 
                 
                InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 3051. | Solve : Frozen!!!!? | 
| Answer» Yes sir!!  Have you ever seen how I look!!!!!!!!!!May I? Better?::: NUDGES Broni, whispers ::: She's already a princess. Yup I like that. You may make it as your new avatar | |
| 3052. | Solve : got around 500 viruses on my pc? | 
| Answer» Looks good now. 
 . The above procedure will: 
 
 ---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER CLEANING your system will ENABLE your computer to roll-back to a clean working state if needed. 
 ---------- Use the Secunia Software Inspector to check for out of date software. 
 ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. To prevent unknown applications from being installed on your computer install WinPatrol 2008 Using Winpatrol to protect your computer from malicious software Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam. SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. Using SpywareBlaster to protect your computer from Spyware and Malware Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.thanks so much my computers now running so much faster than it was before! i will be sure to tell anyone i know having computer problems to try out this site, and i will do the last set of instructions when i get home i found this site so helpful on my computer i have decided to use it on my girlfriends laptop too (the laptop runs soooo slowly and im sure it must have something to do with her having viruses on it) the problem is she uses windows vista, and im used to windows XP, although i didnt think i would have any problem finding the add/remove programs it doesnt seem to be on the computer... (im going through the instructions i did last time to sort my own) any help would be greatly appreciated never mind found it | |
| 3053. | Solve : Spyguarder removal? | 
| Answer» Somehow I have downloaded something called spyguarder, it tells me my computer is infected with all sorts and every page I try to enter is an infected site. | |
| 3054. | Solve : new threat? | 
| Answer» when ever i start my computer (after windows opening) two dialogue box open and says that " script file c:\heap41a\ script1.txt does not exist creat it now" and other one TELLING that "script file c:\heap41a\ reproduce.txt does not exist creat it now" how can i ruled out this Do you use a FLASH drive? If so. 
 ---------- Please go to this thread and read the instructions for posting the required logs. Once the logs are posted a malware specialist will be along to assist you in further removal instructions. | |
| 3055. | Solve : Help Me please!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!? | 
| Answer» i need some help from you if you can help me ! My computer is infected with NVMINI.SYS I cant remove it ,I ccannttt... I scaned my Pc with regrun but with out succses If you have just few minuts to tell me what will i do to remove that *censored* virus that will be good . GoodBay Need...more...info...gasp Operating system / antivirus & antispyware protection / service packs installed / when did it start happening / did it ever work right / installed any new software / tried booting into Safe Mode and running your antivirus/antispyware programs / tried booting into SM and doing a system restore to a date before this happened? Alan <>< First, watch your language, please! Print these instructions out. 1. Download SUPERAntiSpyware Free for Home Users: http://www.superantispyware.com/ * Double-click SUPERAntiSpyware.exe and use the default settings for installation. * An icon will be created on your desktop. Double-click that icon to launch the program. * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.) * Close SUPERAntiSpyware. Restart computer in Safe Mode. To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; SELECT Safe Mode; you'll see "Safe Mode" in all four corners of your screen * Open SUPERAntiSpyware. * Under "Configuration and Preferences", click the Preferences button. * Click the Scanning Control tab. * Under Scanner Options make sure the following are checked (leave all others unchecked): o Close browsers before scanning. o Scan for tracking cookies. o Terminate memory THREATS before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for Harmful Software" click Scan your computer. * On the left, make sure you check C:\Fixed Drive. * On the right, under "Complete Scan", choose Perform Complete Scan. * Click "Next" to start the scan. Please be patient while it scans your computer. * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK". * Make sure everything has a checkmark next to it and click "Next". * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu. * If asked if you want to reboot, click "Yes". * To retrieve the removal information after reboot, launch SUPERAntispyware again. o Click Preferences, then click the Statistics/LOGS tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o If there are several logs, click the current dated log and press View log. A text FILE will open in your default text editor. o Please copy and paste the Scan Log results in your next reply. * Click Close to exit the program. Post SUPERAntiSpyware log. RESTART COMPUTER! 2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select Perform full scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in Notepad. * Post the log back here. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt RESTART COMPUTER! 3. Download HijackThis: http://www.snapfiles.com/get/hijackthis.html Post HijackThis log. | |
| 3056. | Solve : help fixing computer problem? | 
| Answer» - About a month ago, my antivirus program(Avast) said it detected a virus in memory. - Suggested I shut computer down and reboot. - Did so. - Everything WENT fine with no resulting errors or messages. - When attempted to return MS-DOS prompt level, received message that it couldn't fine the .pif file. - Researched and found it still there. - Tryed to recreate an ms-dos prompt. - Then receive message that system couldn't find command.com. - Tryed c:\windows\system32\command.com. - System still couldn't find it, even though file is there. - Then ran virus check; spybot checkers(Adaware, Spybot, SpyDoctor, etc.), etc. - They did find instances of viruses, etc. and removed them. - Ran defrag, checkdisk, scandisk, etc. etc. - Check registery for .exe and exefile settings. All o.k. here - Rebooted computer. - Tryed other user logons. - Tryed creating new user logon. - Still same results. - Did extension research into problem. - Can't find anything that works. - Did EXTENSIVE research on this board concerning MS-DOS. - Have not found anything new that is helping. - NOTE: ---- - Can get cmd command to work and get me to DOS level. - However that are certain dos command I use frequently such as 'edit' 'fd(changes date of file(s))', etc. - These are not working. - I don't want to do a system restore at this point. I just want to fix the problem. - B-T-W. - Have Compaq Presario V5305. - WINDOWS XP MEDIA EDITION - VERSION 2002 - SERVICE PACK 2 - Only have restored disk - did not come with OEM disks. - Any suggestions...... -thanks -dan System Restore won't do any good, because it'd bring back all viruses. Let see, if your computer is clean... Print these instructions out. 1. Download SUPERAntiSpyware Free for Home Users: HTTP://www.superantispyware.com/ * Double-click SUPERAntiSpyware.exe and use the default settings for installation. * An icon will be created on your desktop. Double-click that icon to launch the program. * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.) * Close SUPERAntiSpyware. Restart computer in Safe Mode. To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen * Open SUPERAntiSpyware. * Under "Configuration and Preferences", click the Preferences button. * Click the Scanning Control tab. * Under Scanner Options MAKE sure the following are CHECKED (leave all others unchecked): o Close browsers before scanning. o Scan for tracking cookies. o Terminate memory threats before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for Harmful Software" click Scan your computer. * On the left, make sure you check C:\Fixed Drive. * On the right, under "Complete Scan", choose Perform Complete Scan. * Click "Next" to start the scan. Please be patient while it scans your computer. * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK". * Make sure everything has a checkmark next to it and click "Next". * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu. * If asked if you want to reboot, click "Yes". * To retrieve the removal information after reboot, launch SUPERAntispyware again. o Click Preferences, then click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor. o Please copy and paste the Scan Log results in your next reply. * Click Close to exit the program. Post SUPERAntiSpyware log. RESTART COMPUTER! 2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select Perform full scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in Notepad. * Post the log back here. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt RESTART COMPUTER! 3. Download HijackThis: http://www.snapfiles.com/get/hijackthis.html Post HijackThis log. | |
| 3057. | Solve : Virus Affecting Search Engines?? | 
| Answer» I am using IE 7 on xp with Windows Live OneCare. Every time I type something into Google, Yahoo, Ask...etc the page loads with results but when I click on one it takes me to an online store of some kind related to what I typed in. Any help would be great.  Welcome to CH. 
