InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 2701. |
Solve : Virus or malware. logs included? |
|
Answer» I have avast but downloaded a movie or SOMETHING, saw a quick dos program load and now my security center says my virus protection is not found.
Open the SDFix folder and double click RunThis.bat to start the script.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:38:58 AM, on 12/16/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\XSoft\xworking\sysrts.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\HP\HP Software Update\HPWuSchd.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [winxld] C:\Program Files\XSoft\xworking\xld.exe a O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Max\Application Data\mjusbsp\cdloader2.exe" MAGICJACK O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Login Service (SystemLoginService) - Unknown owner - C:\Program Files\XSoft\xworking\sysrts.exe -- End of file - 6617 bytes SDFix: Version 1.240 Run by Max on Mon 12/15/2008 at 09:20 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : No Trojan Files Found Uninstall XsoftSpy or XpcSpy. This is not a trusted program. Download Malwarebytes' Anti-Malware (MBAM)
---------- Download ComboFix© by sUBs from one of the below links. Be sure TOP save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. For Windows XP Systems install the Recovery Console: - If you are using Windows XP and do not already have the Recovery Console installed, please ensure your Internet connection is active (if possible) and click Yes. - If for some reason your Internet is not working click No. - If you are not using Windows XP, you will not be prompted. - When prompted to accept the EULA click OK. - Accept Microsoft's EULA (Click Yes). - When you are told that the RC is installed correctly click YES to continue scanning for malware. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. ---------- Next post add: MBAM log ComboFix logThank you they are.... Malwarebytes' Anti-Malware 1.31 Database version: 1499 Windows 5.1.2600 Service Pack 3 12/16/2008 5:52:24 PM mbam-log-2008-12-16 (17-52-24).txt Scan type: Quick Scan Objects scanned: 60377 Time elapsed: 24 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) it wouldnt fit in one post so I had to make a few: ComboFix 08-12-16.03 - Max 2008-12-16 18:04:58.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.672 [GMT -7:00] Running from: c:\documents and settings\Max\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\_004064_.tmp.dll c:\windows\system32\_004065_.tmp.dll c:\windows\system32\_004066_.tmp.dll c:\windows\system32\_004067_.tmp.dll c:\windows\system32\_004074_.tmp.dll c:\windows\system32\_004075_.tmp.dll c:\windows\system32\_004076_.tmp.dll c:\windows\system32\_004077_.tmp.dll c:\windows\system32\_004079_.tmp.dll c:\windows\system32\_004080_.tmp.dll c:\windows\system32\_004083_.tmp.dll c:\windows\system32\_004084_.tmp.dll c:\windows\system32\_004086_.tmp.dll c:\windows\system32\_004087_.tmp.dll c:\windows\system32\_004088_.tmp.dll c:\windows\system32\_004090_.tmp.dll c:\windows\system32\_004093_.tmp.dll c:\windows\system32\_004094_.tmp.dll c:\windows\system32\_004098_.tmp.dll c:\windows\system32\_004099_.tmp.dll c:\windows\system32\_004101_.tmp.dll c:\windows\system32\_004104_.tmp.dll c:\windows\system32\_004106_.tmp.dll c:\windows\system32\_004107_.tmp.dll c:\windows\system32\_004108_.tmp.dll c:\windows\system32\_004109_.tmp.dll c:\windows\system32\_004110_.tmp.dll c:\windows\system32\_004113_.tmp.dll c:\windows\system32\_004114_.tmp.dll c:\windows\system32\_004115_.tmp.dll c:\windows\system32\_004116_.tmp.dll c:\windows\system32\_004117_.tmp.dll c:\windows\system32\_004122_.tmp.dll c:\windows\system32\_004124_.tmp.dll c:\windows\system32\hpvaut32.dll c:\windows\system32\hpvcp70.dll c:\windows\system32\hpvcr70.dll . ((((((((((((((((((((((((( Files Created from 2008-11-17 to 2008-12-17 ))))))))))))))))))))))))))))))) . 2008-12-15 21:18 . 2008-12-15 21:18577,024--a--c---c:\windows\system32\dllcache\user32.dll 2008-12-15 21:15 . 2008-12-15 21:16d--------c:\windows\ERUNT 2008-12-15 21:12 . 2008-12-15 21:12d--------c:\documents and settings\Administrator 2008-12-15 20:29 . 2008-12-15 22:39d--------C:\SDFix 2008-12-15 07:06 . 2008-12-16 17:21d--------c:\documents and settings\Rachel 2008-12-14 19:34 . 2008-12-14 19:34d--------c:\documents and settings\All Users\Application Data\Office Genuine Advantage 2008-12-14 13:29 . 2008-12-14 13:29d--------c:\program files\Common Files\Wise Installation Wizard 2008-12-14 13:23 . 2008-12-14 13:23d--------c:\program files\CCleaner 2008-12-14 05:58 . 2008-12-14 05:58d--------c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2008-12-14 05:57 . 2008-12-14 13:30d--------c:\program files\SUPERAntiSpyware 2008-12-14 05:57 . 2008-12-14 13:30d--------c:\documents and settings\Max\Application Data\SUPERAntiSpyware.com 2008-12-14 05:53 . 2008-12-14 05:53d--------c:\program files\Trend Micro 2008-12-14 05:47 . 2008-12-15 00:16d--------c:\program files\Spybot - Search & Destroy 2008-12-14 05:47 . 2008-12-15 00:16d--------c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2008-12-14 05:31 . 2008-12-14 05:31d--------c:\documents and settings\Max\Application Data\Malwarebytes 2008-12-14 05:31 . 2008-12-03 19:5238,496--a------c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-14 05:31 . 2008-12-03 19:5215,504--a------c:\windows\system32\drivers\mbam.sys 2008-12-14 05:30 . 2008-12-14 05:31d--------c:\program files\Malwarebytes' Anti-Malware 2008-12-14 05:30 . 2008-12-14 05:30d--------c:\documents and settings\All Users\Application Data\Malwarebytes 2008-12-13 20:11 . 2008-04-13 17:12159,232--a------c:\windows\system32\ptpusd.dll 2008-12-13 20:11 . 2001-08-17 22:365,632--a------c:\windows\system32\ptpusb.dll 2008-12-13 19:51 . 2008-10-16 14:06268,648--a------c:\windows\system32\mucltui.dll 2008-12-13 19:51 . 2008-10-16 14:06208,744--a------c:\windows\system32\muweb.dll 2008-12-13 19:51 . 2008-10-16 14:0627,496--a------c:\windows\system32\mucltui.dll.mui 2008-12-13 11:36 . 2008-12-15 07:0369--a------c:\windows\NeroDigital.ini 2008-12-12 18:39 . 2008-12-15 07:01d--------c:\documents and settings\Max\Application Data\mjusbsp 2008-12-12 18:38 . 2008-04-13 11:4560,032--a------c:\windows\system32\drivers\USBAUDIO.sys 2008-12-12 18:38 . 2008-04-13 11:4560,032--a--c---c:\windows\system32\dllcache\usbaudio.sys 2008-12-09 20:19 . 2008-12-09 20:47d--------c:\documents and settings\Max\Application Data\Download Manager 2008-12-08 06:30 . 2008-12-16 17:193,400--a------c:\windows\system32\winxtm.dll 2008-12-07 15:35 . 2000-05-22 06:00647,872--a------c:\windows\system32\mscomct2.ocx 2008-12-07 15:35 . 2004-03-09 00:00224,016--a------c:\windows\system32\tabctl32.ocx 2008-12-07 15:35 . 2004-03-09 16:45152,848--a------c:\windows\system32\Comdlg32.ocx 2008-12-07 15:34 . 2008-12-07 15:34d--------c:\program files\AML Products 2008-12-06 22:26 . 2008-09-17 23:55201,050--a------c:\windows\system32\nvapps.nvb 2008-12-06 22:25 . 2008-12-07 02:17d--------c:\windows\NV1364152.TMP 2008-12-06 21:50 . 2008-12-06 21:51d--------c:\documents and settings\Guest 2008-12-06 20:38 . 2008-12-06 20:38d--------c:\documents and settings\Max\LocalLow 2008-12-06 20:38 . 2008-12-06 20:38d--------c:\documents and settings\All Users\Application Data\TVU Networks 2008-12-06 20:17 . 2008-12-06 22:02d--------c:\program files\WMCap 2008-12-06 18:36 . 2008-12-06 19:51d--------C:\downloads 2008-12-06 18:36 . 2008-12-06 20:11d--------c:\documents and settings\Max\Application Data\Orbit 2008-12-06 18:36 . 2008-12-06 18:36d--------c:\documents and settings\Max\Application Data\GrabPro 2008-12-06 14:42 . 2008-12-06 14:42d--h-----c:\windows\PIF 2008-12-06 12:14 . 2008-12-06 12:14d--------c:\documents and settings\Max\Application Data\Apple Computer 2008-12-06 12:10 . 2008-12-06 12:11d--------c:\program files\QuickTime 2008-12-06 12:10 . 2008-12-06 12:13d--------c:\documents and settings\All Users\Application Data\Apple Computer 2008-12-06 12:08 . 2008-12-06 12:09d--------c:\program files\Apple Software Update 2008-12-06 12:08 . 2008-12-06 12:08d--------c:\documents and settings\All Users\Application Data\Apple 2008-12-06 09:10 . 2004-02-25 23:1851,056-ra------c:\windows\system32\drivers\hpzid412.sys 2008-12-06 09:10 . 2004-02-25 23:1816,496-ra------c:\windows\system32\drivers\HPZipr12.sys 2008-12-06 09:09 . 2004-02-25 23:1821,488-ra------c:\windows\system32\drivers\HPZius12.sys 2008-12-06 09:09 . 2008-04-13 11:4515,104--a------c:\windows\system32\drivers\usbscan.sys 2008-12-06 09:09 . 2008-04-13 11:4515,104--a--c---c:\windows\system32\dllcache\usbscan.sys 2008-12-06 09:04 . 2003-12-11 11:1544,544-ra------c:\windows\system32\MSXML4a.dll 2008-12-06 09:03 . 2008-12-06 09:03d--------c:\program files\Common Files\Hewlett-Packard 2008-12-06 08:56 . 2008-12-06 08:56d--------c:\program files\Common Files\HP 2008-12-06 08:53 . 2008-12-06 08:55d--------c:\windows\system32\URTTemp 2008-12-06 08:47 . 2008-12-06 09:04d--------c:\program files\HP 2008-12-06 08:46 . 2004-02-25 23:1738,868---------c:\windows\hpomdl03.dat 2008-12-06 08:46 . 2008-12-06 09:1229,358--a------c:\windows\hpoins03.dat 2008-12-05 20:10 . 2008-12-14 13:27d--------c:\documents and settings\Max\Application Data\U3 2008-12-05 19:29 . 2008-12-05 19:29d--------c:\documents and settings\All Users\Application Data\FLEXnet 2008-12-05 19:24 . 2008-12-05 19:24d--------c:\documents and settings\Max\Application Data\Yahoo! 2008-12-05 19:24 . 2008-12-06 04:47d--------c:\documents and settings\All Users\Application Data\Yahoo! Companion 2008-12-05 19:23 . 2008-12-05 19:24d--------c:\program files\Yahoo! 2008-12-05 19:23 . 2008-12-05 19:25d--------c:\documents and settings\All Users\Application Data\Yahoo! 2008-12-05 19:21 . 2008-12-05 19:21d--------c:\program files\Adobe Media Player 2008-12-05 19:17 . 2008-12-05 19:17d--------c:\program files\Common Files\Adobe AIR 2008-12-05 19:15 . 2008-12-05 19:15d--------c:\program files\Common Files\Macrovision Shared 2008-12-05 19:11 . 2006-10-26 19:5632,592--a------c:\windows\system32\msonpmon.dll 2008-12-05 19:09 . 2008-12-05 19:09d--------c:\program files\MSBuild 2008-12-05 19:09 . 2008-12-05 19:09d--------c:\program files\Microsoft Works 2008-12-05 19:06 . 2008-12-05 19:09d--------c:\windows\SHELLNEW 2008-12-05 19:05 . 2008-12-05 19:11d--------c:\documents and settings\All Users\Application Data\Microsoft Help 2008-12-05 19:03 . 2008-12-05 21:20d--------c:\documents and settings\Max\Application Data\Ahead 2008-12-05 19:02 . 2008-12-05 19:02d--------c:\documents and settings\All Users\Application Data\Ahead 2008-12-05 19:01 . 2008-12-05 19:01d--------c:\program files\Nero 2008-12-05 19:01 . 2008-12-05 19:02d--------c:\program files\Common Files\Ahead 2008-12-05 19:01 . 2008-12-05 19:01d--------c:\documents and settings\All Users\Application Data\Nero 2008-12-05 18:48 . 2008-12-05 18:48dr-h-----C:\MSOCache 2008-12-05 18:38 . 2008-12-05 18:38d--------c:\program files\Windows Media Connect 2 2008-12-05 18:37 . 2008-12-05 18:37d--------C:\61bfea5f06dbd9346e53 2008-12-05 18:36 . 2008-12-05 18:36d--------c:\windows\system32\LogFiles 2008-12-05 18:36 . 2008-12-05 18:37d--------c:\windows\system32\drivers\UMDF 2008-12-05 18:20 . 2008-12-05 18:20d--------c:\program files\uTorrent 2008-12-05 18:20 . 2008-12-16 17:31d--------c:\documents and settings\Max\Application Data\uTorrent 2008-12-05 17:45 . 2008-12-05 17:45d--------c:\documents and settings\Max\Application Data\AdobeUM 2008-12-05 17:37 . 