 
                 
                InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 2801. | Solve : AVG 805? | 
| Answer» Hi There -  | |
| 2802. | Solve : *censored* is going on with my computer? | 
| Answer» Hey i bought my laptop about a year ago and upgraded to 4gigs of ram for GRAPHIC design.  i did download the version of photoshop i have on my computer though if that has anything to do with it . From where? I'm just curious. | |
| 2803. | Solve : help with avast scan? | 
| Answer» i got this below when the scan finished was there something i should have ticked to be scanned | |
| 2804. | Solve : can someone peek at my SAS log please?? | 
| Answer» hi  | |
| 2805. | Solve : Viruses and Trojans found by Dr. Web? | 
| Answer» ok, thank you so much for your help!!!  it's greatly appreciated!check the device manager. Does it display, next to the disk drive thing a yellow triangle with an exclamation point in it? When you click on the device properties, what does it say? an error or is thing okay? check the device manager. Does it display, next to the disk drive thing a yellow triangle with an exclamation point in it? When you click on the device properties, what does it say? an error or is thing okay? sorry, i haven't seen you posting. that's exactly what i have FOUND too. i was able to FIX it and my bitdefender was easy to INSTALL without any errors. thank you for your support Glad that you're all good again | |
| 2806. | Solve : I need help checking for spyware, virus, etc. Thanks? | 
| Answer» I copied this from a previous post word for word because it is the same problem I'm having. Any help would be GREAT. 
 ---------- Download Alternate download link Note: Vista users must use Run As Administrator 
 Note that your system will run slower for a reboot or two after having used this tool so don't panic. . ---------- Download OTCleanIt.exe and save it to your Desktop. 
 Important: Restart the computer before continuing. How is everything now? | |
| 2807. | Solve : I have a virus that never goes away - could be Vundo. Any help appreciated!? | 
| Answer» All I can say is that the XP Media Center CD is the same thing as XP Pro. They have the same files.I don't have another XP CD, but I was able to fix my control panel by: 
 Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software. 
 ---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety TESTS of Web sites. SpywareBlaster - Secure your Internet Explorer to make it HARDER for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't KNOW what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Ace! Done and done; I've taken all your advice, and highly, highly appreciate all your help! Thank you~!Glad you got it figured out! Safe surfing... | |
| 2808. | Solve : HELP > | 
| Answer» (not sure if RIGHT forum~~~~~~~~~~~~) 
 | |
| 2809. | Solve : Can't dowload files with ie7 but can with Opera! - Vista OS? | 
| Answer» I have searched extensively on this - no answers to be found. I did find a lot of other people having the same problem though! Lots of posts on the web with this issue but no solutions except for some that had the problem fixed by removing AVG free. That didn't work for me though. I can download files from anywhere with Opera just fine but with IE7 the file looks LIKE it's downloading but when it completes the file disappears. It's as though an anti-virus program is killing it or something.  There is no error message. There used to be a bar at the top that you had to click on to download the files (same bar that warns about pop-ups) but this doesn't appear anymore. This is a relatively new HP laptop set up by Best Buy. I've gone through the malware removal stuff - it found some things and should be clean now just can't figure why it won't allow downloads. Any ideas? | |
| 2810. | Solve : I need help fixing me computer, i know I have a trojan? | 
| Answer» I know I have a trojan,   things wrong with it, when i turn on pc i have to pick user account, NEVER did that before, plus my clock never stays the right time the minutes yes but never the hours.  
 There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As 
 Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.i don't have vista , I have windows xp, and I think not 100% but it might not be like a real copy, like I didn't by the xp cd from a store or what not. It's either a legal copy or it isn't. Like you know. | |
| 2811. | Solve : Online Virus Scanners? | 
| Answer» Any good FREE ONLINE scans for checking viruses etc.Combines 18 MAJOR anti viruses: | |
| 2812. | Solve : Successful removal of Trojan? | 
| Answer» Hello | |
| 2813. | Solve : Possible Rootkit?? | 
| Answer» In that case thanks for all your help! I just have two more queries. Sorry if I'm stretching this.  | |
| 2814. | Solve : Unknown audio streaming through Live Messenger? | 
| Answer» Starting yesterday, I GOT some weird audio streaming in the background when the Live Messenger is running. I checked in the task manager and there is no suspicious process running (maybe yes but I could not recognize). As soon as I quit Live Messenger, the audio streaming stops. The audio streaming is apparently from a Chinese source. Update Windows.Everytime I click on the "Download and Install" button, IE (6.0) crashes. I try to download IE 7.0 but it takes forever to install. Quote Update AVG 7.5 to AVG 8.0.I cannot upgrade to AVG 8.0. I have posted about it before (check here) but no solution. Btw, if I uninstall Live Messenger, and reinstall it back, it will have no problem initially, until I restart my computer. After the reinstallation, everytime I restart my computer and sign in into Live Messenger, it will crash. Beside, I am having syndrome of the same issue with Firefox now. Sometimes the audio stream will come in when Firefox is running (Live Messenger not running). Just like Live Messenger, if I close Firefox, the audio stream is gone. Also, I cannot attach an attachment (no response) in Gmail if I access it using Firefox. No problem with IE, and no problem with Hotmail or Yahoo Mail.i have a similar thing on my computer. when i plug in a pair of headphones, i can faintly hear a Christian music station that plays in my city. i dont know where the SIGNAL gets picked up, but under specific circumstances, i can hear it. its not a virus, just a quirk.Now it happens randomly when Firefox is running, i.e. closing Live Messenger will not terminate the audio streaming but closing Firefox will. Also, I notice that when the audio streaming is coming in, my current BROWSER window will become inactive. Btw, Live Messenger still crashes from time to time. Attached is the Hijackthis log file that I get when the audio streaming is playing. I post it on the Hijackthis site and the analysis did not show any suspicious threat. Any help? [Saving space - attachment deleted by admin]I don't mind having a look but you are going to have to follow my advice. Running outdated antivirus is very risky. Please update then post a new HijackThis log. Quote from: evilfantasy on October 27, 2008, 01:11:57 PM Update Windows.As I've mentioned earlier, I cannot upgrade from AVG 7.5 to 8.0. Maybe you missed that. So it's not my fault for not following your advice apparently. Quote from: Michael on November 01, 2008, 05:16:49 AM QuoteIt shows an error of incompatible version of Windows when the installation starts even though I've downloaded the correct installer.Update AVG 7.5 to AVG 8.0.I cannot upgrade to AVG 8.0. I've asked about this long ago in another thread (link attached in earlier replay as well) when AVG 8.0 was released. There seems to be some issue with my Windows key. 1. Download this diagnostics tool MGADiag.exe and save this to your Desktop. 2. Double-click on MGADiag.exe and click Continue 3. When the program has finished, click on Copy 4. Post the results in your next reply. | |
| 2815. | Solve : Can someone tell me if there is anything wrong.? | 
| Answer» Here are my Log files for SuperAntiSpyware, Malwarebytes and hijack this Can someone tell me if there is anything wrong. Can you tell us whats wrong or should we just....know? Either way your logs are clean. This does not appear to be a malware issue just as I told you in this THREAD at Computer-Juice. | |
| 2816. | Solve : Six pointed star in task bar Freezes computer? | 
| Answer» It began yesterday, I was doing my thing on my computer and all the sudden my computer seemed to freeze and i noticed that a 6-point white star had appeared down in my Task bar by the clock. I put the mouse over it to see if i could see what it was but it wouldn't show anything, nor would it show anything else. its like the whole bar had frozen, i could not click on the start menu or any icons on my desktop. I Ctrl,Alt,Del and opened task manager and it instantly froze it up. The weird thing was i could still surf the web, it would;d let me use firefox if it was already open.  