 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:47:01 PM, on 5/6/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\arservice.exe C:\WINDOWS\ATKKBService.exe C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe C:\Program Files\Microsoft Windows OneCare Live\winss.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\ARPWRMSG.EXE C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\QuickTime\qttask.exe C:\HP\KBD\KBD.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe C:\Program Files\HP DVD\Umbrella\DVDTray.exe C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\DOCUME~1\HP_ADM~1\APPLIC~1\YSTEM~1\lsass.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\UPDATES from HP\9972322\Program\Updates from HP.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe c:\windows\system\hpsysdrv.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PAVILION&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP DVD\Umbrella\DVDTray.exe" O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe" /NOUI O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Scbu] "C:\DOCUME~1\HP_ADM~1\APPLIC~1\YSTEM~1\lsass.exe" -vt yazb O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.0.0971.42/WinSSWebAgent.CAB O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.miniclip.com/games/ricochet-lost-worlds/en/ReflexiveWebGameLoader.cab O16 - DPF: {B3E0F81F-73F8-470B-A56B-D895EFF19260} (ATLF3D Class) - http://www.famous3d.com/viewer/latest/axf3d.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe -- End of file - 10741 bytes Couldn't tell much from that log. Don't worry, we'll find it. First: Your Java is out of date. Older versions of Java have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version(s) of Java components and update. Step 1 - Get the new version 
 
 
 Second: Please download COMBOFIX by sUBs from one of the below links. (Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop. 
 
 
 If needed, see this Combofix tutorial with screenshots that will detail the downloading and running of combofix more thoroughly. ---------- Next post please add: Combofix logthanks i removed the javas but none of the links for ComboFix work. I tried to find it online but none of those worked either. Are there any other links to it?Try this. http://download.bleepingcomputer.com/sUBs/ComboFix.exeIt said the page cannot be displayed...OK try this one. If you get it to run then try the Combofix again after posting the log from SDFix. Download SDFix.exe and save it to your Desktop. Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows Directory, typically C:\SDFix) Please then reboot your computer in Safe Mode by doing the following: 
 SDFix: Version 1.180 Run by HP_Administrator on Tue 05/06/2008 at 10:40 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting Checking Files : Trojan Files Found: C:\WINDOWS\SYSTEM32\LSPRST7.DLL - Deleted C:\Program Files\Common Files\Yazzle1552OinAdmin.exe - Deleted C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe - Deleted C:\WINDOWS\system32\000060.exe - Deleted C:\WINDOWS\system32\000090.exe - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-06 22:53:59 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\clb.dll] "0"=hex:00,00,28,0a,01,00,05,00 "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\clbcatex.dll] "0"=hex:2a,00,3e,11,0c,00,d1,07 "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\clbcatq.dll] "0"=hex:2a,00,3e,11,0c,00,d1,07 "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmdesched.sys] @="driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmdesched.sys] @="driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clbdriver] "start"=dword:00000001 "type"=dword:00000001 "imagepath"=str(2):"\??\globalroot\systemroot\system32\drivers\vmdesched.sys" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Nls\MUILanguages\RCV2\clb.dll] "0"=hex:00,00,28,0a,01,00,05,00 "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Nls\MUILanguages\RCV2\clbcatex.dll] "0"=hex:2a,00,3e,11,0c,00,d1,07 "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Nls\MUILanguages\RCV2\clbcatq.dll] "0"=hex:2a,00,3e,11,0c,00,d1,07 "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\vmdesched.sys] @="driver" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\vmdesched.sys] @="driver" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\clbdriver] "start"=dword:00000001 "type"=dword:00000001 "imagepath"=str(2):"\??\globalroot\systemroot\system32\drivers\vmdesched.sys" scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\clbImageData] "affid"="7" "subid"="run02" "control"=hex:1a,00,15,13,07,11,5b,1b,1e,1b,0b,15,08,13,1b,0a,0b,f2,e0,ec,f0,.. "prov"="10010" "googleadserver"="pagead2.googlesyndication.com" "FLAGGED"=dword:00000001 scanning hidden files ... C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll 110080 bytes executable C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll 498688 bytes executable C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll 110080 bytes executable C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll 501248 bytes executable C:\WINDOWS\system32\clb.dll 10752 bytes executable C:\WINDOWS\system32\clbcatex.dll 110080 bytes executable C:\WINDOWS\system32\clbcatq.dll 498688 bytes executable C:\WINDOWS\system32\cdosys.dll 35328 bytes executable C:\WINDOWS\system32\clbinit.dll 1695 bytes C:\WINDOWS\system32\drivers\vmdesched.sys 6656 bytes executable C:\WINDOWS\system32\dllcache\clb.dll 10752 bytes executable C:\WINDOWS\system32\dllcache\clbcatex.dll 110080 bytes executable C:\WINDOWS\system32\dllcache\clbcatq.dll 498688 bytes executable C:\Program Files\Common Files\Real\Plugins\clbascauth.dll 41023 bytes executable C:\Program Files\HP Rhapsody\plugins\clbascauth.dll 26112 bytes executable scan completed successfully hidden processes: 0 hidden services: 1 hidden files: 15 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe" "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe" "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe" "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe" "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP" "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "C:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe:*:Enabled:Render Manager" "C:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe:*:Enabled:Studio" "C:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile" "C:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe:*:Enabled:umi" "C:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"="C:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe:*:Enabled:Sentinel Protection Server" "C:\\Program Files\\WildTangent Games\\Polar Bowler\\Polar.exe"="C:\\Program Files\\WildTangent Games\\Polar Bowler\\Polar.exe:*:Enabled:Polar" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\3dsmax7\\3dsmax.exe"="C:\\3dsmax7\\3dsmax.exe:*:Enabled:3ds max 7" "C:\\Program Files\\backburner 2\\monitor.exe"="C:\\Program Files\\backburner 2\\monitor.exe:*:Enabled:backburner 2.3 monitor" "C:\\Program Files\\backburner 2\\manager.exe"="C:\\Program Files\\backburner 2\\manager.exe:*:Enabled:backburner 2.3 manager" "C:\\Program Files\\backburner 2\\server.exe"="C:\\Program