2008-12-05 17:37d--------c:\windows\system32\scripting 2008-12-05 17:37 . 2008-12-05 17:37d--------c:\windows\system32\en 2008-12-05 17:37 . 2008-12-05 17:37d--------c:\windows\system32\bits 2008-12-05 17:37 . 2008-12-05 17:37d--------c:\windows\l2schemas 2008-12-05 17:35 . 2008-12-05 17:37d--------c:\windows\ServicePackFiles 2008-12-05 17:30 . 2008-12-05 17:30d--------c:\windows\EHome 2008-12-05 17:26 . 2008-12-05 17:2613,646--a------c:\windows\system32\wpa.bak 2008-12-05 17:24 . 2008-12-05 17:24d--------c:\windows\system32\Lang 2008-12-05 17:24 . 2008-12-05 17:24940,794--a------c:\windows\system32\LoopyMusic.wav 2008-12-05 17:24 . 2008-12-05 17:24146,650--a------c:\windows\system32\BuzzingBee.wav 2008-12-05 10:48 . 2008-10-03 10:416,066,176-----c---c:\windows\system32\dllcache\ieframe.dll 2008-12-05 10:48 . 2007-04-17 02:322,455,488-----c---c:\windows\system32\dllcache\ieapfltr.dat 2008-12-05 10:48 . 2007-03-07 22:10991,232-----c---c:\windows\system32\dllcache\ieframe.dll.mui 2008-12-05 10:48 . 2008-08-26 00:24459,264-----c---c:\windows\system32\dllcache\msfeeds.dll 2008-12-05 10:48 . 2008-08-26 00:24383,488-----c---c:\windows\system32\dllcache\ieapfltr.dll 2008-12-05 10:48 . 2008-08-26 00:24267,776-----c---c:\windows\system32\dllcache\iertutil.dll 2008-12-05 10:48 . 2008-08-26 00:2463,488-----c---c:\windows\system32\dllcache\icardie.dll 2008-12-05 10:48 . 2008-08-26 00:2452,224-----c---c:\windows\system32\dllcache\msfeedsbs.dll 2008-12-05 10:48 . 2008-08-25 01:3813,824-----c---c:\windows\system32\dllcache\ieudinit.exe 2008-12-05 10:40 . 2008-12-05 10:400--a------c:\windows\nsreg.dat 2008-12-05 10:37 . 2008-12-05 10:37d--------c:\program files\Alwil Software 2008-12-05 10:33 . 2008-12-05 10:33d--hs----c:\documents and settings\Max\UserData 2008-12-05 10:32 . 2008-08-14 03:112,189,184-----c---c:\windows\system32\dllcache\ntoskrnl.exe 2008-12-05 10:32 . 2008-08-14 03:092,145,280-----c---c:\windows\system32\dllcache\ntkrnlmp.exe 2008-12-05 10:32 . 2008-08-14 02:332,066,048-----c---c:\windows\system32\dllcache\ntkrnlpa.exe 2008-12-05 10:32 . 2008-08-14 02:332,023,936-----c---c:\windows\system32\dllcache\ntkrpamp.exe 2008-12-05 10:32 . 2008-09-15 05:121,846,400-----c---c:\windows\system32\dllcache\win32k.sys 2008-12-05 10:32 . 2008-10-24 04:21455,296-----c---c:\windows\system32\dllcache\mrxsmb.sys 2008-12-05 10:32 . 2008-09-08 03:41333,824-----c---c:\windows\system32\dllcache\srv.sys 2008-12-05 10:32 . 2008-06-13 04:05272,128---------c:\windows\system32\drivers\bthport.sys 2008-12-05 10:32 . 2008-06-13 04:05272,128-----c---c:\windows\system32\dllcache\bthport.sys 2008-12-05 10:32 . 2008-05-08 07:02203,136-----c---c:\windows\system32\dllcache\rmcast.sys 2008-12-05 10:32 . 2008-08-14 03:04138,496-----c---c:\windows\system32\dllcache\afd.sys 2008-12-05 10:31 . 2008-12-05 10:49d--h-----c:\windows\$hf_mig$ 2008-12-05 10:31 . 2008-09-04 10:151,106,944--a------c:\windows\system32\SET1375.tmp 2008-12-05 10:31 . 2008-04-11 12:04691,712-----c---c:\windows\system32\dllcache\inetcomm.dll 2008-12-05 10:31 . 2008-10-15 09:34337,408---------c:\windows\system32\SET1397.tmp . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-05 16:59---------d-----wc:\program files\microsoft frontpage 2008-10-24 11:21455,296----a-wc:\windows\system32\drivers\mrxsmb.sys 2008-10-16 21:13202,776----a-wc:\windows\system32\wuweb.dll 2008-10-16 21:131,809,944----a-wc:\windows\system32\wuaueng.dll 2008-10-16 21:12561,688----a-wc:\windows\system32\wuapi.dll 2008-10-16 21:12323,608----a-wc:\windows\system32\wucltui.dll 2008-10-16 21:0992,696----a-wc:\windows\system32\cdm.dll 2008-10-16 21:0951,224----a-wc:\windows\system32\wuauclt.exe 2008-10-16 21:0943,544----a-wc:\windows\system32\wups2.dll 2008-10-16 21:0834,328----a-wc:\windows\system32\wups.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}] 2008-07-28 03:47160496--a------c:\progra~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872] "cdloader"="c:\documents and settings\Max\Application Data\mjusbsp\cdloader2.exe" [2008-08-22 50520] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152] "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016] "SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-09-05 c:\windows\RTHDCPL.exe] "nwiz"="nwiz.exe" [2008-09-17 c:\windows\system32\nwiz.exe] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Documents and Settings\\Max\\Application Data\\mjusbsp\\magicJack.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5353:TCP"= 5353:TCP:Adobe CSI CS4 R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-05 111184] R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944] R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-05 20560] S3 RTRSys;RTRSys;\??\c:\program files\XSoft\xworking\rsrsys.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{100bdf6f-c338-11dd-947f-00508dc3ce1f}] \Shell\AutoRun\command - G:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25766375-c2b0-11dd-b39d-806d6172696f}] \Shell\AutoRun\command - D:\autorun.exe \Shell\phone\command - D:\autorun.exe *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder 2008-12-11 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 13:42] . - - - - ORPHANS REMOVED - - - - HKLM-Run-winxld - c:\program files\XSoft\xworking\xld.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ mStart Page = hxxp://www.yahoo.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 c:\windows\Downloaded Program Files\Manager.exe - c:\windows\Downloaded Program Files\DownloadManagerV2.ocx O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab c:\windows\Downloaded Program Files\DownloadManagerV2.inf FF - ProfilePath - c:\documents and settings\Max\Application Data\Mozilla\Firefox\Profiles\rs7cm6er.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - plugin: c:\documents and settings\Max\Application Data\Mozilla\Firefox\Profiles\rs7cm6er.default\extensions\[emailprotected]\plugins\npTVUAx.dll FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-16 18:07:01 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** .--------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(740) c:\program files\SUPERAntiSpyware\SASWINLO.dll . Completion time: 2008-12-16 18:08:13 ComboFix-quarantined-files.txt 2008-12-17 01:08:03 Pre-Run: 100,729,114,624 bytes free Post-Run: 100,737,097,728 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect 279--- E O F ---2008-12-06 00:41:27 Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Folder:: c:\program files\XSoft File:: c:\windows\NV1364152.TMP c:\windows\system32\SET1375.tmp c:\windows\system32\SET1397.tmp Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25766375-c2b0-11dd-b39d-806d6172696f}] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeThanks again ComboFix 08-12-16.03 - Max 2008-12-17 18:02:04.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.212 [GMT -7:00] Running from: c:\documents and settings\Max\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Max\Desktop\CFScript.txt FILE :: c:\windows\NV1364152.TMP c:\windows\system32\SET1375.tmp c:\windows\system32\SET1397.tmp . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\a.exe c:\windows\system32\hpvaut32.dll c:\windows\system32\hpvcp70.dll c:\windows\system32\hpvcr70.dll c:\windows\system32\SET1375.tmp c:\windows\system32\SET1397.tmp . ((((((((((((((((((((((((( Files Created from 2008-11-18 to 2008-12-18 ))))))))))))))))))))))))))))))) . 2008-12-17 17:58 . 2008-12-17 17:59d--------C:\32788R22FWJFW 2008-12-17 17:54 . 2008-12-17 17:54d--------c:\program files\AC3Filter 2008-12-17 17:54 . 2008-07-09 01:05421,888--a------c:\windows\system32\ac3filter.acm 2008-12-17 06:26 . 2008-12-17 06:26d--------c:\documents and settings\Rachel\Application Data\Yahoo! 2008-12-15 21:18 . 2008-12-15 21:18577,024--a--c---c:\windows\system32\dllcache\user32.dll 2008-12-15 21:15 . 2008-12-15 21:16d--------c:\windows\ERUNT 2008-12-15 21:12 . 2008-12-15 21:12d--------c:\documents and settings\Administrator 2008-12-15 20:29 . 2008-12-15 22:39d--------C:\SDFix 2008-12-15 07:06 . 2008-12-17 06:30d--------c:\documents and settings\Rachel 2008-12-14 19:34 . 2008-12-14 19:34d--------c:\documents and settings\All Users\Application Data\Office Genuine Advantage 2008-12-14 13:29 . 2008-12-14 13:29d--------c:\program files\Common Files\Wise Installation Wizard 2008-12-14 13:23 . 2008-12-14 13:23d--------c:\program files\CCleaner 2008-12-14 05:58 . 2008-12-14 05:58d--------c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2008-12-14 05:57 . 2008-12-14 13:30d--------c:\program files\SUPERAntiSpyware 2008-12-14 05:57 . 2008-12-14 13:30d--------c:\documents and settings\Max\Application Data\SUPERAntiSpyware.com 2008-12-14 05:53 . 2008-12-14 05:53d--------c:\program files\Trend Micro 2008-12-14 05:47 . 2008-12-15 00:16d--------c:\program files\Spybot - Search & Destroy 2008-12-14 05:47 . 2008-12-15 00:16d--------c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2008-12-14 05:31 . 2008-12-14 05:31d--------c:\documents and settings\Max\Application Data\Malwarebytes 2008-12-14 05:31 . 2008-12-03 19:5238,496--a------c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-14 05:31 . 2008-12-03 19:5215,504--a------c:\windows\system32\drivers\mbam.sys 2008-12-14 05:30 . 2008-12-14 05:31d--------c:\program files\Malwarebytes' Anti-Malware 2008-12-14 05:30 . 2008-12-14 05:30d--------c:\documents and settings\All Users\Application Data\Malwarebytes 2008-12-13 20:11 . 2008-04-13 17:12159,232--a------c:\windows\system32\ptpusd.dll 2008-12-13 20:11 . 2001-08-17 22:365,632--a------c:\windows\system32\ptpusb.dll 2008-12-13 19:51 . 2008-10-16 14:06268,648--a------c:\windows\system32\mucltui.dll 2008-12-13 19:51 . 2008-10-16 14:06208,744--a------c:\windows\system32\muweb.dll 2008-12-13 19:51 . 2008-10-16 14:0627,496--a------c:\windows\system32\mucltui.dll.mui 2008-12-13 11:36 . 2008-12-17 17:5869--a------c:\windows\NeroDigital.ini 2008-12-12 18:39 . 2008-12-15 07:01d--------c:\documents and settings\Max\Application Data\mjusbsp 2008-12-12 18:38 . 2008-04-13 11:4560,032--a------c:\windows\system32\drivers\USBAUDIO.sys 2008-12-12 18:38 . 2008-04-13 11:4560,032--a--c---c:\windows\system32\dllcache\usbaudio.sys 2008-12-09 20:19 . 2008-12-09 20:47d--------c:\documents and settings\Max\Application Data\Download Manager 2008-12-08 06:30 . 2008-12-16 17:193,400--a------c:\windows\system32\winxtm.dll 2008-12-07 15:35 . 2000-05-22 06:00647,872--a------c:\windows\system32\mscomct2.ocx 2008-12-07 15:35 . 2004-03-09 00:00224,016--a------c:\windows\system32\tabctl32.ocx 2008-12-07 15:35 . 2004-03-09 16:45152,848--a------c:\windows\system32\Comdlg32.ocx 2008-12-07 15:34 . 2008-12-07 15:34d--------c:\program files\AML Products 2008-12-06 22:26 . 2008-09-17 23:55201,050--a------c:\windows\system32\nvapps.nvb 2008-12-06 22:25 . 2008-12-07 02:17d--------c:\windows\NV1364152.TMP 2008-12-06 21:50 . 2008-12-06 21:51d--------c:\documents and settings\Guest 2008-12-06 20:38 . 2008-12-06 20:38d--------c:\documents and settings\Max\LocalLow 2008-12-06 20:38 . 2008-12-06 20:38d--------c:\documents and settings\All Users\Application Data\TVU Networks 2008-12-06 20:17 . 2008-12-06 22:02d--------c:\program files\WMCap 2008-12-06 18:36 . 2008-12-06 19:51d--------C:\downloads 2008-12-06 18:36 . 2008-12-06 20:11d--------c:\documents and settings\Max\Application Data\Orbit 2008-12-06 18:36 . 2008-12-06 18:36d--------c:\documents and settings\Max\Application Data\GrabPro 2008-12-06 14:42 . 2008-12-06 14:42d--h-----c:\windows\PIF 2008-12-06 12:14 . 