 
 ---------- Download random's system information tool (RSIT) by random/random from and save it to your Desktop. 
 | |
| 2817. | Solve : Slower by the Day?? | 
| Answer» My computer seems to be getting slower every few days. This doesn't seem to be normal. I'm not using up more SPACE on it. Also, now, a lot of websites arn't loading for me. Especially sites with flash apps on. Things like YAHOO answers, Youtube etc don't load. Game sites dont load at all. I have the latest versions of both Flash and Java. I was thinking this might be a virus? Could I post a HJT log? I know a lot of stuff but I don't understand them, so if someone could CHECK it out I'd be greatful. | |
| 2818. | Solve : My friend's computer has been hijacked!? | 
| Answer» Hi, | |
| 2819. | Solve : Stupid AVG 8? | 
| Answer» Once again this AVG has STARTED blocking one of my software programs from running. The Resident Shield | |
| 2820. | Solve : eed halp on whats the best antiim doing reserch on avtivirus? | 
| Answer» i need haelp on knowing what the best anti virus is. i got windows live onecare and the trial has ended so its not updating and my parents wont but the full. i wanna kniw what the best free antivirus it can be a free editon asling as it updated its virus library. | |
| 2821. | Solve : us.imrworldwide.com/redsherrif.com constantly transferring my data? | 
| Answer» I'm not sure if this is the right spot, or even if I'm asking my question right. I did a search but didn't find any posts referring to these data mining sites. 
 
 
 | |
| 2822. | Solve : Bug Screen Saver Eating Desktop? | 
| Answer» 
 Download 
 
 C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l C:\WINDOWS\system32\phc95gj0ej4l.bmp EmptyTemp [start explorer] 
 
 ---------- Let's clear out the programs we've been using to clean up your COMPUTER, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have DONE. . 
 . The above procedure will: 
 
 ---------- 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 ---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed. 
 ---------- Use the Secunia Software Inspector to check for out of date software. 
 ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. To prevent unknown applications from being installed on your computer install WinPatrol 2008 Using Winpatrol to protect your computer from malicious software Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam. SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. Using SpywareBlaster to protect your computer from Spyware and Malware Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. How is everything now? Here are the results from MoveIt! Explorer killed successfully C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine\Packages moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine\BrowserObjects moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine\Autorun\StartMenuCurrentUser moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine\Autorun\StartMenuAllUsers moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine\Autorun\HKLM\RunOnce moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine\Autorun\HKLM moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine\Autorun\HKCU\RunOnce moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine\Autorun\HKCU moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine\Autorun moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l\Quarantine moved successfully. C:\Documents and Settings\Aaron\Application Data\shce5gj0ej4l moved successfully. C:\WINDOWS\system32\phc95gj0ej4l.bmp moved successfully. < EmptyTemp > File delete failed. C:\DOCUME~1\Aaron\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Aaron\LOCALS~1\Temp\~DF9616.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6d8.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. Temp folders emptied. IE temp folders emptied. Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06102008_175046 Have to restart before doing the REST...Everything seems to be up and running fine. Thanks for all of your help. No problem. Safe surfing......Sheesh, this sure is popping up a lot lately. Last night, I was working on a friend's computer that had this exact same thing (among many other infections). There was a blackster.exe file in C:\WINDOWS\system32 that you might want to look out for. | |
| 2823. | Solve : Bug screensaver virus? | 
| Answer» hello, recently i was under a virus attack, after fending it off and scanning it, i disconnected all my network connections. then after running another scan, a screensaver would show up every once in a while. it was a bunch of bugs, eating up the desktop, at the move of my mouse it would dissapear. it acts like a screen saver, but under my desktop settings no screensaver is set, and i have no recollection of ever installing said screensaver. what windows version are you using? IM using XP pro i tried system restore, but it has been turned off and there is no restore point to before my little brother downloaded the game, and the virus attack startedFollow the instructions posted STEP by step...Quote from: lufo4 on April 28, 2008, 04:30:17 PM Quote from: mcxeb52! on April 27, 2008, 07:56:25 PMwhat windows version are you using? when i clicked the .exe setup file it opened up a dialog box titled "WIndows Installer" and it had this in teh dialog box Windows ® Installer. V 3.01.4000.1823 msiexec /Option [Optional Parameter] Install Options Installs or configures a PRODUCT /a Administrative install - Installs a product on the network /j [/t ] [/g ] Advertises a product - m to all users, u to current user Uninstalls the product Display Options /quiet Quiet mode, no user interaction /passive Unattended mode - progress bar only /q[n|b|r|f] Sets user interface level n - No UI b - Basic UI r - Reduced UI f - Full UI (default) /help Help information Restart Options /norestart Do not restart after the installation is complete /promptrestart Prompts the user for restart if necessary /forcerestart Always restart the computer after installation Logging Options /l[i|w|e|a|r|u|c|m|o|p|v|x|+|!|*] i - Status messages w - Nonfatal warnings e - All error messages a - Start up of actions r - Action-specific records u - User requests c - Initial UI parameters m - Out-of-memory or fatal exit information o - Out-of-disk-space messages p - Terminal properties v - Verbose output x - Extra debugging information + - Append to existing log file ! - Flush each line to the log * - Log all information, except for v and x options /log Equivalent of /l* Update Options /update [;Update2.msp] Applies update(s) /uninstall [;Update2.msp] /package Remove update(s) for a product Repair Options /f[p|e|c|m|s|o|d|a|u|v] Repairs a product p - only if file is missing o - if file is missing or an older version is installed (default) e - if file is missing or an equal or older version is installed d - if file is missing or a different version is installed c - if file is missing or checksum does not match the calculated value a - forces all files to be reinstalled u - all required user-specific registry entries (default) m - all required computer-specific registry entries (default) s - all existing shortcuts (default) v - runs from source and recaches local package Setting Public Properties [PROPERTY=PropertyValue] Consult the Windows ® Installer SDK for additional documentation on the command line syntax. Copyright © Microsoft Corporation. All rights reserved. Portions of this software are based in part on the work of the Independent JPEG Group. the only option is OK and when i hit it, it DOESNT do anything Install fresh copy of Windows Installer: http://support.microsoft.com/kb/893803ok i installed, but the message comes up againThat error happens, when you try to install which application?the super anti spyware applicationPlease, proceed to step #2.i would love too but now my network has decided to not to work,Where are you posting from?my second computerDownload Malwarebytes' Anti-Malware on good computer, and install it on bad computer. Same with HijackThis. | |
| 2824. | Solve : Hotmail Compromised?? | 
| Answer» Win XP Home SP.3 AVG ZoneAlarm all updated. Hacking of Hotmail seems to be a regular occurrenceIt hasn't been for me...That's good news but SEE this lot. Yep mine was hit aswell this week and changing password seems to have worked, but you do need to then warn your contacts not to click on the links within any spoof mail. It will show up in sent mail who got mail. | |
| 2825. | Solve : Helo, logs are completed.? | 
| Answer» WAIT!!!!!! Thats not his comps LOG. . .crapola!!!!!!!!!!!!!!!!!!!!!!!! Thats my NEIGHBORS LOL Greesh I am too tired for this crap. But I believe the FIRST post was the ESET log for the comp in this thread. . . I remeber it was only a few lines. Ok. What's the STATUS of the computer now? | |
| 2826. | Solve : relevant knowledge back? | 
| Answer» 'relevant knowledge is back' after switching up Linksys for D-Link it seems to have gotten thru SuperDave HELPWhat is the PROBLEM with relevant knowledge?it's back, when we did all that work it went away, it's messing with IE again. We didn't remove all the LOGS off my desktop from our last session. Someone asked me if you gave me a clean bill of HEALTH and i didn't think so. I switched ROUTERS and it may have gotten in. I know it's here because it sends me emails to do surveys. You can download MailWasher here. You can use that to preview your email and delete any spam sent your way.  Someone asked me if you gave me a clean bill of health and i didn't think soThat's because you STOPPED responding. | |
| 2827. | Solve : Need help analyzing Hijackthis Log? | 
| Answer» I ran the program and everything i found was successively Fixed. The Laptop works better and the original problem hasn't show its self again so ill put that in the "WINNING" categorie. 