Files\\backburner 2\\server.exe:*:Enabled:backburner 2.3 server" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : THU 27 Jul 2006 211 A.SHR --- "C:\BOOT.BAK" Tue 1 Aug 2006 22 A.SH. --- "C:\WINDOWS\SMINST\HPCD.sys" Sun 31 Dec 2006 350 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti1F9.tmp" Tue 15 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp" Sun 4 May 2008 89,088 ..SHR --- "C:\Documents and Settings\HP_Administrator\Application Data\?ystem\lsass.exe" Tue 6 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT400.tmp" Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\HP_Administrator\Application Data\U3\temp\Launchpad Removal.exe" Wed 14 Dec 2005 200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\ACST4.DLL" Tue 22 Nov 2005 81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLFIREWALLMGR.DLL" Tue 22 Nov 2005 73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLINSTALLERFW.DLL" Wed 14 Dec 2005 88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\INSTPH.DLL" Wed 14 Dec 2005 200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\ACST4.DLL" Tue 22 Nov 2005 81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLFIREWALLMGR.DLL" Tue 22 Nov 2005 73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLINSTALLERFW.DLL" Wed 14 Dec 2005 88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\INSTPH.DLL" Tue 8 Aug 2006 11,115 A.SH. --- "C:\Documents and Settings\HP_Administrator\My Documents\My DVDs\My Music\License Backup\drmv2key.bak" Wed 5 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch1\lock.tmp" Wed 5 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch2\lock.tmp" Wed 5 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch3\lock.tmp" Wed 5 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch4\lock.tmp" Thu 6 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch5\lock.tmp" Finished! Will the Combofix download now?No but i have a question. My firewall keeps asking me about "lsass". I looked it up and found that it is a secuirty program but can be a virus, spyware, or worm. I searched for lsass and found two programs that had last been modified in 2004 and one that had last been modified today. Is there any way to tell?lsass has been known to be exploitable by malware and 'can' be a big problem. I need more information in the form of logs to determine if it is legitimate or not. Use the Kaspersky Online Scanner 
 
 
 There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As... 
 Please copy and paste the Kaspersky Online Scanner Report in your next post.The kaspersky page wont load either. Try running the WinSockFix utility to repair your connection and also HostsXpert. Then try to download Combofix again. . Download HostsXpert 
 If you do not know what a HOSTS file is, you are most likely not using a custom one. | |
| 3058. | Solve : AVG 8.0.1 Preventing attachment and torrent file downloads? | 
| Answer» Hi FOLKS, I can't download my email attachments or torrent files.What exactly happens?What happens... Okay...I click on the link where it will say download attachment or download torrent etc. It brings up the box where I get to choose the location where the file needs to be saved to. I point to a folder, desktop etc...and then click OK/Save From there it looks as though its going to dlownload, there are few kbs of data downloaded and then it shuts down. Nothing is saved and no messages pop up stating that the dnload was blocked. I also noticed that the new chat function on FACEBOOK has stopped working for aswell. I just uninstalled AVG and restared nd everything is working again...except that I am now unprotected. I hope this helps explain my situation. Cheers There has been a lot of problems reported around the net about new AVG. I had serious installation problems myself. Try free Avast: http://www.avast.com/http://www.avast.com/ I had trouble with AVG also and downloaded avast and think I like it better than avg. | |
| 3059. | Solve : AVG and WIN98?? | 
| Answer» I have been using AVG 7.5 on both my main and back up COMPUTERS. But have received the notice that AVG will soon STOP updates for 7.5 and I have to change to 8.0. No problem with the main COMPUTER running Win XP Pro, but the back up is Win 98 and AVG 8.0 does not run on that apparently.  | |
| 3060. | Solve : Rundll system error system32/bxlghumi.dll? | 
| Answer» Hi,  | |
| 3061. | Solve : Looking for help with a virus from you smart people? | 
| Answer» You'll have to make a Bootable WINDOWS 2000 CD with Service PACK INTEGRATED: http://old.bink.nu/bootcd/ | |
| 3062. | Solve : problems uninstalling AVG 7.5 + problems with tabbed browsing in Firefox? | 
| Answer» I'm glad, things are BACK to normal  | |
| 3063. | Solve : Internet connection is driving me nuts!? | 
| Answer» I'm GLAD, your internet is back, but still, I'd like to SEE those three logs to see, if your COMPUTER is CLEAN, and it won't happen again. | |
| 3064. | Solve : Roomie's computer infected now...HJT log included.? | 
| Answer» I was helping my coworker with her infection when evilfantasy determined that her situation was devastating. 
 
 
 What DSS will do: 
 Next post please add DSS Main & Extra text logs. Almost missed this... Your Java is out of date. Older versions of Java have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version(s) of Java components and update. Step 1 - Get the new version 
 
 
 Deckard's System Scanner v20071014.68 Run by CATANYAG on 2008-05-10 00:46:03 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 68: 2008-05-10 07:46:08 UTC - RP1250 - Deckard's System Scanner Restore Point 67: 2008-05-10 07:38:18 UTC - RP1249 - Installed Java(TM) 6 Update 5 66: 2008-05-10 07:11:20 UTC - RP1248 - System Checkpoint 65: 2008-05-08 22:01:29 UTC - RP1247 - Software Distribution Service 3.0 64: 2008-05-08 06:35:07 UTC - RP1246 - System Checkpoint -- First Restore Point -- 1: 2008-03-06 12:03:06 UTC - RP1183 - System Checkpoint Backed up registry hives. Performed disk cleanup. -- HijackThis (run as CATANYAG.exe) -------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:48:08 AM, on 5/10/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\TpShocks.exe C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\IBMTOOLS\UTILS\ibmprc.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe C:\Program Files\Winamp\winampa.exe C:\WINDOWS\TPPALDR.EXE C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Documents and Settings\Hotsync.exe C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54Cfg.exe C:\WINDOWS\system32\msiexec.exe C:\Documents and Settings\CATANYAG\Desktop\dss.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\CATANYAG.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper O4 - HKLM\..\Run: [TpShocks] TpShocks.exe O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor O4 - HKLM\..\Run: [TP4EX] tp4ex.exe O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: HotSync Manager.lnk = C:\Documents and Settings\Hotsync.exe O4 - Global Startup: Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [JAVA_IBM] Java (IBM) O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://www.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by133fd.bay133.