2008-12-06 12:14d--------c:\documents and settings\Max\Application Data\Apple Computer 2008-12-06 12:10 . 2008-12-06 12:11d--------c:\program files\QuickTime 2008-12-06 12:10 . 2008-12-06 12:13d--------c:\documents and settings\All Users\Application Data\Apple Computer 2008-12-06 12:08 . 2008-12-06 12:09d--------c:\program files\Apple Software Update 2008-12-06 12:08 . 2008-12-06 12:08d--------c:\documents and settings\All Users\Application Data\Apple 2008-12-06 09:10 . 2004-02-25 23:1851,056-ra------c:\windows\system32\drivers\hpzid412.sys 2008-12-06 09:10 . 2004-02-25 23:1816,496-ra------c:\windows\system32\drivers\HPZipr12.sys 2008-12-06 09:09 . 2004-02-25 23:1821,488-ra------c:\windows\system32\drivers\HPZius12.sys 2008-12-06 09:09 . 2008-04-13 11:4515,104--a------c:\windows\system32\drivers\usbscan.sys 2008-12-06 09:09 . 2008-04-13 11:4515,104--a--c---c:\windows\system32\dllcache\usbscan.sys 2008-12-06 09:04 . 2003-12-11 11:1544,544-ra------c:\windows\system32\MSXML4a.dll 2008-12-06 09:03 . 2008-12-06 09:03d--------c:\program files\Common Files\Hewlett-Packard 2008-12-06 08:56 . 2008-12-06 08:56d--------c:\program files\Common Files\HP 2008-12-06 08:53 . 2008-12-06 08:55d--------c:\windows\system32\URTTemp 2008-12-06 08:47 . 2008-12-06 09:04d--------c:\program files\HP 2008-12-06 08:46 . 2004-02-25 23:1738,868---------c:\windows\hpomdl03.dat 2008-12-06 08:46 . 2008-12-06 09:1229,358--a------c:\windows\hpoins03.dat 2008-12-05 20:10 . 2008-12-14 13:27d--------c:\documents and settings\Max\Application Data\U3 2008-12-05 19:29 . 2008-12-05 19:29d--------c:\documents and settings\All Users\Application Data\FLEXnet 2008-12-05 19:24 . 2008-12-05 19:24d--------c:\documents and settings\Max\Application Data\Yahoo! 2008-12-05 19:24 . 2008-12-06 04:47d--------c:\documents and settings\All Users\Application Data\Yahoo! Companion 2008-12-05 19:23 . 2008-12-05 19:24d--------c:\program files\Yahoo! 2008-12-05 19:23 . 2008-12-05 19:25d--------c:\documents and settings\All Users\Application Data\Yahoo! 2008-12-05 19:21 . 2008-12-05 19:21d--------c:\program files\Adobe Media Player 2008-12-05 19:17 . 2008-12-05 19:17d--------c:\program files\Common Files\Adobe AIR 2008-12-05 19:15 . 2008-12-05 19:15d--------c:\program files\Common Files\Macrovision Shared 2008-12-05 19:11 . 2006-10-26 19:5632,592--a------c:\windows\system32\msonpmon.dll 2008-12-05 19:09 . 2008-12-05 19:09d--------c:\program files\MSBuild 2008-12-05 19:09 . 2008-12-05 19:09d--------c:\program files\Microsoft Works 2008-12-05 19:06 . 2008-12-05 19:09d--------c:\windows\SHELLNEW 2008-12-05 19:05 . 2008-12-05 19:11d--------c:\documents and settings\All Users\Application Data\Microsoft Help 2008-12-05 19:03 . 2008-12-05 21:20d--------c:\documents and settings\Max\Application Data\Ahead 2008-12-05 19:02 . 2008-12-05 19:02d--------c:\documents and settings\All Users\Application Data\Ahead 2008-12-05 19:01 . 2008-12-05 19:01d--------c:\program files\Nero 2008-12-05 19:01 . 2008-12-05 19:02d--------c:\program files\Common Files\Ahead 2008-12-05 19:01 . 2008-12-05 19:01d--------c:\documents and settings\All Users\Application Data\Nero 2008-12-05 18:48 . 2008-12-05 18:48dr-h-----C:\MSOCache 2008-12-05 18:38 . 2008-12-05 18:38d--------c:\program files\Windows Media Connect 2 2008-12-05 18:37 . 2008-12-05 18:37d--------C:\61bfea5f06dbd9346e53 2008-12-05 18:36 . 2008-12-05 18:36d--------c:\windows\system32\LogFiles 2008-12-05 18:36 . 2008-12-05 18:37d--------c:\windows\system32\drivers\UMDF 2008-12-05 18:20 . 2008-12-05 18:20d--------c:\program files\uTorrent 2008-12-05 18:20 . 2008-12-17 17:54d--------c:\documents and settings\Max\Application Data\uTorrent 2008-12-05 17:45 . 2008-12-05 17:45d--------c:\documents and settings\Max\Application Data\AdobeUM 2008-12-05 17:37 . 2008-12-05 17:37d--------c:\windows\system32\scripting 2008-12-05 17:37 . 2008-12-05 17:37d--------c:\windows\system32\en 2008-12-05 17:37 . 2008-12-05 17:37d--------c:\windows\system32\bits 2008-12-05 17:37 . 2008-12-05 17:37d--------c:\windows\l2schemas 2008-12-05 17:35 . 2008-12-05 17:37d--------c:\windows\ServicePackFiles 2008-12-05 17:30 . 2008-12-05 17:30d--------c:\windows\EHome 2008-12-05 17:26 . 2008-12-05 17:2613,646--a------c:\windows\system32\wpa.bak 2008-12-05 17:24 . 2008-12-05 17:24d--------c:\windows\system32\Lang 2008-12-05 17:24 . 2008-12-05 17:24940,794--a------c:\windows\system32\LoopyMusic.wav 2008-12-05 17:24 . 2008-12-05 17:24146,650--a------c:\windows\system32\BuzzingBee.wav 2008-12-05 10:48 . 2008-10-03 10:416,066,176-----c---c:\windows\system32\dllcache\ieframe.dll 2008-12-05 10:48 . 2007-04-17 02:322,455,488-----c---c:\windows\system32\dllcache\ieapfltr.dat 2008-12-05 10:48 . 2007-03-07 22:10991,232-----c---c:\windows\system32\dllcache\ieframe.dll.mui 2008-12-05 10:48 . 2008-08-26 00:24459,264-----c---c:\windows\system32\dllcache\msfeeds.dll 2008-12-05 10:48 . 2008-08-26 00:24383,488-----c---c:\windows\system32\dllcache\ieapfltr.dll 2008-12-05 10:48 . 2008-08-26 00:24267,776-----c---c:\windows\system32\dllcache\iertutil.dll 2008-12-05 10:48 . 2008-08-26 00:2463,488-----c---c:\windows\system32\dllcache\icardie.dll 2008-12-05 10:48 . 2008-08-26 00:2452,224-----c---c:\windows\system32\dllcache\msfeedsbs.dll 2008-12-05 10:48 . 2008-08-25 01:3813,824-----c---c:\windows\system32\dllcache\ieudinit.exe 2008-12-05 10:40 . 2008-12-05 10:400--a------c:\windows\nsreg.dat 2008-12-05 10:37 . 2008-12-05 10:37d--------c:\program files\Alwil Software 2008-12-05 10:33 . 2008-12-05 10:33d--hs----c:\documents and settings\Max\UserData 2008-12-05 10:32 . 2008-08-14 03:112,189,184-----c---c:\windows\system32\dllcache\ntoskrnl.exe 2008-12-05 10:32 . 2008-08-14 03:092,145,280-----c---c:\windows\system32\dllcache\ntkrnlmp.exe 2008-12-05 10:32 . 2008-08-14 02:332,066,048-----c---c:\windows\system32\dllcache\ntkrnlpa.exe 2008-12-05 10:32 . 2008-08-14 02:332,023,936-----c---c:\windows\system32\dllcache\ntkrpamp.exe 2008-12-05 10:32 . 2008-09-15 05:121,846,400-----c---c:\windows\system32\dllcache\win32k.sys 2008-12-05 10:32 . 2008-10-24 04:21455,296-----c---c:\windows\system32\dllcache\mrxsmb.sys 2008-12-05 10:32 . 2008-09-08 03:41333,824-----c---c:\windows\system32\dllcache\srv.sys 2008-12-05 10:32 . 2008-06-13 04:05272,128---------c:\windows\system32\drivers\bthport.sys 2008-12-05 10:32 . 2008-06-13 04:05272,128-----c---c:\windows\system32\dllcache\bthport.sys 2008-12-05 10:32 . 2008-05-08 07:02203,136-----c---c:\windows\system32\dllcache\rmcast.sys 2008-12-05 10:32 . 2008-08-14 03:04138,496-----c---c:\windows\system32\dllcache\afd.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-05 16:59---------d-----wc:\program files\microsoft frontpage 2008-10-24 11:21455,296----a-wc:\windows\system32\drivers\mrxsmb.sys . ((((((((((((((((((((((((((((( [emailprotected]_18.07.40.07 ))))))))))))))))))))))))))))))))))))))))) . + 2008-12-18 01:09:0916,384----atwc:\windows\Temp\Perflib_Perfdata_5a8.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}] 2008-07-28 03:47160496--a------c:\progra~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872] "cdloader"="c:\documents and settings\Max\Application Data\mjusbsp\cdloader2.exe" [2008-08-22 50520] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152] "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016] "SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-09-05 c:\windows\RTHDCPL.exe] "nwiz"="nwiz.exe" [2008-09-17 c:\windows\system32\nwiz.exe] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.ac3filter"= ac3filter.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Documents and Settings\\Max\\Application Data\\mjusbsp\\magicJack.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5353:TCP"= 5353:TCP:Adobe CSI CS4 R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-05 111184] R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944] R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-05 20560] S3 RTRSys;RTRSys;\??\c:\program files\XSoft\xworking\rsrsys.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{100bdf6f-c338-11dd-947f-00508dc3ce1f}] \Shell\AutoRun\command - G:\LaunchU3.exe -a . Contents of the 'Scheduled Tasks' folder 2008-12-11 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 13:42] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ mStart Page = hxxp://www.yahoo.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 c:\windows\Downloaded Program Files\Manager.exe - c:\windows\Downloaded Program Files\DownloadManagerV2.ocx O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab c:\windows\Downloaded Program Files\DownloadManagerV2.inf FF - ProfilePath - c:\documents and settings\Max\Application Data\Mozilla\Firefox\Profiles\rs7cm6er.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - plugin: c:\documents and settings\Max\Application Data\Mozilla\Firefox\Profiles\rs7cm6er.default\extensions\[emailprotected]\plugins\npTVUAx.dll FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-17 18:09:52 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\windows\system32\hpvaut32.dll 626960 bytes executable c:\windows\system32\hpvcp70.dll 487424 bytes executable c:\windows\system32\hpvcr70.dll 344064 bytes executable scan completed successfully hidden files: 3 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(748) c:\program files\SUPERAntiSpyware\SASWINLO.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Alwil Software\Avast4\aswUpdSv.exe c:\program files\Alwil Software\Avast4\ashServ.exe c:\windows\system32\nvsvc32.exe c:\program files\Alwil Software\Avast4\ashMaiSv.exe c:\program files\Alwil Software\Avast4\ashWebSv.exe c:\windows\system32\wscntfy.exe c:\windows\system32\rundll32.exe c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe . ************************************************************************** . Completion time: 2008-12-17 18:15:57 - machine was rebooted ComboFix-quarantined-files.txt 2008-12-18 01:15:54 ComboFix2.txt 2008-12-17 01:08:14 Pre-Run: 99,536,203,776 bytes free Post-Run: 99,528,687,616 bytes free 258--- E O F ---2008-12-06 00:41:27
---------- Download Alternate download link Note: Vista users must use Run As Administrator
. ---------- Download OTCleanIt.exe and save it to your Desktop.
---------- How is the computer running now?much, muchbetter Thank you for all your assistance. I can see the virus is gone because the computer recognizes my avast software now. Thanks again.Sounds good. Final suggestions. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't SLOW down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running SMOOTH. |
|
| 2702. |
Solve : Horrible Trojan? |
|
Answer» Good stuff!! Playing with the registry always scares me. Ive been bitten by it a few times in the past and had to do rebuilds as a result. lolProblem solved, apparently it was a permissions issue and they sent me a fix.
---------- Download OTCleanIt.exe and save it to your Desktop.
Important: Restart the computer before continuing. ---------- Delete temporary files Go to:
When prompted select the C: drive and click OK. Check the boxes for:
Click OK or Enter ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and SPAM. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from SPYWARE and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.All finished, thank you again Your welcome. Safe surfing... |
|
| 2703. |
Solve : An unknown trojan is/was in here... am I safe now?? |
|
Answer» Hi all!, and thanks for the help. |
|
| 2704. |
Solve : remove windows association to fumohune.dll? |