 •Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your COMPUTER. Please be patient as this can take some time. •When the scan completes, push •Push , and save the FILE to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt I ran the ESET scan and it said "no threats were found" GOOD. Let's do some cleanup. To uninstall ComboFix 
 (Note: Make sure there's a space between the word ComboFix and the forward-slash.) 
 Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are RUNNING on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. *********************************************** To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe. 
 ************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. **************************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in SPYBOT - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!looks like i have it all cleaned up. just one question... if i have the standard windows firewall, will a 3rd party firewall interfere with the original windows firewall?Quote if i have the standard windows firewall, will a 3rd party firewall interfere with the original windows firewall?Yes, it will. A third-party firewall is much safer than the generic Windows firewall but it also very intrusive. It's the price to pay for extra security. I will lock this thread. If you need it re-opened, please send me a pm. | |
| 2828. | Solve : HELP WINSPYWAREPROTECT? | 
| Answer» I scanned again with malwarebytes malware thing and this is what I got: | |
| 2829. | Solve : Hi Im trying to learn as much as I can.? | 
| Answer» Heeyy!! guess you probably know  there is another question. I use facebook and got a POST that SAYS that any person can get hack on facebook if any person that you have on your profile has that hacker on their list of friends so you I mean anyone can get hack by the hacker. Is in spanish so I wont post it UNLESS you know spanish or if you anyway!!! here what the hacker does I mean thats what the post I received says: Do not accept this person Luisa Ledezma or something it doest not matter what she does is that she formats your PC and then stoles your info and get your password from your mail. For me totally sounds way to risky for a hacker to be that dumb so I just want feedback. If you didnt understand or will like more info I can say I post a reply to get exactly what happens. oohh!!    Thanks for replying and just letting you know I GAVE up Ill just watch movies at the TV is good that the board does not allow to talk about it. I learn that watching those things on the web is just really BAD and can get anyone in a lot of trouble. Unfortunately, I don't know much about Facebook, but I'm sure, others do, so you may start new topic on this.Great!!! I will!!! but first Ill try to get more info see ya soon    No problem Find out; more,about activex, | |
| 2830. | Solve : Virus Clean-up? | 
| Answer» I see. No hurries Logfile of Trend Micro HijackThis v2.0.2 Everything looks fine, just one empty entry to fix. Yep, everything seems fine this one. Again, thanks a MILLION, Evil.Any time. It would be good to go ahead and flush the Restore Points and visit Windows Update to make sure you are current with the latest patches. Safe SURFING..... | |
| 2831. | Solve : Avira? | 
| Answer» I downloaded Avira fee edition, And every once In a while i get An ad that comes up that tries to get you to UPGRADE there PRODUCT. I like the ANTI virus and may upgrade soon, but In the mean time is there a way to stop that ad from popping up?Nope. thats the only bad thing about the FREE version. | |
| 2832. | Solve : Virus Allert in Time Bar? | 
| Answer» If at all possible, could someone check over my highjack this log for me? I'll be online for the next HOUR or so.. but then I have to go to bed.. Got an early start. | |
| 2833. | Solve : Trying to Fix my desktop? | 
| Answer» I own an HP Pavillion desktop that my sisters-in-law got a virus on when i let them borrow it, and it crashed the computer. Now I am trying to figure out how in the heck to wipe the hard drive clean and re-install Windows XP professional so that I can have a system up and running at my house, because I work at home. Best buy geek squad WANTS to charge me an arm and a leg and for the price they quoted me i could go buy a new desktop, but i am not MADE of money unfortunately and either have to suffer GOING ten miles to my parents house or get this thing fixed. Help!You could do a system restore which if anything was added when this happen it WOULD be gone, yeah they usually do cause they try an seem like there better.I cannot even get the start screen to come up when I turn on the computer. I have tried going into the dos system, but I am not that computer literate, I just did what I was told by a friend of mine. He said to load the start up disk for XP professional and start the computer and then it should prompt me, but nothing comes up but a blank screen.Check your cds there should be one. If nothing else try an get a boot disk for your operating system but you need a floppy drive + floppies.1. you can try booting into safe mode, once you are in safe mode I would turn off system restore as the virus could be in the restore points as well once that is done you can run your anti virus and see if you can remove it. Once done with this step reboot your computer and turn system restore back on. | |
| 2834. | Solve : Mywebsearch mess!? | 
| Answer» Hello CH and Thanks ahead of time for your help and advice! | |
| 2835. | Solve : I have Question? | 
| Answer» When you run virus scan on your computer , comes up saying have Threats, are they viruses?=( I thought  the anti-virus would have alerted me if I had viruses. 
 
 
 | |
| 2836. | Solve : Page not found!? | 
| Answer» The O17 - HKLM\ entries are from a wareout infection and need to be fixed. 
 When you run fixwareout, just follow the prompts, you will need to restart when prompted. After rebooting (restart) back into normal boot mode. Make sure you have all web browsers closed. 