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/DeltaCVX.cab O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe -- End of file - 13451 bytes -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) ----------- backup-20080510-004336-415 O9 - Extra 'Tools' menuitem: GigaSize Toolbar - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file) backup-20080510-004336-509 O9 - Extra button: (no name) - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file) backup-20080510-004336-592 O2 - BHO: (no name) - {B8A7839C-51E8-4067-ADA3-CA74BABC1976} - (no file)-- File Associations ----------------------------------------------------------- .reg - regfile - shell\open\command - regedit.exe "%1" %* .scr - scrfile - shell\open\command - "%1" %* -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R0 Shockprf - c:\windows\system32\drivers\shockprf.sys R1 SbcpHid - c:\windows\system32\drivers\sbcphid.sys R1 Smapint - c:\windows\system32\drivers\smapint.sys R1 TDSMAPI - c:\windows\system32\drivers\tdsmapi.sys R1 TPHKDRV - c:\windows\system32\drivers\tphkdrv.sys R1 TPPWR - c:\windows\system32\drivers\tppwr.sys R1 TSMAPIP - c:\windows\system32\drivers\tsmapip.sys R2 EGATHDRV (IBM Access Support) - c:\windows\system32\egathdrv.sys R2 ibmfilter - c:\windows\system32\drivers\ibmfilter.sys R2 PMEM - c:\windows\system32\drivers\pmemnt.sys R2 ShockMgr - c:\windows\system32\drivers\shockmgr.sys R3 ASAPIW2k - c:\windows\system32\drivers\asapiw2k.sys S3 CBTNDIS5 (CBTNDIS5 NDIS Protocol Driver) - c:\windows\system32\cbtndis5.sys S3 IPN2220 (Wireless-G Notebook Adapter ver.4.0 Driver) - c:\windows\system32\drivers\i2220ntx.sys (file missing) S3 PCAMPR5 (PCAMPR5 NDIS Protocol Driver) - c:\windows\system32\pcampr5.sys (file missing) S3 psadd (IBM PSA Access Driver) - c:\windows\system32\drivers\psadd.sys S3 stusb2ir (USB 2.0 IrDA Bridge) - c:\windows\system32\drivers\stusb2ir.sys S3 ZD1211U(WLAN) (IEEE 802.11g USB Wireless LAN Driver(WLAN)) - c:\windows\system32\drivers\zd1211u.sys S3 ZDBRGSYS (ZDBRGSYS NDIS Protocol Driver) - c:\windows\system32\zdbrgsys.sys S3 ZDPNDIS5 (ZDPNDIS5 NDIS Protocol Driver) - c:\windows\system32\zdpndis5.sys -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" R2 IBM Rapid Restore Ultra Service - c:\program files\ibm\ibm rapid restore ultra\rrpcsb.exe R2 RegSrvc (Intel(R) PROSet/Wireless Registry Service) - c:\program files\intel\wireless\bin\regsrvc.exe R2 TpKmpSVC (IBM KCU Service) - c:\windows\system32\tpkmpsvc.exe S2 NICSer_WPC54G - c:\program files\linksys\wireless-g notebook adapter\nicserv.exe S3 PsaSrv (IBM PSA Access Driver Control) - c:\windows\system32\psasrv.exe (file missing) -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2008-05-09 23:58:28 380 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job 2008-05-09 23:10:45 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job 2008-05-07 10:14:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job 2008-05-02 22:39:54 536 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - CATANYAG.job 2007-11-24 09:37:55 506 --a------ C:\WINDOWS\Tasks\BMMTask.job -- Files created between 2008-04-10 and 2008-05-10 ----------------------------- 2008-05-09 00:09:04 0 d-------- C:\Program Files\Trend Micro 2008-05-08 23:59:54 0 d-------- C:\Documents and Settings\CATANYAG\Application Data\Malwarebytes 2008-05-08 23:59:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-05-08 23:59:49 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-05-08 23:16:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-05-08 22:43:14 5276 --a------ C:\WINDOWS\system32\tmp.reg 2008-05-08 22:38:29 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe 2008-05-08 22:38:29 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe 2008-05-08 22:38:29 86528 --a------ C:\WINDOWS\system32\VACFix.exe 2008-05-08 22:38:29 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2008-05-08 22:38:29 53248 --a------ C:\WINDOWS\system32\Process.exe http://www.beyondlogic.org; Command Line Process Utility> 2008-05-08 22:38:29 82944 --a------ C:\WINDOWS\system32\IEDFix.exe 2008-05-08 22:38:29 51200 --a------ C:\WINDOWS\system32\dumphive.exe 2008-05-08 22:38:29 82944 --a------ C:\WINDOWS\system32\404Fix.exe 2008-05-08 06:22:58 0 d-------- C:\Documents and Settings\CATANYAG\Application Data\Google 2008-05-08 06:18:13 0 d-------- C:\Documents and Settings\UST TRAINING\Application Data\Google 2008-05-08 06:16:08 0 d-------- C:\Documents and Settings\All Users\Application Data\Google 2008-05-07 23:53:20 0 d-------- C:\Documents and Settings\UST TRAINING\Application Data\Adobe 2008-05-07 00:25:42 0 d-------- C:\Program Files\Enigma Software Group 2008-05-07 00:02:07 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2008-05-06 23:58:36 0 d-------- C:\Documents and Settings\LocalService\Desktop 2008-05-06 17:41:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-05-06 17:30:38 0 d-------- C:\Program Files\Windows Defender 2008-05-01 21:58:03 0 d-------- C:\Documents and Settings\LocalService\Application Data\Intel 2008-05-01 12:01:31 0 d-------- C:\WINDOWS\system32\FxsTmp 2008-04-22 17:30:55 0 d-------- C:\Program Files\iTunes 2008-04-22 17:28:40 0 d-------- C:\Program Files\QuickTime -- Find3M Report --------------------------------------------------------------- 2008-05-10 00:39:30 0 d-------- C:\Program Files\Java 2008-05-10 00:13:49 0 d-------- C:\Program Files\Common Files 2008-05-08 19:58:25 0 d-------- C:\Program Files\Common Files\Symantec Shared 2008-05-08 17:37:43 0 d-------- C:\Program Files\Absolute Poker 2008-05-08 09:07:02 0 d-------- C:\Documents and Settings\CATANYAG\Application Data\Yahoo! 2008-05-08 06:20:04 0 d-------- C:\Program Files\Google 2008-05-06 17:23:38 0 d-------- C:\Program Files\Symantec 2008-04-22 17:31:08 0 d-------- C:\Program Files\iPod 2008-04-22 17:23:25 0 d-------- C:\Program Files\Apple Software Update 2008-04-17 00:06:14 0 d-------- C:\Documents and Settings\CATANYAG\Application Data\Adobe -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "S3TRAY2"="S3Tray2.exe" [10/11/2001 11:32 PM C:\WINDOWS\system32\S3Tray2.exe] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [11/19/2003 09:56 AM] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [11/19/2003 09:56 AM] "ATIModeChange"="Ati2mdxx.exe" [09/04/2001 01:24 PM C:\WINDOWS\system32\Ati2mdxx.exe] "BluetoothAuthenticationAgent"="irprops.cpl" [08/04/2004 12:56 AM C:\WINDOWS\system32\irprops.cpl] "TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [10/23/2003 11:39 PM] "TpShocks"="TpShocks.exe" [12/17/2003 11:12 AM C:\WINDOWS\system32\TpShocks.exe] "TPHOTKEY"="C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [03/10/2004 10:10 AM] "BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [12/25/2003 01:36 AM] "BMMMONWND"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll" [12/25/2003 01:36 AM] "TP4EX"="tp4ex.exe" [09/04/2002 01:05 AM C:\WINDOWS\system32\TP4EX.exe] "EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [12/25/2003 02:04 AM] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [02/10/2004 09:10 PM] "UC_Start"="C:\Program Files\IBM\Updater\\ucstartup.exe" [09/30/2003 03:39 PM] "UC_SMB"="" [] "UpdateManager"="c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [08/19/2003 01:01 AM] "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [10/22/2003 01:04 AM] "IBMPRC"="C:\IBMTOOLS\UTILS\ibmprc.exe" [03/19/2004 12:12 PM] "BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [12/25/2003 01:36 AM] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/09/2007 05:32 PM] "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [05/06/2008 05:23 PM] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [04/13/2005 04:48 AM] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 12:50 PM] "PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [] "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [02/13/2007 11:29 AM] "TPP Auto Loader"="C:\WINDOWS\TPPALDR.EXE" [10/05/2001 12:54 PM] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 11:37 PM] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 07:20 PM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IBM RecordNow!"