|
Answer» Just removed a trojan ans was wondering if there was an easy way to fix the dependeny that WINDOWS has to C:\Windows\System32\fumohune.dll as for I get a RUNDLL alert "Error Loading C:\Windows\System32\Fumohune.dll The specified module could not be found. [ OK ] message.
That took care of it! Dave |
|
| 2705. |
Solve : Blocked from using eBay? |
|
Answer» For a number of months now, I've been totally blocked from accessing eBay. When I type in the URL, it takes a little longer than NORMAL to connect and then I get this message on a totally white screen: "Can't connect to MySQL server on 'lasolarmall.com' (10060)." Lasolarmall appears to be an inactive shopping site, so I have to wonder whether there's any connection to my problem. EBay says to scan with anti-virus software, but won't help beyond that. I've tried all types of anti-virus, anti-spyware scans and nothing SEEMS to work. I checked my host file to see if someone had gotten into that, but only the local host is showing, which I'm TOLD is normal. I sent a message to the owner of the Lasolarmall site to try and get some help, but no response. I tried the company that hosts the site and they give me essentially the same response as eBay. If anyone has any suggestions, they would be much appreciated. Thanks.Download Malwarebytes' Anti-Malware (MBAM)
---------- Please download from DDS by sUBs and save it to your Desktop. Vista users. Right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)
|
|
| 2706. |
Solve : Writing to another persons PC without their knowledge.? |
|
Answer» Hi, Please don't try it on me! Too late! I've added some interesting things to your collection of files but I'm not going to say where, of course! Quote If they can, how would the many convictions stand up where people have been convicted of possessing illegal downloaded images? (Not that I have any, but it is worrying if an innocent person can be framed in such a way). There is such a thing as a 'zombie' computer which is used by a remote user without the owner's consent (or knowledge) but these computers are usually very heavily compromised and probably have very lacking security. And yes, these computers are used to TRANSFER illegal content and in some countries, the law might hold the owner accountable rather than the offender since the offender is very hard to trace in most cases. What you need to make sure of is the following; 1. That you have a hardware firewall which is ENABLED. (Your Internet Service Provider modem may act as a router and a firewall) 2. That you have a software firewall (If you have a hardware firewall, you can use the XP/Vista firewall) 3. That you have an up-to-date virus scanner 4. That you have an up-to-date spyware scanner 5. That you use Firefox rather than Internet Explorer. If you take these points into account and keep your installation of Windows up-to-date with automatic updates. Never open attachments from people you do not trust (Or people you trust unless you -asked- for the attachment) Never use dictionary-word passwords. If you need software for any of the above points, google for these programs; AVG Free (Anti-virus/spyware) Adaware SE (Anti-spyware) Mozilla Firefox (Browser) ZoneAlarm (software firewall) A hardware firewall can only be obtained through purchasing a router although your modem might come with one. Check the documentation or ask your ISP. Here's your homework; http://en.wikipedia.org/wiki/Zombie_computer http://computer.howstuffworks.com/computer-internet-security-channel.htmCheers, It's a bit of a war zone out there on the web! Next we'll be needing bullet proof vests and MILITARY style hard hats.Quote from: Baffled on December 18, 2008, 06:49:16 AM Cheers, It's a bit of a war zone out there on the web! Next we'll be needing bullet proof vests and military style hard hats. We needed those long before the web was invented. I trust that you are STOCKING up on those as well? Come back if you need any help with configuring any security programs. |
|
| 2707. |
Solve : some odd .dll problems? |
|
Answer» hey, i appear to have aquired a virus of some sort but its quite odd compared to what I'm usually used to DEALING with, Norton didn't pick it up and my ad-aware is being silly and not running fully, I did some research on the problem I was having and ended up DOWNLOADING "Security Task Manager" , It found four things potentially dangours in my system so I quarantined them all. |
|
| 2708. |
Solve : Recommended Aint-Virus Program? |
|
Answer» I just bought a new computer and it came with McCafee coverage for 15 months pre-installed. Is this a good Anti-virus program? If not, which program would you recommend for me to get? |
|
| 2709. |
Solve : hit hard by trojan, can't even perform "pre-scans" for forum? |
|
Answer» I'm running legal system:
disabled it. had to reboot twice. on rebooting avg's resident shield found a bunch of infections. I just removed threats. opened firefox to access this forum and resident shield alert came up again. 39 threats, all some sort of trojan horse virus. All detected on open. I can't log the file, i can open paint so here are all the screen caps. then i'll remove threats and then scan the computer. heres the list: http://img361.imageshack.us/img361/1894/logir6.jpg removed threats and avg came back and said specific file not found for each of them. now i'm about to begin scanning.opened avg to do initial scan, got 8 threats. all trojan horses they're either BHO.GQR or Vundo.CQ Vundo.CM Vundo.CS all specific files not found.logs so far. [attachment deleted by admin]more logs. Malwarebytes' Anti-Malware 1.31 Database version: 1515 Windows 5.1.2600 Service Pack 3 12/18/2008 12:46:37 PM mbam-log-2008-12-18 (12-46-37).txt Scan type: Quick Scan Objects scanned: 77919 Time elapsed: 25 minute(s), 55 SECOND(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 18 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e63efb46-c46f-46dc-8cdc-7ecf358f610f} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{e63efb46-c46f-46dc-8cdc-7ecf358f610f} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_id (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_options (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_server1 (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_reserv (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_forms (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_certs (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_options (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_ss (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_pstorage (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_command (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_file (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_idproject (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_pauseopt (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_pausecert (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_deletecookie (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_deletesol (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_patch (Backdoor.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_control_crc (Backdoor.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\spdvnc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\kernel32.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\TDSSixgp.dll (Rootkit.Agent) -> Quarantined and deleted successfully. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:09:43 PM, on 12/18/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\system32\ZuneBusEnum.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe C:\Program Files\InterVideo\Common\Bin\WinRemote.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\HPQ\SHARED\HPQWMI.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Documents and Settings\sandra!\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Trend Micro\HijackThis\sniper.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=laptop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = ¸?Ô R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {4046A27F-B156-4312-8A1B-790EDEF1067D} - C:\WINDOWS\system32\wvUkHYsp.dll (file missing) O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe" O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\sandra!\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c O4 - S-1-5-18 Startup: AutoTBar.exe (User 'SYSTEM') O4 - .DEFAULT Startup: AutoTBar.exe (User 'Default user') O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: HotSync Manager.lnk = ? O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201 O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204 O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203 O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O9 - Extra button: StumbleUpon - {75C9223A-409A-4795-A3CA-08DE6B075B4B} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop O15 - Trusted Zone: *.avsystemcare.com O15 - Trusted Zone: *.onerateld.com O15 - Trusted Zone: *.safetydownload.com O15 - Trusted Zone: *.stumbleupon.com O15 - Trusted Zone: *.trustedantivirus.com O15 - Trusted Zone: *.virusschlacht.com O15 - Trusted Zone: *.avsystemcare.com (HKLM) O15 - Trusted Zone: *.onerateld.com (HKLM) O15 - Trusted Zone: *.safetydownload.com (HKLM) O15 - Trusted Zone: *.trustedantivirus.com (HKLM) O15 - Trusted Zone: *.virusschlacht.com (HKLM) O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (FACEBOOK Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://download.games.yahoo.com/games/web_games/playfirst/trijinx/TriJinx.1.0.0.55.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_games/tikgames/cinematycoon/cinematycoon.cab O16 - DPF: {DBA8E419-0D5F-439B-A3CC-D01C768D9B51} (DVCDownloaderControl Object) - http://aolsvc.aol.com/onlinegames/sonydavincicode/DVCDownloaderControl.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4946/mcfscan.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll spdvnc.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O20 - Winlogon Notify: hgGyxWMG - hgGyxWMG.dll (file missing) O23 - Service: afisicx Manages messages (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe (file missing) O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe (file missing) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: mabidwe Service (mabidwe) - Unknown owner - C:\WINDOWS\system32\mabidwe.exe (file missing) O23 - Service: MBackMonitor - Unknown owner - C:\Program Files\McAfee\MBK\MBackMonitor.exe (file missing) O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe O23 - Service: noxtcyr Event propagation service (noxtcyr) - Unknown owner - C:\WINDOWS\system32\noxtcyr.exe (file missing) O23 - Service: noytcyr Service (noytcyr) - Unknown owner - C:\WINDOWS\system32\noytcyr.exe (file missing) O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: roxtctm pass-through (roxtctm) - Unknown owner - C:\WINDOWS\system32\roxtctm.exe (file missing) O23 - Service: roytctm Service (roytctm) - Unknown owner - C:\WINDOWS\system32\roytctm.exe (file missing) O23 - Service: sotpeca Manages messages (sotpeca) - Unknown owner - C:\WINDOWS\system32\sotpeca.exe (file missing) O23 - Service: soxpeca Service (soxpeca) - Unknown owner - C:\WINDOWS\system32\soxpeca.exe (file missing) O23 - Service: tdydowkc Service (tdydowkc) - Unknown owner - C:\WINDOWS\system32\tdydowkc.exe (file missing) O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: wsldoekd Corporation inc. (wsldoekd) - Unknown owner - C:\WINDOWS\system32\wsldoekd.exe (file missing) -- End of file - 14879 bytes thats it. am i forgetting any logs?Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there) - R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = ¸?Ô - O2 - BHO: (no name) - {4046A27F-B156-4312-8A1B-790EDEF1067D} - C:\WINDOWS\system32\wvUkHYsp.dll (file missing) - O20 - AppInit_DLLs: avgrsstx.dll spdvnc.dll - O20 - Winlogon Notify: hgGyxWMG - hgGyxWMG.dll (file missing) Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Before you begin the SDFix instructions you should copy these instructions in a Notepad file and save them to your desktop or print them for easy reference. Much of SDFix will be done in Safe mode and you will be unable to access this web page after booting into Safe mode. Download SDFix by AndyManchesta and save it to your desktop. When using this tool, you must use the Administrator's account or an account with Administrative rights