 ---------- Now post a fresh Hijackthis log.Hi, I didn't buy Super System Helper and I cant find it anywhere on my computer to remove it either??...?? I couldn't find WinFixer2006 to remove that either??...?? I followed the rest of your intructions though although I couldn't find P2P Networking, e.exe,ztbrvp.exe to remove them either??.... That's fine. Post new HJT log, please.Fixwareout log as requested: Username "Ali" - 16/07/2008 16:38:09 [Fixwareout edited 9/01/2007] ~~~~~ Prerun check Could not FLUSH the DNS Resolver Cache: Function failed during execution. System was rebooted successfully. ~~~~~ Postrun check HKLM\SOFTWARE\~\Winlogon\ "System"="" .... .... ~~~~~ Misc files. .... ~~~~~ Checking for older varients. .... ~~~~~ Current runs (hklm hkcu "run" Keys Only) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe" "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe" "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe" "AGRSMMSG"="AGRSMMSG.exe" "THotkey"="C:\\Program Files\\Toshiba\\Toshiba Applet\\thotkey.exe" "Tvs"="C:\\Program Files\\TOSHIBA\\Tvs\\TvsTray.exe" "TPSMain"="TPSMain.exe" "NDSTray.exe"="NDSTray.exe" "SmoothView"="C:\\Program Files\\TOSHIBA\\TOSHIBA Zooming Utility\\SmoothView.exe" "PadTouch"="C:\\Program Files\\TOSHIBA\\Touch and Launch\\PadExe.exe" "dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe" "YBrowser"="C:\\PROGRA~1\\Yahoo!\\browser\\ybrwicon.exe" "DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033" "CmSkype"="\"C:\\Program Files\\USBPhone\\USBPhone.exe\" RUNSTART" "Sony Ericsson PC Suite"="\"C:\\Program Files\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions" "Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.2\\Apps\\apdproxy.exe\"" "LogitechCommunicationsManager"="\"C:\\Program Files\\Common Files\\LogiShrd\\LComMgr\\Communications_Helper.exe\"" "LogitechQuickCamRibbon"="\"C:\\Program Files\\Logitech\\QuickCam\\Quickcam.exe\" /hide" "Super System Helper"="C:\\Program Files\\igoodsoft\\Super System Helper\\SystemTool /1" "NBKeyScan"="\"C:\\Program Files\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\"" "Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\"" "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\"" "EnGraph QuickTimeKiller"="C:\\Program Files\\EnGraph\\QuickTimeKiller\\QuickTimeKiller.exe" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="C:\\Program Files\\TOSHIBA\\TOSCDSPD\\toscdspd.exe" "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\lib\\NMBgMonitor.exe\"" "Disk Cleaner"="\"C:\\Program Files\\Disk Cleaner\\DiskCleaner.Exe\" /boot" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" .... Hosts file was reset, If you use a custom hosts file please replace it... ~~~~~ End report ~~~~~ HJT log as requested: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:23:39, on 16/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ACS.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe C:\Program Files\TOSHIBA\Tvs\TvsTray.exe C:\WINDOWS\system32\TPSMain.exe C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe C:\Program Files\D-Tools\daemon.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/ R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [CmSkype] "C:\Program Files\USBPhone\USBPhone.exe" RUNSTART O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide O4 - HKLM\..\Run: [Super System Helper] C:\Program Files\igoodsoft\Super System Helper\SystemTool /1 O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [EnGraph QuickTimeKiller] C:\Program Files\EnGraph\QuickTimeKiller\QuickTimeKiller.exe O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Disk Cleaner] "C:\Program Files\Disk Cleaner\DiskCleaner.Exe" /boot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab O16 - DPF: {070CA17A-4BD2-4612-83B4-32B1B9159B47} (ULiveCtrl Control) - http://uc.sina.com.cn/download/live/weblive2.4.0.0.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://totalikinki69.spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {71057C18-0507-4747-86BC-E11CE7512C5F} (mailhelper Class) - https://register.btinternet.com/templates/btmailcontrol013.cab O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.filelodge.com/ImageUploader3.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - https://register.btinternet.com/templates/btwebcontrol028.cab O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: Print Spooler Service (dorairtoe) - Unknown owner - C:\WINDOWS\system32\e.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE -- End of file - 11904 bytes Looks better but there is one that keeps coming back. Open Hijackthis and select Do a system scan only. Place a check mark next to the following entries: (if there) O23 - Service: Print Spooler Service (dorairtoe) - Unknown owner - C:\WINDOWS\system32\e.exe Important: Close all windows except for Hijackthis and then click Fix checked. Exit Hijackthis and run CCleaner. ---------- Go to Start > Run and type Notepad.exe then click OK. Copy and paste the following text within the quote box into the new Notepad file. Quote @ECHO OFF In Notepad select File and Save as Save it to your Desktop as fixme.bat making sure that the Save as type field says All files. Next double click FixService.bat to run it. A black box should open and close after a short time, this is normal. Do not continue until the black box has closed When complete delete the FixService.bat file on the desktop. ---------- Download OTMoveIt2 by OldTimer 
 
 [kill explorer] 
 
 ---------- Next post add OTMoveIt log How is everything now?Results of OTMoveIt2, thanks. Explorer killed successfully C:\WINDOWS\system32\e.exe moved successfully. < EmptyTemp > File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_668.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. Temp folders emptied. IE temp folders emptied. Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07172008_112529 Files moved on Reboot... C:\WINDOWS\temp\Perflib_Perfdata_668.dat moved successfully. File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot. Did you add the extra files to OTMoveIt? C:\WINDOWS\temp\Perflib_Perfdata_668.dat File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt ---------- 1. Double click OTMoveIt2.exe to launch it. If using Vista Right-Click OTMoveIt and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 
 ---------- Use the Kaspersky Online Scanner - http://www.kaspersky.com/virusscanner 
 
 When the scan is done, in the Scan is complete window, any infection is displayed. There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As 
 Copy and paste the Kaspersky Online Scanner Report in your next reply.Link fixed.I didnt add any extra files to OTMoveIt.....? Followed all the instructions and here is the report form the KScan as requested. Thanks. -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Thursday, July 17, 2008 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, July 17, 2008 16:15:59 Records in database: 963552 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 66140 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 02:07:48 No malware has been detected. The scan area is clean. The selected area was scanned. Looks good. Final steps and advice. Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed. 
 Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software. 