="" [] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM] "NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [07/14/2005 10:35 PM] "Aim6"="" [] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [12/14/2004 5:44:06 AM] Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [9/2/2004 6:51:35 PM] HotSync Manager.lnk - C:\Documents and Settings\Hotsync.exe [6/9/2004 2:16:08 PM] Wireless-G Notebook Adapter Utility.lnk - C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe [10/13/2004 10:17:35 PM] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] "Notification Packages"= scecli pwdmon [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProvidersmsapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume SHADOW copy" -- End of Deckard's System Scanner: finished at 2008-05-10 00:49:27 ------------ Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: Intel(R) Pentium(R) M processor 1500MHz Percentage of Memory in Use: 38% Physical Memory (total/avail): 1278.92 MiB / 792.63 MiB Pagefile Memory (total/avail): 1517.93 MiB / 1155.96 MiB Virtual Memory (total/avail): 2047.88 MiB / 1926.57 MiB C: is Fixed (NTFS) - 32.97 GiB total, 6.54 GiB free. D: is CDROM (No Media) \\.\PHYSICALDRIVE0 - HTS548040M9AT00 - 37.26 GiB - 2 partitions \PARTITION0 (bootable) - Installable File System - 32.97 GiB - C: \PARTITION1 - Unknown - 4.29 GiB -- Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. Windows Internal Firewall is enabled. AntiVirusDisableNotify is set. FW: Norton Internet Worm Protection v2005 (Symantec) AV: Norton AntiVirus 2005 v2005 (Symantec Corporation) Outdated [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger" "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader" "C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\CATANYAG\Application Data CLASSPATH=.;C:\Program Files\Java\jre1.5.0_03\lib\ext\QTJava.zip CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=DENNIS ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\CATANYAG IBMSHARE=C:\IBMSHARE LOGONSERVER=\\DENNIS NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\PROGRAM FILES\THINKPAD\UTILITIES;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\WINDOWS\Downloaded Program Files;C:\IBMTOOLS\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\Pinnacle\Shared Files\Filter;C:\Program Files\Intel\Wireless\Bin\;C:\Program Files\QuickTime\QTSystem\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.pyo;.pyc;.py;.pyw PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 9 Stepping 5, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0905 ProgramFiles=C:\Program Files PROMPT=$P$G PYTHONCASEOK=1 PYTHONPATH=C:\IBMTOOLS\utils\support;C:\IBMTOOLS\utils\logger QTJAVA=C:\Program Files\Java\jre1.5.0_03\lib\ext\QTJava.zip RRU=C:\Program Files\IBM\IBM Rapid Restore Ultra\ SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TCL_LIBRARY=C:\IBMTOOLS\Python22\tcl\tcl8.4 TEMP=C:\DOCUME~1\CATANYAG\LOCALS~1\Temp TK_LIBRARY=C:\IBMTOOLS\Python22\tcl\tk8.4 TMP=C:\DOCUME~1\CATANYAG\LOCALS~1\Temp USERDOMAIN=DENNIS USERNAME=CATANYAG USERPROFILE=C:\Documents and Settings\CATANYAG windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- CATANYAG (admin) UST TRAINING (admin) Office.DENNIS (admin) Administrator (admin) -- Add/Remove Programs --------------------------------------------------------- --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu --> c:\WINDOWS\System32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6} --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19} --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\SETUP.EXE" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\SETUP.EXE" -l0x9 ControlPanelAnyText --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\SETUP.EXE" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\SETUP.EXE" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll -l0x9 ControlPanelAnyText --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Absolute Poker --> C:\Program Files\_uninstallation_info\Absolute Poker\CasinoUninstall.exe AC3Filter (remove only) --> C:\Documents and Settings\CATANYAG\Desktop\AC3Filter\uninstall.exe Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 7.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000} Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log AIM 6 --> C:\Program Files\AIM6\uninst.exe Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543} Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F} ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe" ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,[emailprotected] -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean ATI HYDRAVISION --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}\setup.exe" ccCommon --> MsiExec.exe /I{DC367608-64A7-4BF7-92F4-8BAA25BA02DB} Coupon Printer for Windows --> "C:\Program Files\Coupons\uninstall.exe" "/U:C:\Program Files\Coupons\Uninstall\uninstall.xml" Cucusoft DVD to iPod + iPod Video Converter Suite 5.28.5.12 --> "C:\Program Files\Cucusoft\ipod-converter\unins000.exe" DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC DVD Decrypter (Remove Only) --> "C:\Documents and Settings\CATANYAG\Desktop\DVD Decrypter\uninstall.exe" DVD Shrink 3.2 --> "C:\Program Files\DVD Shrink\unins000.exe" Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll" HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F} HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" IBM 32-bit Runtime Environment for Java 2, v1.4.1 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6C72E14A-C1F3-45E5-8810-83CE3C19ED63} /l1033 IBM Active Protection System --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{72806716-7088-41B2-8FA6-717A2A164DAB}\SETUP.EXE" -l0x9 anything IBM DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6} IBM Integrated 56K Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014\HXFSETUP.EXE -U -IVEN_8086&DEV_24C6&SUBSYS_05591014 IBM RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19} IBM Rescue and Recovery with Rapid Restore --> MsiExec.exe /X{11783F13-C3A9-44A8-929B-21A476F65272} IBM Themes --> MsiExec.exe /I{6CE96A14-61E2-48CC-837E-22710A953ADE} IBM ThinkPad Battery MaxiMiser and Power Management Features --> C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unbmm.