Open the SDFix folder and double click RunThis.bat to start the script.
|
|
| 2710. |
Solve : Decrease computer's hard disk space? |
|
Answer» I have a problem in the computer's hard disk |
|
| 2711. |
Solve : Laptop infected logs attached? |
|
Answer» Hello horn1988. I'll give you a heads up when COMBOFIX is back on-line. Hello Horn1988. ComboFix is back on-line. You can run this SCAN. |
|
| 2712. |
Solve : Worm.Win32.Netsky? |
|
Answer» My computer has Worm.Win32.Netsky. I'm using another computer as I can no longer use my other. (which is why i can't include all the file stuff) Everything was fine till a LAST night. A few webpages where coming up red and saying I was infected or whatever so I closed everything off. It seemed like something fake. I reboot but when I did sign back on everything was messed up. |
|
| 2713. |
Solve : Cleaning the mess a virus did to my computer? |
|
Answer» One of my Dell windows XP computers recently was struck by a virus and it left quite a mess. the COMPUTER works, but just very inefficiently. anybody knows how to fix that?HI, WELCOME the Computer HOPE MESSAGE boards. |
|
| 2714. |
Solve : logs help!! Expert? |
|
Answer» ATTACHED are my logs help me out... [Saving space, attachment deleted by admin]I USED Windows process and HIJACKTHIS log tool and here's Your HijackThis report. Please wait also for an expert to ADVISE you on what to do next. |
|
| 2715. |
Solve : Terrible virus? |
|
Answer» I use firefox |
|
| 2716. |
Solve : svcipa.exe found in my computer? |
|
Answer» Hi.. anyone please help me.. !!! Is by disable the system restore and rerun all the scan in safe mode will total make the computer free of virus?This isn't guaranteed. It will definitely help, though. To give it a try... 1. Go to Start > Programs > Accessories > System Tools > System Restore 2. Click on System Restore Settings. 3. Check Turn off System Restore and click OK. 4. Reboot into Safe Mode and scan with your anti-virus, then restart. 5. Follow STEPS 1 and 2 to RETURN to the settings, uncheck Turn off System Restore, and click OK. 6. Create a new restore point and close the program. System Restore will now be active again. If you would LIKE to learn more about System Restore, go here. Let us know if you still have problems after this. Quote from: cysmark on August 23, 2007, 11:42:14 PM By the way, waht is the best antivirus recommendation to keep my computer away from virus as I used to download files from the internet..This is up to debate, but my personal favorite is AVG Free.hi CBMatt, the svcipa.exe virus is back in my computer.. what should i do now..? Pls help.. Regards, markDownload ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly SHORT) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls. Then go ahead and post a HijackThis for us to take a look at.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 2717. |
Solve : Desperately Seeking Help? |
|
Answer» I have been having some major issues with my computer. I can not open programs, I can not use my printer, I can not use System Restore I keep getting script error messages and debugging prompts, I suddenly have icons in my taskbar that I don't know what they are or where they came from. I have been to several message boards for help and I have had no one even respond! I am running Windows XP Home Edition. I use AOL's security systems. I don't know if this is a Virus or what...I have run SpyBot, Adaware,different online scans etc and can not get anywhere. I'm frustrated! Please, please, please take a look at my Hijack This log and tell me if there is anything going on... I appreciate any help in advance. My log will be posted in my next thread...Thanks |
|
| 2718. |
Solve : 271 threats detected? |
|
Answer» Hey folks, my computer has been basically unusable for many months due to lots of viruses and trojans on it...and I finally decided it was time to clean up this mess. I'm running windows xp, with AVG free edition and super anti-spyware, along with various other generic virus scans here and there. Super anti-spyware found 271 threats when I was in safe mode, and I deleted / quarantined them all only to find many are coming back right when I start up. And doing the virus scans while not in safe mode doesn't work, as they take literally 20 hours to complete the scan, where the viruses just close the results automatically and I can't do anything. And CBMatt, by CD's for my computer do you mean the CD's to reformat? I've never done a reformat so I don't have the slightest clue of the specifics of it, but people keep telling me you need a CD to reformat the computer, and since this computer was given to me I do not have that CD.Yes, that's exactly what I mean. It's possible to reformat a computer without CD's, but I've never done it, so I don't think I'm the best person to ask. And I'm not even sure if that would help because it could be a hardware problem (quite likely if Safe Mode also gives you problems). Out of curiosity, go ahead and post a HijackThis log and I'll see if there's anything else that should be removed.Hey, it seems something was overlooked because some of the viruses and what not seem to be back. When I went online to post the hijack this log a day after my last post, my computer was bogged down again and I could tell there was stuff running in the background. I also noticed something changed the date / year on my computer to 2107 which seemed really random. Anyway, I haven't been able to find what's causing this but I figured I'd risk going online to post that hijack this log. Logfile of HijackThis v1.99.1 Scan saved at 5:40:55 AM, on 8/6/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\QuickTime\qttask.exe F:\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\System32\snmp.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\WINDOWS\system32\divxsm.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\explorer.exe F:\MY stuff\VR.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - Default URLSearchHook is missing F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe,aeyohdy.exe O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\System32\cscentfy.dll (file missing) O2 - BHO: Acrobat Helper - {06846E6F-C8D7-4D56-B87D-784B7D6BE083} - C:\WINDOWS\system\ctlsdlg.dll__SpybotSDDisabled (file missing) O2 - BHO: (no name) - {822D8AB0-812D-4E59-9A86-E58CBE0B9512} - C:\WINDOWS\System32\ponai.dll__SpybotSDDisabled (file missing) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [CountrySelection] pctptt.exe O4 - HKLM\..\Run: [a-squared] "F:\MY stuff\a-squared Anti-Malware\a2guard.exe" O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k O4 - HKLM\..\Run: [eanth_critical_update_alert] C:\PROGRA~1\ACCELE~1\ANTI-V~1\EANTH_~1.EXE /Startup O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ZoneAlarm Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O12 - Plugin for .tga: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 UPDATE Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: W2k PCtel speaker phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Oh and one last question that I've been wondering about, when I ran the original virus scans it found svehost.exe to be a virus, and I know svchost in itself is a system process, but is it normal to have 4 svchosts running at the same time? Cause my task manager says theres 4 running at all times and I thought that was weirdQuote Oh and one last question that I've been wondering about, when I ran the original virus scans it found svehost.exe to be a virus, and I know svchost in itself is a system process, but is it normal to have 4 svchosts running at the same time? Cause my task manager says theres 4 running at all times and I thought that was weirdI have quite a few svchost.exe's running as well. You should consider the fact the a virus can be named anything, including svchost. If your antivirus picked it up as a virus, it could be one, although i'm not sure. And one last thing, i'm not a pro at Hijackthis so wait for someone else to analyze it I see that you have a lot of protection software. Ample protection is a good thing, but you need to be careful. Make sure you don't run all of these programs at once, as that may cause problems with scanning, detecting, and cleaning malware. If you have more than one anti-virus running, they'll "fight" over which program takes precedence. This can cause many errors and may result in INFECTED files going unnoticed. So, you should pick the anti-virus you want to keep (I suggest AVG Free) and just get rid of the rest. As for anti-spyware...you should disable AVG Anti-Spyware (not the same as AVG Free) and keep Spybot as your active scanner, because AVG AS doesn't have a live scanner unless you pay for it. Now, for your log... Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet... R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - Default URLSearchHook is missing F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe,aeyohdy.exe O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\System32\cscentfy.dll (file missing) O2 - BHO: Acrobat Helper - {06846E6F-C8D7-4D56-B87D-784B7D6BE083} - C:\WINDOWS\system\ctlsdlg.dll__SpybotSDDisabled (file missing) O2 - BHO: (no name) - {822D8AB0-812D-4E59-9A86-E58CBE0B9512} - C:\WINDOWS\System32\ponai.dll__SpybotSDDisabled (file missing) O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k O4 - HKLM\..\Run: [eanth_critical_update_alert] C:\PROGRA~1\ACCELE~1\ANTI-V~1\EANTH_~1.EXE /Startup Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)... Stop Sign or Acceleration Software Please note any other programs that you dont recognize in that list in your next response. Navigate to and delete the following folder(s) if present... C:\Program Files\Acceleration Software Navigate to and delete the following file(s) if present... C:\WINDOWS\system\ctlsdlg.dll C:\WINDOWS\System32\aeyohdy.dll C:\WINDOWS\System32\cscentfy.dll C:\WINDOWS\System32\ponai.dll Once you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we need to clean up. Let me know how everything's running now and if you had any problems following my steps.Quote from: Drin on August 24, 2007, 06:49:11 AM Oh and one last question that I've been wondering about, when I ran the original virus scans it found svehost.exe to be a virus, and I know svchost in itself is a system process, but is it normal to have 4 svchosts running at the same time? Cause my task manager says theres 4 running at all times and I thought that was weird There's a big difference between svehost and svchost. Sure, they look similar, but svchost is a vital system process (it's very normal to have 4 instances) and svehost is a commonly-known infection. If your anti-virus hasn't deleted C:\WINDOWS\system32\svehost.exe, then you should delete it manually in Safe Mode.As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 2719. |