 ---------- Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates. If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update. ---------- Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum. Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I would suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running MOZILLA based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Ok all that done too. Can I just ask please, all those programs that I've used and put on my desktop.... which ones do I need to keep on and which do I need to remove??... CtfmonRemover KScan.txt Hijack This CCleaner SuperAntispyware Malwarebytes' Anti-Malware I would put them in a folder, all the programs and update every week.I just want to say a great big THANKYOU to both "Broni" and "Evilfantasy" for all the 1 on 1 help I have received. I very much appreciate the personal time you both have GIVEN up to help me. So once again, thankyou both very very much!!!!!! Also, thankyou to everyone else who has taken the time to reply too.your welcome 3 piece and feel free to COME and chat in the Offtopic section... | |
| 2837. | Solve : I Will Have A Panic Attack If I Don't Get Help, NOW!? | 
| Answer» Okay, here it is. I can't turn on my FirewallNorton's? From HJT log, I can see it's ON. The log looks better again, but we're not done yet. Open HJT again, and checkmark: - O4 - HKLM\..\Run: [RRT-Auto] C:\DOCUME~1\Sean\LOCALS~1\Temp\Temporary Directory 2 for RRT[1].zip\RRT.exe auto - O4 - HKCU\..\Run: [HijackThis STARTUP scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan - O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe - O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE Click "Fix checked". Restart computer. Post new HJT log. Here's the new HTJ log. [recovering disk space -- attachment deleted by admin]Download, and install Unlocker: http://ccollomb.free.fr/unlocker/ It'll install under right click menu. Open Windows Explorer. Navigate to C:\Program Files. Right click on MyWebSearch folder. Click Unlocker Select Delete from drop-down menu: Click OK. MyWebSearch will refuse to be deleted, but Unlocker will give you an option to delete on reboot. Select that option. Restart computer. Post new HJT log. hello i just read this guys message and I am having the same problem I let my friend use my computer and he downloaded something and this same virus got onto my computer but before i could do what he did my computer shutdown and now it wont start windows it wont go into safe mode and all that comes on is a blue screen that tells me my computer is corrupted and it also says *** STOP: 0x0000007B (0xf8a95528, 0x0000034, 0x00000000, 0x00000000) if anyone could help me please i need it!!!!!!!! big matt You need to start your own topic.Hello, I've recently been away from computer, but I'm here now, with a new problem. I don't know if it because of the virus, because all seems, (or seemed) well until the power was lost. I'm going to start another thread... | |
| 2838. | Solve : AVG or Mcafee? | 
| Answer» I have Mcafee viruscan Enterprise 8.0.0 anti virus installed on my cpu. I downloaded Avg free for my GIRLFRIEND and really liked it. My question is which ones better Avg or mcafee? Or which one would admins recommend?.Neither. I have Mcafee viruscan Enterprise 8.0.0 anti virus installed on my cpu. I downloaded Avg free for my girlfriend and really liked it. My question is which ones better Avg or mcafee? Or which one would admins recommend?. ? Since when could you do that?Don - Please stop spamming the FORUMS. You can't promote your web site without permission from the site owner. Thanks. | |
| 2839. | Solve : which is better? | 
| Answer» Spyware Doctor STARTER Edition 5.5 or SPYBOT.I certainly PREFER Spybot - Search & Destroy, but it's all a matter of opinion.Spyware Doctor is too resource hungry. And I can't really justify paying for a program when there are so many good free alternatives.tyIts unanamos spybot is defintly better. I never had any problems that I COULD say an caught alot of nasties for me. | |
| 2840. | Solve : updating my antivivrus programme? | 
| Answer» how can i remember my ID and PASSWORD for updating my intivirus programme?What AV PROGRAM? | |
| 2841. | Solve : webroot? | 
| Answer» will ENDING the PROCESS "wrsssdk.exe" stop webroot? i did this and the webroot icon left notification AREA by the clock. i was just wondering what EXACTLY it will stop.http://www.bleepingcomputer.com/startups/WRSSSDK.exe-11742.html | |
| 2842. | Solve : I have a trojan...? | 
| Answer» THATS it besides looking at the links. Cookies are nothing to WORRY about. Some people like to make a lot of noise about them but all they are is small .txt files. They can't do any harm. Check this out: Are cookies really SPYWARE and are they dangerous? Run CCleaner occasionally, once a day if you like to keep all of the JUNK out. Glad EVERYTHING is back to normal. Let us know if anything else pops up.Thats good news. I want you know that Im really REALLY grateful for the knowledge. Youre a genius, and very impressive. This website is really sweet. Its refreshing to get something for free these days. Just checking a bag on the airplane costs money, ya know. I will recommend this site, and drop your name to anyone I know that gets in trouble. Thanks again!!!Thanks for the kind words! That makes it all worth while. Safe surfing...... One last thing. Can i now remove these programs I downloaded during the clean up? CCleaner HiJackThis MalwareBytes ANTI Malware SuperAnti spyware Free Edition I have upgraded to AVG 8.0. Will that alone be sufficient protection? Also, the super anti spyware has two infected files in quarantine. Is it better to remove (delete) or restore? Seems like deleting is an obvious choice it it was found to be infected. I dont understand why I would restore suh a file Empty the quarantine. Uninstall HijackThis. Run scans with SAS and MBAB every other week or so. | |
| 2843. | Solve : need to disable automatic virus update? | 
| Answer» i have got AVG 8.0 anti virus. i have disabled the automatic updates, but it still checks for the updates every time i switch on the computer and connect directly to the internet. i cant access the option of checking for updates periodically. the option of checking for updates daily is checked and i cant disable it.Quote i have disabled the automatic updatesWhy? It's very important for your computer safety to have them ON. Broni is right. Disabling the updates is almost the same as disabling the AV itself. It is extremely important. That said I'm pretty sure the free version doesn't have that option. If I remember correctly AVG 7.5 free had that option disabled, but it's available in AVG 8.0 free: the screen which u have shown does come, but even if i uncheck the 'start automatic updates' option the 'At the specific time interval' option is selected, i can undo that. i have disabled it because it checks for updates everyday, and usually no update is found. i intend to manually update it about once a week. That's not true. AVG updates every day (at least), and this is for your own good. I have no more comments on this subject.Then there should be a update once a week at a specific time option right?Quote from: !~*:.Pink Floyd.:*~! on July 16, 2008, 07:59:39 PM Then there should be a update once a week at a specific time option right?Microsoft releases a bunch of updates at the end of every month though. *clap* *clap* *clap* *clap* Broni --> 13,000The time for resetting is coming...LOLThere is a difference in program updates and definition updates. The program updates don't happen very often but the definition (virus detection database) updates happen very often, usually daily.Quote from: evilfantasy on July 16, 2008, 08:11:09 PM (virus detection database) updates happen very often, usually daily.My Kaspersky gets a new update available every 3 hours. Very smooth and uninterrupted updating too.That's another thing I LIKE about AVAST. Quote By DEFAULT, avast checks for virus definitions (IAVS or VPS or database) once every 4 hours when you PC is on. I think it was yesterday that I saw it update 2 times within about an 8 HOUR period. Always ready for any new threats!Out of curiosity, nirma...do you have dial-up or broadband?broadband, but with a download limit.Quote from: sr_nirma on July 18, 2008, 06:26:51 AM broadband, but with a download limit. Hmm, nevermind, I was just wondering because AVG 8 seems to have a lot of issues with dial-up users. Personally, with all of the problems I've been seeing lately, I'm actually starting to advise against AVG 8. I've always been a strong supporter of AVG, but they've really dropped the ball with this last upgrade. | |
