin]

2494.

Solve : I Followed The Directions but....!!!!?

Answer»

Run the Kaspersky Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

  • Click on SCAN NOW
  • Click Accept.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan SETTINGS and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or something similar.
  • In Save as type: click the drop ARROW and select: Text file [*.TXT]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 users: If at any time you have trouble VIEWING the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
2495.

Solve : Computer Hijacked, Can't update software, starting to panic.?

Answer»

My computer has been hijacked. My browser redirects, I can't update anti-virus software and no amount of malware or anti-virus software seems to help.

If anyone can give me some advice on how to save my computer it would be greatly appreciated.

I ran Hijack this and have included the log file.

Help, please!

Logfile of Trend Micro HijackThis v2.0.2
Scan SAVED at 12:42:26 PM, on 1/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet EXPLORER v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Belkin\F5D8053v4\BelkinWCUI.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avwsc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -SCHEDULER
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - Global Startup: Belkin Wireless Networking Utility.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B662D5E-E8AD-42C6-92E1-F1EA6399E697}: NAMESERVER = 85.255.115.34;85.255.112.112
O17 - HKLM\System\CCS\Services\Tcpip\..\{82D279C3-D942-48BD-AEB6-31A75FBD29AD}: NameServer = 85.255.115.34;85.255.112.112
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.34;85.255.112.112
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.34;85.255.112.112
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.34;85.255.112.112
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 6491 bytes

2496.

Solve : Tough Hijacker - can't run Spybot, SAS, or MBAM, and HJT log looks clean?

Answer»

I've got a tough one for you. It's a HIJACKER of some sort, it blocks me from accessing sites like AVG, superantispyware.com, spybot, etc. It also won't let me run Spybot, SAS, MBAM, etc... when I try to run them the computer just processes for a few minutes, and nothing happens, even when I try in Safe Mode.

Other than that, I've run everything as close as possible to the instructions in the sticky post at the top of this forum. I can run AVG and have updated it manually by downloading the defs on my uninfected laptop, and did the same for Adaware, but both scans came out clean.

My HJT log is attached. The "DBRas" and "CONFIDENCE Online" entries are for getting onto my WORK's network from home.

I've TRIED updating HJT to the latest version, and it does not work... it just processes for a minute and does not continue.

I'm running Windows XP Pro, Version 5.1 (Build 2600.xpsp_sp3_gdr.080814-1236 : Service Pack 3)
It's a homebuilt machine, Pentium 4, 3.2Ghz, 1.00 GB of RAM

I've had no hardware problems, and first noticed this problem about two weeks ago.

Edit: AVG reports that I have an adware.secondthought infection. I'm going to try removing it by using the instructions at www.safer-networking.com/removeadwaresecondthought.php I doubt this is my only problem but we'll see. Edit #2: no luck. Still there.

Thanks for your help!

[attachment deleted by admin]I have been having the same problem. I went to the Spybot site and cannot navigate anywhere there. Wanted to E-mail Spybot about the problem, but when I try to click to go to the contact E-mail, get a FAILED connection notification.

2497.

Solve : Browser not working but Internet is?

Answer»

Ok, so 2 nights ago my computer was working fine, I checked the usual stuff before going to bed and turned of my computer.
Well the next morning I turned it on and found out that neigther IE or FF were working, but the BROWSER on Ares was. So I did a spyware check and all of that GOOD stuff, deleted Ares and the browser arent working, but MSN and other online things are.
When I try to use FF it tells me:

Connection Interrupted
the connection to the server was reset while page was loading
the network link was interrupted while negotiating a connection. please try again

So Ive tried several spyware and adware tools and still not working.
Also reset the router, clicked DIAGNOSE connection and it never find anything.
any suggetions? Im USING my regular PC to type this btw.
ThanksWhats the version of your IE?IE6Are you also having this issue in safemode with networking? by the way what type of internet connection do you have?Ok so i just tried in on SAFE mode and it is working like that, same with IE6. hmmmm, oh yeah and I have Cox Cable high speed internet, wired connection to a router.

So, how should I make it work on normal mode and not safe mode only??YEah I Is Having The Same ProblemEven I faced this problems many times.Quote from: Gean Freaks on February 10, 2009, 12:02:48 PM

Are you also having this issue in safemode with networking? by the way what type of internet connection do you have?
well what do u suggest bro?
2498.

Solve : Malware removal logs for followup?

Answer» HI -- First, God bless you for this site! I just went through the malware removal process because of a nasty FAKE virus alert that hijacked my internet, too. All seems well now, but I am posting the LOGS as REQUESTED for review. Thank you so much for your help!



[attachment deleted by admin]
2499.

Solve : A virus that can't be detected by an anti vi and its hiding your files?

Answer»

the question is how do i get rid of it?
pls helpBackup spur data if you can.
Prepare for a full install. This can be done in 3 to 6 hours.
Trying to fix a bad virus can TAKE two or three days of work.
Your choice.
Quote from: Geek-9pm on FEBRUARY 10, 2009, 11:51:18 PM

Backup spur data if you can.
Prepare for a full install. This can be done in 3 to 6 hours.
Trying to fix a bad virus can take two or three days of work.
Your choice.


or 20-30 minutes with rootkit REVEALER and RECOVERY console...

Assuming one knows what they are doing, of course.

beladona- could you follow the steps here

and post your logs in this thread? Our malware experts are good at what they do, even when dealing with ROOTKITS.
2500.

Solve : Internet Security. A Waste of Money??

Answer»

Internet Security. A Waste of Money?
Now if I took that position, Whould you agree?

Look here:
CODE: [Select]The U.S. federal government is accelerating its efforts to SECURE the
Internet's routing system, with plans this year for the Department of
Homeland Security to quadruple its investment in research aimed at adding
digital signatures to router communications
The blurb is from a reliable source in the internet. Rather that give a link,
I would invite you to do your own research. Or just make a comment without any research.

In view of the present economical problems, would this not be
a big waste of money?

The Internet is already as safe as it will ever be.
Do you agree?
Digital Signatures never worked for ActiveX... Don't see how you would add digital signatures to a router system anyway.


And besides, the internet is a Global network, and as much as the U.S likes to think otherwise they have no jurisdiction as to the network infrastructure of other countries, so it would just be a waste of money. Unless of course they are actually TAPPING into the internet infrastructure for "big brother" monitoring... but that's another story altogether they will catch and trace heap of people for doing heaps of stuff. its probably a good idea. but some one will hack it. they hack every thing. so yeah it will work but if you really wont to there always a way. a hacker never quits it just increases the FUN. Yep. If they make the internet safer, the crooks will go back to breaking and ENTERING our homes. In some cities apartment houses already look like jails. All the iron bars and gates.