Solve : 462 fatal error message? |
|
Answer» hi chris, thank you for all your help.. |
|
| 2720. |
Solve : Popups popups everywhere!? |
|
Answer» I was recently browsing the internet looking for how to videos on coke and mentos (youtube is not aloowed in this household.) Anyway a popup came us saying I have not got the latest active x controll. Being a fool I accepted and thats where my problems began. First of all it tryed installing a trojan but AVG picked that up. After doing that I did a full system scan of everything on my computer. Using Windows Washer I cleaned any Teporary internet files / cookies. Then I went into controll panel and deleted suspicious looking prgrams. While this did get rid of my extra internet toolbar I'm still recieving popups saying I may have been infected and companies tring to sell me there PRODUCTS to help me get rid of it. As soon as anyone can aid me by telling me to upload a PICTURE I can gladly show you what 1 of the popups are (the're several) are. Windows Firewall and this is an iMac, I have used a program named boot-camp to get into Windows XP. I'm to scared to go into the Mac area of the computer, will it be infected? So I assume you're dual-booting. No the MAC OS should not have been affected. Something might have been attempted I guess, depending on how the trojan / virus spreads on your computer but no I doubt there will be any problems. CBMatt will fix your problem(s) in no time when a HJT log is posted, make sure you get all of it and if it doesn't fit 2 or more posts is alright.Not to fear Spybot is here! I found 9 differant pieces of spyware and the problem ceases to exist. Shall I still use HiJack this?Yes.Anything I should be worried about? Logfile of HijackThis v1.99.1 Scan saved at 7:57:03 AM, on 22/08/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\Brightness.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Apple Keyboard Support\KbdMgr.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Seaward\PATGuard Elite\eManagerNR.exe C:\Program Files\Webroot\Washer\WasherSvc.exe C:\Program Files\Webroot\Washer\wwDisp.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\0BKXUVNN\HijackThis[1].exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {5DDE5591-A8AB-4897-93EF-1E4E943F85A7} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing) O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: Protection Bar - {CC18AE76-7E65-4258-A193-9EA0C52DA6B8} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing) O4 - HKLM\..\Run: [AppleTime] C:\WINDOWS\system32\AppleTime.exe O4 - HKLM\..\Run: [Brightness] C:\WINDOWS\system32\Brightness.exe O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [Apple_KbdMgr] "C:\Program Files\Apple Keyboard Support\KbdMgr.exe" O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [OPSE2 Reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini" O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\RunOnce: [SpybotDeletingA9216] command /c del "C:\Program Files\Video ActiveX Access\imsmain.exe_tobedeleted_old" O4 - HKLM\..\RunOnce: [SpybotDeletingC332] cmd /c del "C:\Program Files\Video ActiveX Access\imsmain.exe_tobedeleted_old" O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "James" O4 - HKCU\..\RunOnce: [SpybotDeletingB2530] command /c del "C:\Program Files\Video ActiveX Access\imsmain.exe_tobedeleted_old" O4 - HKCU\..\RunOnce: [SpybotDeletingD1221] cmd /c del "C:\Program Files\Video ActiveX Access\imsmain.exe_tobedeleted_old" O4 - Global Startup: PATGuard e-Manager.lnk = C:\Program Files\Seaward\PATGuard Elite\eManagerNR.exe O8 - Extra context menu item: &Search - ?p=ZJxdm035YYAU O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Aaron\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe CBMatt will tell you if you need to fix anything but it looks like you still need to reboot for Spybot to finish clearing out those files, judging by the O4, RUNONCE entries.First, Your HijackThis is in a temporary location. If you leave it there, it (along with its important backups) can and will eventually be deleted. Please download it again and save it to a new permanent folder at C:\Program Files\HJT. DeltaSlaya is right. Typically, it's best to scan in Safe Mode. If you don't, some programs require you to restart your computer to clean the infection. So, make sure you do that. Those entries shouldn't show up in your next log. Until then, we'll take care of what's on this current one... Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet... O2 - BHO: (no name) - {5DDE5591-A8AB-4897-93EF-1E4E943F85A7} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing) O3 - Toolbar: Protection Bar - {CC18AE76-7E65-4258-A193-9EA0C52DA6B8} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing) O8 - Extra context menu item: &Search - ?p=ZJxdm035YYAU Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)... Video ActiveX Access Please note any other programs that you dont recognize in that list in your next response. Navigate to and delete the following folder(s) if present... C:\Program Files\Video ActiveX Access Once you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we need to clean up. Let me know how everything's running now and if you had any problems following my steps.I did the following as you stated above but I couldn't find the file Video ActiveX, hope I've stamped it out now. Here is a HiJack this log if you wish to have a second look Logfile of HijackThis v1.99.1 Scan saved at 7:44:23 PM, on 22/08/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Webroot\Washer\WasherSvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\Brightness.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Apple Keyboard Support\KbdMgr.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Webroot\Washer\wwDisp.exe C:\Program Files\Seaward\PATGuard Elite\eManagerNR.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HiJack This\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O4 - HKLM\..\Run: [AppleTime] C:\WINDOWS\system32\AppleTime.exe O4 - HKLM\..\Run: [Brightness] C:\WINDOWS\system32\Brightness.exe O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [Apple_KbdMgr] "C:\Program Files\Apple Keyboard Support\KbdMgr.exe" O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [OPSE2 Reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini" O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe O4 - Global Startup: PATGuard e-Manager.lnk = C:\Program Files\Seaward\PATGuard Elite\eManagerNR.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Aaron\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe Thanks for all your help, James.I figured the program would probably be gone; I just wanted to be thorough to make sure we get everything. With that out of the way, your log now looks clean. However, you're using an older version of Java. You'll want to correct this quickly, as it will help provide further protection for you. To do so, go here and click on Free Java Download. You will be given instructions on what to do next. After installing the newest version, you should remove any older versions. Also...you're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo. They're all good free firewalls. Just be sure you only have one installed at a time! Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall. Take care of those and you should be set. You're no longer experiencing any problems, are you?Not at all, I'll just install these now. Any use installing firewalls for my Mac partition? Any Mac freindly ones? James.Because it's not as widely-used, Mac isn't nearly as vulnerable. Of course, that doesn't make it completely immune. I don't usually work with Macs, so unfortunately, I don't know for sure which firewalls are best-suited for it, but I'm PRETTY sure ZoneAlarm has a Mac version. And if you're using Mac OS X, it should have a built-in firewall, which may be sufficient.As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 2721. |
Solve : ehjalrp.exe and quqnrtl.exe - Frustrating Viruses? |
|
Answer» OS: Windows XP (home and professional) |
|
| 2722. |
Solve : Email Bug? |
|
Answer» This computer and another one. |
|
| 2723. |
Solve : I think some virus is using my internet connection.? |
|
Answer» I ran AVG free edition in safe mode, and there are the results: hmmm please do a hijack this log and post it here please upload any files please check For Missmurder.exe in your task manager becus ive found it uses up most of ussage on most things and has been commonly known on some other foroums good day. Stop it already...bennyman, You'll run into that a lot when getting situated with a new firewall. Although you don't have to allow the connection, both of those programs are trustworthy, and blocking them might prevent you from accessing FTP's and other similar connections. Just pay attention to the alerts and if there's anything you don't recognize, you can either perform a search on Google or ASK for our opinion. Are you still having problems? |
|
| 2724. |
Solve : WinAntiVirus 2007 Pro wont go away!? |
|
Answer» I have tried everything from Spybot to vondu to hijackthis and nothing seems to help. I can see the files in the system32 folder but some how my administrative privilages have been taken away. How can that happen? I am the only administrator! Now what? I have no credit card for other "expensive" cures. Plese help. Thankshttp://www.malwarebytes.org/rogueremover.php |
|
| 2725. |
Solve : HiJackThis Saved Log? |
|
Answer» Hello, |
|
| 2726. |
Solve : Trojan/Malware infected- Problem! Heeellllpppp!? |
|