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsbmm.dll" IBM ThinkPad Configuration --> C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\UNTPUW.ISU -c"C:\Program Files\ThinkPad\Utilities\Tpinswin.dll" IBM ThinkPad EasyEject Utility --> C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unezej.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsej.dll" IBM ThinkPad Keyboard Customizer Utility --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2111B23F-7FDA-4A41-8309-E5A1663CA296}\SETUP.EXE" -l0x9 anything IBM ThinkPad Power Management Driver --> RunDll32.exe tpinspm.dll,Uninstall IBM ThinkPad Presentation Director --> C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\UNNPDR.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsnpd.dll" IBM ThinkPad UltraNav Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall IBM ThinkPad UltraNav Wizard --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{82512BC9-BD5D-4C50-BE4D-B98E7DF78687}\SETUP.EXE" UNINSTALL IBM TrackPoint Accessibility Features --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA664480-3844-11D5-8C25-444553540000}\SETUP.EXE" IBM Update Connector --> MsiExec.exe /X{8D815BF3-2399-459C-B121-49373FEFB9E8} Intel(R) PRO Network Adapters and Drivers --> Prounstl.exe Intel(R) PROSet/Wireless Software --> C:\WINDOWS\Installer\iProInst.exe Internet Worm Protection --> MsiExec.exe /I{2908F0CB-C1D4-447F-97A2-CFC135C9F8D4} InterVideo WinDVD --> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL iPod Access for Windows v2.9.4 --> "C:\Program Files\iPod Access for Windows\unins000.exe" iPod for Windows 2005-10-12 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A} /l1033 iPod Reset Utility --> MsiExec.exe /X{91A2689C-D4B1-43BB-A521-0E29B963FC56} iTunes --> MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B} J2SE Runtime Environment 5.0 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030} Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050} LimeWire 4.14.8 --> "C:\Program Files\LimeWire\uninstall.exe" LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe /REMOVE LiveUpdate 2.6 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" mCore --> MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779} mDriver --> MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29} Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe" Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9} Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe" mMHouse --> MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5} mPfMgr --> MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5} mProSafe --> MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83} MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E} mWlsSafe --> MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4} Nero 6 Ultra Edition --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL Norton AntiVirus 2005 --> MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B} Norton AntiVirus 2005 (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\SymSetup\{C6F5B6CF-609C-428E-876F-CA83176C021B}.exe /X Norton AntiVirus Help --> MsiExec.exe /I{34EEB1F5-E939-40A1-A6BA-957282A4B2C8} Norton AntiVirus Parent MSI --> MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43} Norton AntiVirus SCSSDist MSI --> MsiExec.exe /I{541230A3-1D3A-4879-B7E0-E71F90E35548} Norton AntiVirus SYMLT MSI --> MsiExec.exe /I{D1FF75E7-DD42-4CFD-B052-20B3FFF4EDB8} Norton WMI Update --> MsiExec.exe /X{1526D87C-A955-4FAB-BF18-697BA457E352} Norton WMI Update --> MsiExec.exe /X{F64306A5-4C32-41bb-B153-53986527FAB4} Odyssey Client --> MsiExec.exe /X{99D42EC7-652B-4819-B3E6-6450C815E03F} palmOne --> MsiExec.exe /X{E434580A-2D4A-4433-A81E-4BCAE86AD148} PC-Doctor for Windows --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\SETUP.EXE" PCFriendly --> C:\Program Files\PCFriendly\inuninst.exe Pinnacle Mobile Media Organizer --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BCC64390-4796-4BEC-87AB-87282CBAFF8C}\Setup.exe" -l0x9 UNINSTALL QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD} Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe" Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe" Sonic Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3} SPBBC --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56} Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe" Symantec --> MsiExec.exe /I{228F6876-A313-40A3-91C0-C3CBE6997D09} Symantec Script Blocking Installer --> MsiExec.exe /I{D327AFC9-7BAA-473A-8319-6EB7A0D40138} SymNet --> MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2} ThinkPad FullScreen Magnifier --> RunDll32 setupapi.dll,InstallHinfSection DefaultUninstall.NT 132 C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.inf ThinkPad Software Installer --> _tpiu000.exe /U TPP Storage Driver Installation --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E258A840-7E9A-443A-B156-67102C48BF17}\Setup.exe" NotFirstInstall USB 2.0 IrDA Bridge --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{10F5D9BB-E2F2-4B18-A65D-928B73D22E6F}\setup.exe" -l0x9 USB Storage Adapter (TPP) --> tppun.exe TPP725 USB Storage Adapter V2 (TPP) --> tppun.exe TPP200 USB Storage Adapter V3 (TPP) --> tppun.exe TPP300 Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u Wallpapers --> MsiExec.exe /I{F386C340-DF4B-4BBA-9503-420FB7EDB395} Winamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe" Windows Defender --> MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401} Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" Wireless-G Notebook Adapter --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A2EDF5F-F3C6-4919-AE34-C08A71AD034A}\Setup.exe" -l0x9 -- Application Event Log ------------------------------------------------------- Event Record #/Type9341 / Warning Event Submitted/Written: 05/09/2008 00:16:05 AM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type9326 / Warning Event Submitted/Written: 05/08/2008 10:45:38 PM Event ID/Source: 1015 / MsiInstaller Event Description: Failed to connect to server. Error: 0x8007043C Event Record #/Type9325 / Warning Event Submitted/Written: 05/08/2008 10:45:38 PM Event ID/Source: 1004 / MsiInstaller Event Description: Detection of product '{90110409-6000-11D3-8CFE-0150048383C9}', feature 'OfficeUserData', component '{4A31E933-6F67-11D2-AAA2-00A0C90F57B0}' failed. The resource 'HKEY_CURRENT_USER\Software\ODBC\ODBC.INI\MS Access Database\' does not exist. Event Record #/Type9323 / Warning Event Submitted/Written: 05/08/2008 10:39:30 PM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type9307 / Warning Event Submitted/Written: 05/08/2008 10:30:48 PM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type112440 / Warning Event Submitted/Written: 05/10/2008 00:48:34 AM Event ID/Source: 3004 / WinDefend Event Description: %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow. For more information please see the following: %DENNIS275 Scan ID: {3533E261-EA50-4BEA-AC48-037552BE9E79} User: DENNIS\CATANYAG Name: %DENNIS271 ID: %DENNIS272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %DENNIS276 Alert Type: %DENNIS278 Detection Type: 1.1.1593.02 Event Record #/Type112439 / Warning Event Submitted/Written: 05/10/2008 00:48:34 AM Event ID/Source: 