| 2844. | Solve : I NEED HELP WITH COMPUTER PROBLEM? | 
| Answer» Everything i click on says not responding i cant install anything new on my computer the sound is not working.. internet explorer is not working. My computer isnt slow or anything dosent pop up with weird messages programs are just not working properly. I have windows xp home edition with service pack 2.  | |
| 2845. | Solve : Can't access Emails? | 
| Answer» I have Windows XP1 Home and Mozilla Thunderbird on Broadband. For a long time now when I launch Thunderbird and click GET MAIL a window come on with the heading: ALERT! "This folder is being processed. Please wait until processing is complete to get messages"  | |
| 2846. | Solve : My friends computer is infected by something? | 
| Answer» iam sorry BRONI its just so frustrating with this computer getting so slow  and i just cant wait to get it fixed HELP ME!. Anyways i do what you say and remove the thing then i restart but thing keeps coming back i dunno knkow why then i remove it again with the program you told me to and restart the i do the hijack thing and it says its still in there!My friend said ty for helping her. btw I must admit, I MADE a mistake. | |
| 2847. | Solve : virus caused loss of some windows functions? | 
| Answer» I have removed the impact of antivirus 2008 and have recovered most functions. F8 safe mode is not displayed as an option.. just F1 and F10 You're doing something wrong... To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears: nope not there HP hides the option under esc next im trying to get the software but keep getting page cannot be displayed. will try to save from another pc and than install. also i keep getting redirected when going to some websites. ie. www.websire.com redirected to some other totally different page usually the the rediect name is a long stream of garbage.Quote nope not there HP hides the option under escNope, by pressing Esc, you probably can get to BIOS, and Recovery Partition. Anyway, we'll try to solve it later. Run Malwarebytes, then, post its log. When done, fresh HJT log. Both in Normal Mode. Don't worry about other problems, now. Your computer is infected, remember? sorry for the delay in responding making progress and its slow this was one nasty virus... So far i have run AVG and seems to have the virus out. I have also run superantispyware. that too has removed some things. I have identified thru the regedit find 3 entries containing the VIRUS ALERT! text string. and i have corrected the registry ( i am a mainframe tech i have no fear lol ). I have also found that the virus disabled several START entries and I have got those back. Also the ALL PROGRAMS on the start menu i re-enabled in the registry variable NoStartMenuMorePrograms Also the F8 OS load boot screen is back issues remaining still no harddrive icon on the my computer ( removeables are displayed ) the most annoying is the blocking/redirect of websites. i find that some can be accessed thru google cache. others like update.microsoft.com are blocked anbd page can not be displayed. I have gone thru the IE6 options and deleted all Restricted Sites ( there was a very long list ) I even put some sites in the Trusted Site list and disabled the windows firewall. w/o having success. I also deleted all the toolbars. The addons (?) is that something to consider. also in HJT i see alot of BHO w/o files I will download the malware progam you suggested ( need to use another pc ). also FYI seems that SPYBOT/sd was also hit ( some of its programs are in quarantine ) here is the latest HJT Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:51, on 7/17/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\NETGEAR\WG111T\wlan111t.exe C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\nda.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: {10fdf994-1605-5439-6e14-7ca1c5ecb331} - {133bce5c-1ac7-41e6-9345-5061499fdf01} - (no file) O2 - BHO: (no name) - {21461821-DED9-4D67-BE47-C9800C50B7FE} - (no file) O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {41F39511-418E-4DCB-AA1A-248F6DA0A451} - (no file) O2 - BHO: (no name) - {4930DF70-4618-429B-9BA7-5A3208101307} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {698F8AB4-660F-48F6-2D75-4AB6033DF1BF} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: (no name) - {76FB9208-8EC2-4F9F-89D0-37AF10ECD2EC} - (no file) O2 - BHO: (no name) - {771FF2EC-39CF-4BF2-8D0B-DE19D62C8C02} - (no file) O2 - BHO: (no name) - {79492E60-FC25-42BC-9752-522C3F4A02AD} - (no file) O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: (no name) - {AFB2C802-BC28-4B89-AB07-23D785A369D0} - (no file) O2 - BHO: (no name) - {EC950B42-DD0B-40B3-AAFB-3139A2A85308} - (no file) O2 - BHO: (no name) - {F8AC36D7-F602-4B69-99B5-2A812E05779F} - (no file) O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: HP Organize.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ? O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe O4 - Global Startup: VPN Client.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU) O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU) O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://qp.acsonline.com/qp2.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - https://webdl.symantec.com/activex/symdlmgr.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138551828593 O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx O16 - DPF: {CAA057EE-809B-48E4-BE9C-367C32486C0D} (Crystal Print Control 10.0) - https://acsreports.acs-inc.com/crystalreportviewers10/ActiveXControls/PrintControl.cab O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mymeetings.webex.com/client/v_mywebex-wbs-mciprodins/webex/ieatgpc.cab O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://livewc02.custhelp.com/7520-b289h-turbotax/rnl/java/RntX.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: eAcceleration Notification Service (eac_notifysvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: MSSysInterv - Unknown owner - c:\winself.exe (file missing) O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe -- End of file - 11441 bytes Don't play too much with registry, unless you're 100% sure what you're doing. I'd like to see Malwarebytes log, and then, new HJT log.whewwwwwww finally after hoop jumping and a few hours of configurations things are back to normal. just lost some desktop icons. malwarebytes and superantispyware did the tricks. i discovered in searching ariound thru my pc that the virus attacke current user settings. when i logged on to my guest account i could see the hard drive and some other functions. in order to install mwb and sasw i had to create a new admin account. after running mwb under the temp admin account this cleared the brwoser issue ( redirects ). The homepage i found thru the privacy report had a couple bogus garbage url's ie absjubvytuiopon.com I than ran mwb against my regulra logon and that restorrd by ability to see the hard drives and the account logon buttons on the START. atabase version: 930 Windows 5.1.2600 Service PACK 2 19:27:07 7/20/2008 mbam-log-7-20-2008 (19-26-07).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 132437 Time elapsed: 34 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 5 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ADP (Rogue.Multiple) -> No action taken. Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives (Hijack.Drives) -> Bad: (12) Good: (0) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders (Hijack.Explorer) -> Bad: (1) Good: (0) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCPL (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\clbinit.dll (Trojan.Vundo) -> No action taken. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:51, on 7/20/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\NETGEAR\WG111T\wlan111t.exe C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\nda.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: {10fdf994-1605-5439-6e14-7ca1c5ecb331} - {133bce5c-1ac7-41e6-9345-5061499fdf01} - (no file) O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: HP Organize.