Answer» Hi, Should I try and delete some?No, don't make any changes without being instructed to do so. Doing the wrong thing could cause some serious problems with your computer. Post the log here and you will be instructed further.Logfile of HijackThis v1.99.1 Scan saved at 10:39:22, on 17/08/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe C:\WINDOWS\system32\DLA\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\Program Files\McAfee.com\VSO\oasclnt.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Spyware Doctor\sdhelp.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\mcafee.com\mps\mscifapp.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe C:\Program Files\DellSupport\DSAgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Spyware Doctor\swdoctor.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\SpywareBot\SpywareBot.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\STOPzilla!\STOPzilla.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.skybroadband.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.tiscali.co.uk/dell R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided By Sky Broadband R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing) O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: bet365 Poker - {B1BA4A3F-1C95-497b-9F82-F8DA4A5C89DD} - C:\Program Files\bet365MPP\MPPoker.exe (file missing) O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://static.photobox.co.uk/sg/common/uploader_uni.cab O18 - Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum167.txt O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll This is the rest of the Hijack this log. O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe O23 - Service: SpywareBot Scanning Engine (SpywareBotSrv) - Unknown owner - C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exeWell, your log looks relatively clean and I don't see anything that might be causing these restrictions, but we'll see what we can do here. Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet... R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O9 - Extra button: bet365 Poker - {B1BA4A3F-1C95-497b-9F82-F8DA4A5C89DD} - C:\Program Files\bet365MPP\MPPoker.exe (file missing) O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum167.txt O23 - Service: SpywareBot Scanning Engine (SpywareBotSrv) - Unknown owner - C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe (SpywareBot looks legit, but it's an insufficient and deceptive program. See here: http://www.fbmsoftware.com/spyware-net/Application/SpywareBot) Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)... bet365MPP SpywareBot Please note any other programs that you dont recognize in that list in your next response. Navigate to and delete the following folder(s) if present... C:\Program Files\bet365MPP C:\Program Files\SpywareBot Once you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we NEED to clean up. Let me know how everything's running now and if you had any problems following my steps. Also...download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.Hi, I checked the entries you mentioned and rebooted into safe mode, then enabled hidden files and folder. In safe mode when I went to my computer and there was no control panel so I couldn't do add/remove programs and remove anything. I instead deleted them from internet options. Anyway, I then rebooted back into normal mode and thankfully I now have access to My computer and Add/Remove programs. I have removed some files I don't need, but when I tried to delete Spwarebot from Add/Remove Program it says, 'Service 'AntiSpy Filter' could not be stopped, verify you have sufficient privileges to stop the system services.' Anyway, I will include the HJT log and the Combo log. Also, anytime I start up my pc Stopzilla, my AV pops up, saying I have 145 infections, do i want to remove them or not. [Saving disk space - old attachment deleted by admin]Combo Log [Saving disk space - old attachment deleted by admin]Did you remove those entries above with HijackThis? They're still showing up in your log. Try uninstalling SpywareBot in Safe Mode. Any difference? And if your anti-virus is detecting infections, then yes, you most likely want to remove them.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 2727. |
Solve : adware/spyware? |
|
Answer» i recently tried to download a music file and immediately got a popup from my security suite that there was a VIRUS detected and asked what to do. I opted to delete and navigated away from the page. since then I have a yellow triangle with an exclamation point in it in my system tray that gives me a balloon when i hover over it that says "YOUR COMPUTER IS INFECTED! windows has detected spyware. windows will now download and install the most up-to-date antispyware for you. click here to protect your computer." If i click on it it takes me to an antispyware program. If I dont click on it i get a popup window about every five mins telling entiteled. Windows Security Alert. Warning! POTENTIAL spyware click here to download spyware remover. I can close the box out easy enough but it keeps coming back. Also when I go to Add/Remove programs it wont let me and says this operation has been cancelled due to restrictions on this computer. please CONTACT your system administrator. |
|
| 2728. |
Solve : win32/malum.ceqc? |
|
Answer» My EZ ANTIVIRUS keeps telling me about this INFECTION but when I TRY to follow its link to an information page there are no RESULTS. Anyone know what this virus is and how to get rid?Download SUPERAntiSpyware, update it, and scan with it in Safe Mode. You should then scan with HijackThis and post a log here for us to look at.Due to lack of feedback, I am closing this topic. If you are the original poster and you would LIKE this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. |
|
| 2729. |
Solve : hijacker in my computer! help please!? |
|
Answer» i was using aim and i got a message from a friend that said, hey! can i put this picture of us on myspace? i downloaded the file being the complete idiot that i am and the next time i restated my computer it was extremely slow and windows explorer wouldn't open. i don't have the money to fix this so i really need to know if there is a way i can get rid of the hijacker/virus in my computer! i've tried AVG spybot and all of those. i heard about a program called hijackthis and i'm going to try it. i really need this laptop fixed so please if anyone can help me, it would be appreciated. i use windows xp, amd semron, ati radeon xpress 200M, incase that is needed..thanks tons!If its a friend then i doubt its a virus. and the only protection I use.If that's true, then you're terribly underprotected.about a year or so ago, i got a message like that from my friend on AIM saying to "CHECK out my new pics!". it was a virus that was going around, it'll probably be getting more common again since classes are starting for the fall..EVEN if it's from your friend, you should ask what it is..make sure you warn your friends to not click or download anything in a message that they get from you on AIM, by the way. check out these websites and see if you can find anything useful. my friend used them and it fixed her computer. i'm not sure how up to date it would be now, it's been around a year. good luck. http://www.jayloden.com/aimfix.htm http://www.computing.net/security/wwwboard/forum/17899.html http://forum.pcmech.com/showthread.php?t=153774i tried all of it, aim fix then reeboot, trend micro housecall while in safe mode, spybot while in safe mode and regular, hijackthis.. nothing.. You need to post the hijackthis log here. Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 2730. |
Solve : w32.spybot.worm? |
|
Answer» hey all, |
|
| 2731. |
Solve : can you tell me wht this is? |
|
Answer» I dont belive it... i just DOWNLOAD hotfix kB updates, |
|
| 2732. |
Solve : Desktop Icons that will not delete???? |
|
Answer» ...There are two of them on my Desktop one says "Windows Update" and the other "Help and Support Center" both link to a site called storageprotector.com |
|
| 2733. |
Solve : Laptop Audio quite choppy, itunes, winamp, youtube, streaming etc.? |
|
Answer» All sorts of audio on my laptop plays really choppily, at first it was mainly happening only when I had Internet Explorer windows open, so I switched to opera to try it out which helped a bit but I'm still having problems. I think I should be fine in the RAM department, and my CPU is performing fine, not overworked or anything. This will happen even if I only have a program or 2 open. Could this be a virus? |
|
| 2734. |
Solve : Computer Virus Help? |
|
Answer» Hi, Symnatec shows the same viruses nightly.Can you write the names down, and post them back here? We also need your computer specs... - processor speed - hard drive size/how much free space - how much RAM?1) I ran a scan of symnatec. It came up with TWO different viruses this time. They are: Jvmusafe.jar-6ba32b3f-74e517da.zip Status: Still contains one infected item Action taken: Quarantined Scan type: Manual Scan Event: Threat Found! Threat: Downloader File: C:\Documents and Settings\Trent Berger\.jpi_cache\jar\1.0\jvmusafe.jar-6ba32b3f-74e517da.zip>>vmain.class Location: Quarantine Computer: TRENT-31A63E0D1 User: Trent Berger Action taken: Quarantine succeeded Date found: Friday, December 21, 2007 10:37:42 PM -Are these now taken care of or is there more I have to do? 2) How do I find out the computer specs -Processor Speed -Hardrive/Free Space -Ram 3) What should I do about -Ad Aware -Spybot -eWido -AVG -Should I delete and just use SAS, ESET? Thanks! 1. Two messages from Symantec are about ONE file: Jvmusafe.jar-6ba32b3f-74e517da.zip It was taken care of (Quarantined), so you're done. 2. Get BgInfo: http://technet.microsoft.com/en-us/sysinternals/bb897557.aspx 3. You may have only ONE firewall, and ONE antivirus, and this is exactly what you have: Norton, in both cases. As for other antimalware programs (Spybot, Ad-aware, etc.), and on-line antivirus scanners, you may have as many, as you want.I downloaded it. Am I fine then? Your computer is clean. How is it now? Faster? Crashes? |
|
| 2735. |
Solve : Here's my plan? |
|
Answer» I have an assortment of viruses on my laptop, here's a few of them. |
|
| 2736. |
Solve : cetihpz://errors/blank.htm? |
|
Answer» please, anyone help me remove this blank window on my desktop. as its KEEP on appearing EVERYTIME my windows STARTS "cetihpz://errors/blank.htm".. my OS is windows XP service pack 2. If you have HP printer, UNINSTALL it, reboot, and reinstall printer's software.again, thank you very much for your help.. now my computer is working fine..Good job |
|
| 2737. |
Solve : hjt log files? |
|
Answer» Would it be possible for someone to take a look at my hijackthis log? I have no idea how to read these. My client was complaining of pop-ups and threat alerts from AVG stating that her personal information was being compromised. I rushed to her house this evening and immediately installed HijackThis and ran a scan, then saved the log. Next, I updated her AVG, and now I am running a scan. So far the scan has found 22 trojan/viruses. BTW...HJT log looks strange. Only O23 (services) entries listed. Ditto. There are some strange entries even though there are only a few. This may be a case for renaming HijackThis before running anymore scans with it. Delete the HijackThis shortcut you have on the desktop. Enable Viewing Of Hidden System Files & Folders 1. Click Start. 2. Select Control Panel. 3. Select the Tools menu and click Folder Options. 4. Select the View Tab. 5. Under the Hidden files and folders heading select Show hidden files and folders. 6. Uncheck the Hide extensions for known file types option. 7. Uncheck the Hide protected operating system files (recommended) option. 8. Click Apply. 9. Click OK. Now go to C:\Program Files\Trend Micro\HijackThis\HijackThis.exe Right click on the HijackThis.exe and select Rename. Rename it to chscan.exe and press enter. Now right click the chscan.exe and send it to the desktop as a shortcut. As Broni stated, you should run the other scans and post the logs. Run a new HijackThis scan last and post that also.thanks. I will get started on that, and then post the logs. ttys here are the scan log files. let me know what you suggest. thanks, solotekk [saving space - attachment deleted by admin]Open HijackThis and select Do a system scan only then place a check mark next to: O2 - BHO: (no name) - {5136B3A0-0856-4D2E-9BA8-C657448668D1} - (no file) O2 - BHO: (no name) - {8E3FBDE2-7DBD-4040-85D9-29BBC559C129} - (no file) O2 - BHO: (no name) - {973FBB2F-AB8C-4637-92A8-E55F83D64E45} - (no file) O2 - BHO: (no name) - {FF64059D-4D2A-4D6B-AA0F-2EE4A2FE3856} - (no file) O20 - Winlogon Notify: fccaxwu - fccaxwu.dll (file missing) O20 - Winlogon Notify: vtuurss - vtuurss.dll (file missing) Close all windows except for HijackThis and click Fix checked ---------- Please download Combofix by sUBs from either here or here Save Combofix.exe to your your Desktop.