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ? O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe O4 - Global Startup: VPN Client.lnk = ? O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU) O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU) O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://qp.acsonline.com/qp2.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - https://webdl.symantec.com/activex/symdlmgr.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138551828593 O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx O16 - DPF: {CAA057EE-809B-48E4-BE9C-367C32486C0D} (Crystal Print Control 10.0) - https://acsreports.acs-inc.com/crystalreportviewers10/ActiveXControls/PrintControl.cab O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mymeetings.webex.com/client/v_mywebex-wbs-mciprodins/webex/ieatgpc.cab O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://livewc02.custhelp.com/7520-b289h-turbotax/rnl/java/RntX.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: eAcceleration Notification Service (eac_notifysvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe -- End of file - 10273 bytes I'm glad to see progress... However Malwarebytes log shows: "No action taken" after each line. Most likely, it's the log from before fixes were applied. If so, please post correct log. Make sure, HJT log is from after all fixes were done.i had to run mwb twice here is the first run under the master admin account i had to create Malwarebytes' Anti-Malware 1.20 Database version: 930 Windows 5.1.2600 Service Pack 2 12:20:39 AM 7/20/2008 mbam-log-7-20-2008 (00-20-38).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 132729 Time elapsed: 42 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 12 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 18 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssysinterv (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\sqvgnrpx.bsol (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\sqvgnrpx.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\PCHealthCenter (Trojan.Fakealert) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\PCHealthCenter\0.exe._eac_qt_ (Trojan.Fakealert) -> Quarantined and deleted successfully. C:\Program Files\PCHealthCenter\0.gif (Trojan.Fakealert) -> Quarantined and deleted successfully. C:\Program Files\PCHealthCenter\1.gif (Trojan.Fakealert) -> Quarantined and deleted successfully. C:\Program Files\PCHealthCenter\2.gif (Trojan.Fakealert) -> Quarantined and deleted successfully. C:\Program Files\PCHealthCenter\3.gif (Trojan.Fakealert) -> Quarantined and deleted successfully. C:\Program Files\PCHealthCenter\5.exe._eac_qt_ (Trojan.Fakealert) -> Quarantined and deleted successfully. C:\Program Files\PCHealthCenter\sc.html (Trojan.Fakealert) -> Quarantined and deleted successfully. C:\Program Files\PCHealthCenter\sex1.ico (Trojan.Fakealert) -> Quarantined and deleted successfully. C:\Program Files\PCHealthCenter\sex2.ico (Trojan.Fakealert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sex2.ico (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\lfn.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\clbdll.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\drivers\clbdriver.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\HP_Owner\Application Data\TmpRecentIcons\Vista Antivirus 2008.lnk (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\HP_Owner\results.txt (Malware.Trace) -> Quarantined and deleted successfully. HJT log above was after everything was corrected just encase here is hjt from the master admin account (my regular account logon is terry ) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:20:09 PM, on 7/20/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\NETGEAR\WG111T\wlan111t.exe C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\AVG\AVG8\aAvgApi.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop&parm1=seconduser R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop&parm1=seconduser R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop&parm1=seconduser R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop&parm1=seconduser R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop&parm1=seconduser R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: {10fdf994-1605-5439-6e14-7ca1c5ecb331} - {133bce5c-1ac7-41e6-9345-5061499fdf01} - (no file) O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S O4 - HKUS\S-1-5-21-1775530687-154687343-135775073-1009\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S (User 'HP_Owner') O4 - HKUS\S-1-5-21-1775530687-154687343-135775073-1009\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'HP_Owner') O4 - HKUS\S-1-5-21-1775530687-154687343-135775073-1009\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User 'HP_Owner') O4 - S-1-5-21-1775530687-154687343-135775073-1009 Startup: HP Organize.lnk = ? (User 'HP_Owner') O4 - S-1-5-21-1775530687-154687343-135775073-1009 User Startup: HP Organize.lnk = ? (User 'HP_Owner') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ? O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe O4 - Global Startup: VPN Client.lnk = ? O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU) O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU) O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://qp.acsonline.com/qp2.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - https://webdl.symantec.com/activex/symdlmgr.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138551828593 O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx O16 - DPF: {CAA057EE-809B-48E4-BE9C-367C32486C0D} (Crystal Print Control 10.0) - https://acsreports.acs-inc.com/crystalreportviewers10/ActiveXControls/PrintControl.cab O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mymeetings.webex.com/client/v_mywebex-wbs-mciprodins/webex/ieatgpc.cab O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://livewc02.custhelp.com/7520-b289h-turbotax/rnl/java/RntX.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: eAcceleration Notification Service (eac_notifysvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe -- End of file - 11964 bytes | |
| 2848. | Solve : Re: Some big computer issues (computer #2 - aunt)? | 
| Answer» I INSTALLED avira free anyways and the volume bug is fixed thank you so much . ANyways I will post BACK if the other bugs (windows freezing,and STUFF appear again) Thank you Broni You're very welcome  | |
| 2849. | Solve : please help me fix this problem hijack this? | 
| Answer» Logfile of The Avenger Version 2.0, (c) by Swandog46 
 . The above procedure will: 
 
 ---------- 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 ---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed. 
 Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software. 
 ---------- How is everything now?this is flipping back so fast now that its not even funny i have to keep hitting forwarding button Post a fresh HijackThis log please.Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:14:42 PM, on 7/26/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Google\Google Desktop SEARCH\GoogleDesktop.exe C:\Program Files\Digital Media Reader\readericon45G.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe C:\WINDOWS\PixArt\PAC207\Monitor.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Ascentive\Performance Center\ApcMain.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE C:\sniper.exe\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.armstrongmywire.com/index.php R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\RunOnce: [OOBEDDDemise] cmd /x /c erase C:\WINDOWS\System32\oobe\msoobe.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe -m O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user') O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table MANAGER (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS -- End of file - 8391 bytes Just so I understand. Does it do this when you open IE, or when you try to go to another page in IE?as soon as i open the internet and try to go to this or anything elseSo it's closing or do you get to your Homepage at all? I'm working on another fix.whats happening help im going crazyDownload Combofix by sUBs from one of the below links. Important! Combofix.exe MUST be saved to and ran from the Desktop. Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 
 Code: [Select]KillAll:: REGISTRY:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2273231-e6d2-11da-8f08-806d6172696f}] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick combofix's window while it is running. That may cause your system to freezeComboFix 08-07-26.1 - Owner 2008-07-26 19:34:29.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.173 [GMT -4:00] Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-06-26 to 2008-07-26 ))))))))))))))))))))))))))))))) . 2008-07-26 18:40 . 2008-07-26 18:40d--------C:\WINDOWS\system32\oobe 2008-07-26 14:08 . 2008-07-26 14:08d--------C:\Documents and Settings\Owner\Application Data\Malwarebytes 2008-07-26 14:07 . 2008-07-26 14:08d--------C:\Program Files\Malwarebytes' Anti-Malware 2008-07-26 14:07 . 2008-07-26 14:07d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-26 14:07 . 2008-07-23 20:0938,472--a------C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-07-26 14:07 . 2008-07-23 20:0917,144--a------C:\WINDOWS\system32\drivers\mbam.sys 2008-07-26 10:24 . 2008-07-26 19:14d--------C:\sniper.exe 2008-07-26 10:22 . 2008-07-26 10:22d--------C:\Program Files\Trend Micro 2008-07-26 04:34 . 2008-07-26 12:04d--h-----C:\$AVG8.VAULT$ 2008-07-26 04:32 . 2008-07-26 15:43d--------C:\WINDOWS\system32\drivers\Avg 2008-07-26 04:32 . 2008-07-26 17:54d--------C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR 2008-07-26 04:32 . 2008-07-26 04:3297,928--a------C:\WINDOWS\system32\drivers\avgldx86.sys 2008-07-26 04:32 . 2008-07-26 04:3276,040--a------C:\WINDOWS\system32\drivers\avgtdix.sys 2008-07-26 04:32 . 2008-07-26 04:3212,936--a------C:\WINDOWS\system32\drivers\avgrkx86.sys 2008-07-26 04:32 . 2008-07-26 04:3210,520--a------C:\WINDOWS\system32\avgrsstx.dll 2008-07-26 04:31 . 2008-07-26 04:31d--------C:\Program Files\AVG 2008-07-26 04:31 . 2008-07-26 12:39d--------C:\Documents and Settings\All Users\Application Data\avg8 2008-07-24 16:53 . 2007-08-10 12:56303,104--a------C:\WINDOWS\system32\ciplListBar.ocx 2008-07-24 16:53 . 2007-08-10 12:56155,648--a------C:\WINDOWS\system32\ciplImageList.ocx 2008-07-24 16:26 . 2008-07-24 16:26d--------C:\Documents and Settings\Owner\Application Data\Ascentive 2008-07-24 16:09 . 2008-07-24 16:09d--------C:\Program Files\RegCure 2008-07-24 03:40 . 2008-07-24 03:40d--hs----C:\found.000 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-26 21:53---------d-----wC:\Documents and Settings\All Users\Application Data\WholeSecurity 2008-07-26 17:22---------d-----wC:\Program Files\Winzy 2008-07-26 17:22---------d-----wC:\Documents and Settings\All Users\Application Data\Viewpoint 2008-07-26 17:21---------d-----wC:\Program Files\Java 2008-07-26 16:59---------d-----wC:\Program Files\McAfee 2008-07-26 16:56---------d-----wC:\Documents and Settings\All Users\Application Data\McAfee.com 2008-07-26 08:27---------d--h--wC:\Program Files\InstallShield Installation Information 2008-07-26 08:27---------d-----wC:\Program Files\Ascentive 2008-07-24 18:31---------d-----wC:\Program Files\LimeWire 2008-07-24 18:29---------d-----wC:\Program Files\BigFix 2008-07-19 18:19---------d-----wC:\Documents and Settings\Owner\Application Data\WholeSecurity 2008-07-18 00:544,724-c--a-wC:\Documents and Settings\Owner\Application Data\wklnhst.dat 2008-07-16 03:45---------d-----wC:\Documents and Settings\Owner\Application Data\WeatherBug 2008-07-13 00:12---------d--h--wC:\Documents and Settings\Owner\Application Data\Move Networks 2008-06-20 17:41245,248----a-wC:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45360,320----a-wC:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44138,368----a-wC:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52225,920----a-wC:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-14 02:42---------d-----wC:\Program Files\Battle For Troy 2008-06-13 13:10272,128------wC:\WINDOWS\system32\drivers\bthport.sys 2008-06-02 07:29---------d-----wC:\Program Files\Disney 2008-06-02 03:17---------d-----wC:\Program Files\AIM6 2008-05-28 01:22---------d-----wC:\Documents and Settings\Owner\Application Data\QQ Games Plugin 2008-05-27 22:58---------d-----wC:\Program Files\Tencent 2008-05-27 22:57---------d-----wC:\Documents and Settings\All Users\Application Data\AOL Downloads 2008-05-07 05:181,287,680----a-wC:\WINDOWS\system32\quartz.dll 2008-04-29 17:14208,896----a-wC:\WINDOWS\system32\ConTest.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-12 17:26 68856] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 16:32 8699904] "Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 17:43 4670704] "Performance Center"="C:\Program Files\Ascentive\Performance Center\ApcMain.exe" [2008-03-13 17:35 3239936] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 06:01 32768] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-05-18 21:10 169984] "readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 21:44 139264] "eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2008-04-20 17:29 652528] "Monitor"="C:\WINDOWS\PixArt\PAC207\Monitor.exe" [2006-11-03 11:01 319488] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-26 04:32 1235736] "RTHDCPL"="RTHDCPL.EXE" [2006-04-04 20:44 16120832 C:\WINDOWS\RTHDCPL.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "OOBEDDDemise"="erase" [X] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Power2GoExpress"="NA" [X] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 16:32 8699904] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "C:\\Program Files\\AIM6\\aim6.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-07-26 04:32] R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-26 04:32] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-26 04:32] R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-26 04:32] R3 PAC207;PC Camera;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-29 13:30] S2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-26 04:32] S2 W55U01;WINBOND W55U01 USB;C:\WINDOWS\system32\Drivers\W55U01.sys [2005-08-12 09:58] S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys [2006-09-27 16:12] . Contents of the 'Scheduled Tasks' folder 2008-07-26 C:\WINDOWS\Tasks\RegCure Program Check.job - C:\Program Files\RegCure\RegCure.exe [2008-04-21 17:21] 2008-07-24 C:\WINDOWS\Tasks\RegCure.job - C:\Program Files\RegCure\RegCure.exe [2008-04-21 17:21] . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-26 19:40:40 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce OOBEDDDemise = cmd /x /c erase C:\WINDOWS\System32\oobe\msoobe.exe????C?w????e??i?wis??H???*&?|l?&?|??-w?`??|?&?|??&?|B%?|?|?$?|???-wC scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe C:\WINDOWS\system32\wdfmgr.exe C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe . ************************************************************************** . Completion time: 2008-07-26 19:52:11 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-26 23:51:17 Pre-Run: 63,690,960,896 bytes free Post-Run: 63,639,945,216 bytes free 160--- E O F ---2008-07-25 00:46:52 now that you had me to put that combofix back in its not going crazy i will be back on tomorrow i cant stand to sit here any longer i had a hip replacement and im in very bad pain thank you for all your help and i hope to see you tomorrow No problem, I'm about done in for now also. We've been at this for a while now! Tomorrow please run this online scan. Run the F-Secure Online Scanner for Viruses, Spyware and RootKits. Note: This Scanner is for Internet Explorer Only! 
 | |
| 2850. | Solve : Re: HELP Antivirus 2008 infection? | 
| Answer» TURN off Tea-Timer. To be honest I never use Tea-Timer and will never ADVISE anyone to use it. It slows down the PC and doesn't offer enough protection to bother with. Try cleaning your temp files and then try to download and INSTALL it again. 1) Click Start, Programs (or All Programs), Accessories, System Tools, Disk Cleanup 2) Choose the correct drive usually C:\ 3) CHECK the boxes in the list and delete the filesok I have done the rest now do I download the antivirus again and should I keep spybot I like the superantivirus do I need bothSpybot is good to keep for the Immunize feature. Update it about once a week and always click the Immunize button as well for added security. You can keep SuperAntiSpyware and run it occasionally to make sure nothing has crept back in. Try to download a fresh copy of the antivirus, the other one is CORRUPTED for some reason. | |