Also add a new HijackThis log.here are the logs. oh YEAH, there is a program that seems fishy to me. its in the add/remove programs list and it says that in order for me to uninstall completely, i should go to the WEBSITE. the website name is www.outerinfo.com my client has never heard of the program or the website. can you investigate this and let me know if it's legit? and is it in the logs? thx. [saving space - attachment deleted by admin]Open HijackThis and select Do a system scan only then place a check mark next to: O4 - HKCU\..\Run: [QdrPack10] "C:\Program Files\QdrPack\QdrPack10.exe" Close all windows except for HijackThis and click Fix checked The locate and delete this file/folder QdrPack10.exe Found at C:\Program Files\QdrPack\QdrPack10.exe ---------- Delete these files/folders, as follows: * Open notepad and copy/paste the text in the quote box below into it (all except the word QUOTE): Quote File:: * Save this as CFScript on the desktop. * Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! * ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it shall produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick combofix's window while it is running. That may cause your system to hang ---------- Repost a new HijackThis log and let me know how things are now. ok, so i had to leave my clients house...they were going christmas shopping...... which means i won't be able to make it back there untill sometime tomorrow. When I return, I will follow your instructions from your last post. Then I will send you the hjt scan log. Thank you for your help once again. I appreciate it. Have a good evening. No problem. Don't forget the Combofix.txt also. here are the log files from hjt and combofix. thx. [saving space - attachment deleted by admin]Please download, update and run a-squared free At the main menu, click Scan Now, there will be 4 options, choose Deep Scan. * If malware is found, click the button Remove Selected Malware * If malware is found, select all found and click Quarantine selected objects * Click Save Report. Save the report to SOMEWHERE convenient, such as your desktop * Add the report as an attachment in your next post. |
|
| 2738. |
Solve : PC Clogged...keeps re-starting. Need Help!? |
|
Answer» System keeps re-starting and re-starting .... Tell us when the problem started and whether you noticed or did anything around that time. Like installing or removing software for example. You can disable the automatic reboot. This will allow you too see what error is causing the REBOOTS. This error message is crucial. Start the computer in normal mode and let it crash and reboot. Tap F8 reaptedly during the bootup. This should bring you to the "Windows Advanced Options Menu". From this menu select "Disable automatic restart on system failure" and press enter. Select XP as the operation system to start and hit enter. Now windows will try to load again. This time instead of restarting you should get a blue screen similar to this one. The red boxes on the picture shows you what information from the blue screen you need to write down. Post the info here. Thanks for the reply help... * I got the blue screen with all the info you stated , except the cause of the problem, which is the FIRST thing you circled in red. * As fart as technical information, I got the following: ****STOP: 0x0000007F (0x00000008, 0x80042000, 0x00000000, 0x00000000) Appreciate all the help you can give me in getting my PC back to normal, fast-speed performance.Ouch... this stop code may indicate a hardware problem. I really hate repeating myself here... but it would help if you could tell me anything about when this problem started. Have you added or removed any software or hardware or noticed any strange noises or anything else out of the ordinary? Also, do you by chance have Symantec AntiVirus installed?I have SuperAntispyware installed as well as CA Internet Security Suite. I ran the Superantispyware and quarantined/deleted the checked boxes. I believe this problem started thereafter... If I could access past the Windows Logo screen to actually log into my system, that'll be FANTASTIC. Again, your help is greatly appreciated and looking forward to your reply.I'll do it for you DeerPark... Quote from: Deerpark on December 27, 2007, 08:34:41 AM Ouch... this stop code may indicate a hardware problem.I was able to do a clean install of XP Home...which resolved lots of issues. * However, when I select to restart PC, it does not read my DVD Burner drive...Only reads floppy and cd rom drive. Occasional freezes occur as well. * Below is latest HJT Log to guide as to what need not be there to get optimum performance with PC: Logfile of Trend Micro HijackThis v2.0.2 Scan SAVED at 1:22:35 PM, on 12/28/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.28\QOELoader.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DNA\btdna.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O1 - Hosts: 75.67.92.226 paypal.com O1 - Hosts: 75.67.92.226 www.paypal.com O1 - Hosts: 75.67.92.226 http://paypal.com O1 - Hosts: 75.67.92.226 http://www.paypal.com O1 - Hosts: 75.67.92.226 paypal.co.uk O1 - Hosts: 75.67.92.226 www.paypal.co.uk O1 - Hosts: 75.67.92.226 http://paypal.co.uk O1 - Hosts: 75.67.92.226 http://www.paypal.co.uk O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.28\QOELoader.exe" O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe -- End of file - 5002 bytes _______________________________________ _______________________________________ ___________________________ Thanks and looking forward to any additional guidance. |
|
| 2739. |
Solve : Free AVG Pro ??? |
|
Answer» Came across a site that is OFFERING AVG Pro for free. |
|
| 2740. |
Solve : task manager repetedly locked out ??? |
|
Answer» We STILL were not able to remove: it is gone now.Cool... How is your Task Manager doing now? Download, and install free Comodo firewall: http://www.personalfirewall.comodo.com/ I'll investigate your Windows firewall further, but I want you to be safe, and Comodo firewall is much better, anyway.As for your Windows firewall... Go Start>Run, type in: services.msc Hit Enter. Find Windows Firewall entry, and tell me what does it say under Status, and Startup type column. Don't change anythingunder status it says started under start up says automatic and didnt change anything Go Start>Run, type in: regedit Hit Enter. Navigate to: HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ If you have a folder: WindowsFirewall right click on it, and click Export. Save it to known location. Right click again, click Delete. Close regedit. Restart Windows. Check if firewall options are still greyed out. How about your Task Manager?after deleting that register key the windows firewall is no longer greyed out. and it was on when i pulled it up as well. thanks for all of your help with this problem i had. is there anything else i need to do at this point ? Good going Quote it was on when i pulled it up as wellYou turned it off? Did you install Comodo? Is your Task Manager working OK?Task manager is no longer a problem and thanks again for all of your help. not sure how much it would have cost me and to be with out my computer for a week or so if i would have taken it to a shop to fix. And thanks for helping me straighten out the fire wall as well if i COULD buy ya a SIX pack i would You're very welcome, but I'm still not clear about your firewall situation. Do you have Windows firewall turned off, and Comodo running?sorry if i was not clear before but i have them both on now. windows and comondoNot good. It calls for some conflict. Turn Windows firewall off.OK will do that . is there anything else i should do ?That should do it. |
|
| 2741. |
Solve : how do I back up my computer without my destop icons?? |
|
Answer» O.k. I have been trying all day to get my icons back on my DESK top and I was told that I could maybe back my computer up a few days.I just need to know how I can get there without my icons.Which program do I go into? What OS are you using? |
|
| 2742. |
Solve : i need help with viruses? |
|
Answer» My Avg has detected a couple viruses can some one help me?
Next post please attach DrWeb log New HijackThis log it seems that in my last post i attached 3 logs but you said you only got 1 so i'm doing this in 2 post this time to make sure you get each attachment. first one is drweb.csv log [saving space - attachment deleted by admin]here is my log for hijackthis after my drweb scan log [saving space - attachment deleted by admin]Open HijackThis and select Do a system scan only then place a check mark next to: O16 - DPF: {8D7AFAB7-42D6-4671-A53E-CD355673F026} (SonySncMView Control) - http://65.196.226.166/SonySncMView.cab O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/sites/errorsafe.com/www/pages/scanner/ErrorSaf eNewReleaseInstall.cab Close all windows except for HijackThis and click Fix checked How is the computer running now?it seems to be doing good now... thank you! after i'm done with everything what should I do with the stuff i loaded such as Drweb, hijackthis, CCleaner and superanti ? is superanti better than AVG? You can keep them as they are free to use whenever you may need them. To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? Let us know if ANYTHING else comes up. |
|
| 2743. |
Solve : Some help would be highly appreciated.? |
|
Answer» Here's my problem: |
|
| 2744. |
Solve : Analyse the attached notepad files and the hijack log? |
|
Answer» Logfile of Trend Micro HijackThis v2.0.2
Restart the computer. To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first PLACE? |
|
| 2745. |
Solve : why would spoolsv.exe be on task manager when printer is off? |
|
Answer» in fact not working so I never HIT print. Could this be a spyware? I have antivirus of course & run spybot all the time too. I just NOTICED this and it seemed odd SINCE I never print. spoolsv.exe is the Printer Spool serviceIt's on, no matter, if your printer is on, or not. It's ready, whenever you are ready for printing.Heck...it's on even if you don't have a printer ! ! |
|
| 2746. |
Solve : error-language library? |
|
Answer» Hi...I have Windows xp and after logging in, I GET error:Language Library couldnt be Loaded" ...My Panda Security will not LOAD. HELP!!!?? I ran Lavasoft Adware,,,didnt help. Will this error appear in SAFE MODE?What websites have you been on recently? |
|
| 2747. |
Solve : Please Help Virus? |
|
Answer» ALRIGHT this probably something stupid thats going on with my laptop which is probably easy to FIX but I have no KNOWLEGE of how to fix it. I either have a virus or a virus that is trying to get on my computer which my anti-virus software is blocking.I have NORTON AntiVirus. On my security history it shows that it has been detecting W32.Trats!inf, Trojan.adclicker, Trojan.Vundo and Trojan.dropper. And I keep getting all these pop-ups telling me that there has been "adult files" put on my computer and I need to scan my computer click here. Which I don't click cause i'm not that stupid. I don't what to do my knowlege of computers is only so MUCH. Any help would be great. Thanks.You will need to see post 1 and follow the steps in post 2 from this thread and submit the logs so we can see what is going on. Thanks. |
|
| 2748. |
Solve : unable to use internet without turingoff firewall? |
|
Answer» Originally I had installed McAfee on the computer. Then I un-installed it so that I COULD install Norton. Norton is READY to expire so I want to install AVG. |
|
| 2749. |
Solve : Why does my screen go black after the Windows screen when I boot?? |
|
Answer» Why does my SCREEN go black after the Windows screen logo appears when I boot? |
|
| 2750. |
Solve : windows xp logon password virus? |
|
Answer» hi FOLKS, |
|