3004 / WinDefend Event Description: %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow. For more information please see the following: %DENNIS275 Scan ID: {57941E0F-A630-4E96-A90B-88353EDE282D} User: DENNIS\CATANYAG Name: %DENNIS271 ID: %DENNIS272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %DENNIS276 Alert Type: %DENNIS278 Detection Type: 1.1.1593.02 Event Record #/Type112438 / Warning Event Submitted/Written: 05/10/2008 00:48:34 AM Event ID/Source: 3004 / WinDefend Event Description: %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow. For more information please see the following: %DENNIS275 Scan ID: {159A93A4-5612-4A73-9E97-BAABD4EA9841} User: DENNIS\CATANYAG Name: %DENNIS271 ID: %DENNIS272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %DENNIS276 Alert Type: %DENNIS278 Detection Type: 1.1.1593.02 Event Record #/Type112437 / Warning Event Submitted/Written: 05/10/2008 00:48:31 AM Event ID/Source: 3004 / WinDefend Event Description: %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow. For more information please see the following: %DENNIS275 Scan ID: {348AC47F-9B1B-4648-B5AB-15C5D248421E} User: DENNIS\CATANYAG Name: %DENNIS271 ID: %DENNIS272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %DENNIS276 Alert Type: %DENNIS278 Detection Type: 1.1.1593.02 Event Record #/Type112436 / Warning Event Submitted/Written: 05/10/2008 00:48:31 AM Event ID/Source: 3004 / WinDefend Event Description: %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow. For more information please see the following: %DENNIS275 Scan ID: {DDC1C48A-EA8C-4D35-BFDE-28EB2024A503} User: DENNIS\CATANYAG Name: %DENNIS271 ID: %DENNIS272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %DENNIS276 Alert Type: %DENNIS278 Detection Type: 1.1.1593.02 -- End of Deckard's System Scanner: finished at 2008-05-10 00:49:27 ------------ The current version of Java is Java(TM) 6 Update 6 and you can get it HERE Go to add/remove programs and uninstall J2SE Runtime Environment 5.0 Update 3 Java(TM) 6 Update 5 Viewpoint Media Player ---------- Try running StartUpLite to get rid of the un-necessary startups. ---------- Is Norton up to date? Is is a paid version or has the subscription run out? Quote AV: Norton AntiVirus 2005 v2005 (Symantec Corporation) OutdatedOkay, got rid of the 3 things from Add/Remove (strangely enough, the download of Java I got was from Java's website...and it was 6.5). Downloaded the new Java. Ran the startup cleaner. The Norton is EXTREMELY outdated and not paid for.OK we need to get you some current protection. First download these programs, don't install them yet. Antivurus: Pick only one. I will list multiple but if you want my personal preference it is Avast. Avast - http://www.filehippo.com/download_avast_antivirus/ AVG - http://www.filehippo.com/download_avg_antivirus/ AntiVir - http://www.filehippo.com/download_antivir/ Firewall: Be sure to choose Advanced Mode when installing. http://www.filehippo.com/download_comodo/ After they are downloaded don't connect to the internet until you have Norton uninstalled and the new protection installed. Download the Norton Removal Tool Go to add remove programs and uninstall anything with Norton, Live Update or Symantec in the name. Now run the Norton Removal Tool Install the new AV and Firewall then run a full scan with the new AV. Let me know how everything is now. | |
| 3065. | Solve : HijackThis log for a win32/vundo!generic problum? | 
| Answer» if someone could please help 
 
 
 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.166 [GMT -4:00] Running from: C:\Documents and Settings\Jeff Hansen\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Guest\err.log C:\Documents and Settings\Jeff Hansen\Application Data\macromedia\Flash Player\#SharedObjects\JLWWAZY2\www.broadcaster.com C:\Documents and Settings\Jeff Hansen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com C:\Documents and Settings\Jeff Hansen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol C:\Documents and Settings\Jeff Hansen\err.log C:\Documents and Settings\Jeff Hansen\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML C:\Documents and Settings\Jeff Hansen\Local Settings\Temporary Internet Files\bestwiner.stt C:\Documents and Settings\Jeff Hansen\Local Settings\Temporary Internet Files\CPV.stt C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Internet Speed Monitor C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk C:\Program Files\Common Files\{34F43~1 C:\Program Files\Common Files\{34F43~1\Uninstall.exe C:\Program Files\Common Files\{34F43~2 C:\Program Files\Common Files\{C4F43~1 C:\Program Files\CPV C:\Program Files\inetget2 C:\Program Files\inetget2\sacatapo821058.exe C:\Program Files\ISM C:\Program Files\ISM\ism.exe C:\Program Files\ISM\Uninstall.exe C:\Program Files\JavaCore C:\Program Files\JavaCore\JavaCore.exe C:\Program Files\JavaCore\UnInstall.exe C:\Program Files\QdrDrive C:\Program Files\QdrDrive\qdrloader.exe C:\Program Files\QdrPack C:\Program Files\QdrPack\QdrPack15.exe C:\Program Files\Temporary C:\WA6P C:\WINDOWS\b104.exe C:\WINDOWS\b148.exe C:\WINDOWS\b149.exe C:\WINDOWS\b152.exe C:\WINDOWS\b155.exe C:\WINDOWS\b156.exe C:\WINDOWS\b999.exe C:\WINDOWS\mrofinu1535.exe C:\WINDOWS\system32\components C:\WINDOWS\system32\dgjlm.ini2 C:\WINDOWS\system32\dgjlm.tmp C:\WINDOWS\system32\iyspawlq.ini C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\mevrkpsw.ini C:\WINDOWS\system32\mlnmp.bak1 C:\WINDOWS\system32\mlnmp.bak2 C:\WINDOWS\system32\mlnmp.ini C:\WINDOWS\system32\mlnmp.ini2 C:\WINDOWS\system32\mlnmp.tmp C:\WINDOWS\system32\nnnmjgHy.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_COM+_MESSAGES ((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 ))))))))))))))))))))))))))))))) . 2008-05-10 12:55 . 2008-05-10 12:55d--------C:\Program Files\Spcron 2008-05-10 12:50 . 2008-05-10 12:50d--------C:\Program Files\Svconr 2008-05-09 22:31 . 2008-05-09 22:32d--------C:\Documents and Settings\Jeff Hansen\.limewire 2008-05-09 19:22 . 2008-05-09 19:22d--------C:\Documents and Settings\Jeff Hansen\Application Data\Lavasoft 2008-05-09 12:40 . 2008-02-12 14:4548--a------C:\Documents and Settings\Jeff Hansen\readme.bat 2008-05-09 10:45 . 2008-05-09 10:45d--------C:\Program Files\Common Files\Macromedia Shared . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-11 01:39---------d-----wC:\Program Files\Steam 2008-05-11 01:38---------d-----wC:\Documents and Settings\Jeff Hansen\Application Data\WTablet 2008-05-11 01:37---------d-----wC:\Documents and Settings\LocalService\Application Data\WTablet 2008-05-08 21:33---------d-----wC:\Program Files\Common Files\Adobe 2008-05-08 21:27---------d-----wC:\Documents and Settings\Jeff Hansen\Application Data\AdobeUM 2008-03-26 21:40---------d-----wC:\Program Files\LimeWire 2008-03-26 17:45---------d-----wC:\Program Files\Kate's Video Converter 2008-02-10 03:2115----a-wC:\Documents and Settings\Jeff Hansen\StopWZC.bat 2008-02-10 03:2016----a-wC:\Documents and Settings\Jeff Hansen\StartWZC.bat 2008-01-09 21:20251----a-wC:\Program Files\wt3d.ini 2007-03-23 14:39382----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb1942.dat 2007-03-23 14:3869,632----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb4827.dat 2007-03-23 14:38151----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb292.dat 2007-03-23 14:380----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb2391.dat 2006-11-30 03:4249----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb41.dat 2006-11-29 15:466,144----a-wC:\Documents and Settings\Guest\Application Data\internaldb1362.dat 2006-11-22 06:520----a-wC:\Program Files\Common Files\err.log 2006-11-18 17:080----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb5436.dat 2006-11-16 20:079,216----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb9040.dat 2006-11-16 20:070----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb1912.dat 2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb4604.dat 2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb3902.dat 2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb153.dat 2006-11-04 21:037,048----a-wC:\Documents and Settings\All Users\Application Data\ypinfo.bin 2007-12-06 23:1088--sh--rC:\WINDOWS\system32\41457874FA.sys 2007-09-10 18:0756--sh--rC:\WINDOWS\system32\FA74784541.sys 2007-12-06 23:106,580--sha-wC:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E1550C1-DB0B-4B2D-B338-CA5DCF368E13}] C:\WINDOWS\system32\pwlosnmw.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7C0AA32-5656-42F4-BF96-09ED9F459BD9}] 2008-02-07 21:07217088--a------C:\Program Files\Messenger\kywokelyt821058.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E93121AD-7C67-417A-A6A5-87C60214AC80}] C:\WINDOWS\system32\pmnlm.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ] "Steam"="c:\program files\steam\steam.exe" [2008-04-01 19:03 1271032] "Svconr"="C:\Program Files\Svconr\Svconr.exe" [2008-05-10 12:50 57344] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 17:44 98304] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 17:41 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 17:45 118784] "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-12-19 09:08 1347584] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 12:56 761947] "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035] "CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2007-03-23 14:31 230512] "CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2007-03-23 14:31 185456] "YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43 407032] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-07 19:15 180269] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608] "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe] "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-16 02:37 57344] C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2005-03-09 15:57:14 81920] Microsoft Office Shortcut Bar.Lnk [2007-04-02 15:06:31 761] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696] Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-12-25 09:30:07 784912] WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-09-26 23:45:57 106560] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] c:\program files\common files\logitech\bluetooth\LBTWlgn.dll 2007-11-15 11:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm] C:\WINDOWS\system32\pmnlm.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\Program Files\\America Online 9.0\\waol.exe"= "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\WINDOWS\\system32\\sessmgr.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\StubInstaller.exe"= "C:\\Program Files\\Opera\\Opera.exe"= "C:\\Program Files\\AIM\\aim.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"= "C:\\Program Files\\Steam\\SteamApps\\hippiegothie\\team fortress 2\\hl2.exe"= R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38] R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2006-02-14 17:18] R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2006-11-15 15:55] S3 SaiH0461;SaiH0461;C:\WINDOWS\system32\DRIVERS\SaiH0461.sys [2006-08-08 13:25] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}] \Shell\AutoRun\command - E:\setup.exe . Contents of the 'Scheduled Tasks' folder "2008-05-05 15:24:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-05-11 01:37:22 C:\WINDOWS\Tasks\Winter Fun Wallpaper Changer.job" - C:\Documents and Settings\All Users\Start Menu\Programs\Winter Fun Pack 2004 for Windows XP\Winter Fun Wallpaper Changer.lnk . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-10 21:39:09 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\WLTRYSVC.EXE C:\WINDOWS\system32\BCMWLTRY.EXE C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Yahoo!\Antivirus\iSafe.exe C:\WINDOWS\ehome\ehrecvr.exe C:\WINDOWS\ehome\ehSched.exe C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\Tablet.exe C:\Program Files\Yahoo!\Antivirus\VetMsg.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe . ************************************************************************** . Completion time: 2008-05-10 21:45:36 - machine was rebooted ComboFix-quarantined-files.txt 2008-05-11 01:45:30 Pre-Run: 10,848,620,544 bytes free Post-Run: 10,703,892,480 bytes free 220--- E O F ---2008-04-11 07:09:05Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 
 Code: [Select]KillAll:: Folder:: C:\Program Files\Spcron C:\Program Files\Svconr REGISTRY:: [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E1550C1-DB0B-4B2D-B338-CA5DCF368E13}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7C0AA32-5656-42F4-BF96-09ED9F459BD9}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E93121AD-7C67-417A-A6A5-87C60214AC80}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Svconr"=- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick combofix's window while it is running. That may cause your system to freeze ---------- Create An Uninstall List 
 ---------- Next post add (you may need to use two posts to get everything in) New Combofix log Uninstall list Let me know how everything is now .ComboFix 08-05-09.1 - Jeff Hansen 2008-05-10 22:18:40.2 - NTFSx86 Running from: C:\Documents and Settings\Jeff Hansen\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Jeff Hansen\Desktop\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Jeff Hansen\Local Settings\Temporary Internet Files\bestwiner.stt C:\Program Files\Spcron C:\Program Files\Spcron\Spcron.dll C:\Program Files\Svconr C:\Program Files\Svconr\Svconr.exe . ((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 ))))))))))))))))))))))))))))))) . 2008-05-09 22:31 . 2008-05-09 22:32d--------C:\Documents and Settings\Jeff Hansen\.limewire 2008-05-09 19:22 . 2008-05-09 19:22d--------C:\Documents and Settings\Jeff Hansen\Application Data\Lavasoft 2008-05-09 12:40 . 2008-02-12 14:4548--a------C:\Documents and Settings\Jeff Hansen\readme.bat 2008-05-09 10:45 . 2008-05-09 10:45d--------C:\Program Files\Common Files\Macromedia Shared . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-11 02:26---------d-----wC:\Program Files\Steam 2008-05-11 02:25---------d-----wC:\Documents and Settings\Jeff Hansen\Application Data\WTablet 2008-05-11 02:24---------d-----wC:\Documents and Settings\LocalService\Application Data\WTablet 2008-05-08 21:33---------d-----wC:\Program Files\Common Files\Adobe 2008-05-08 21:27---------d-----wC:\Documents and Settings\Jeff Hansen\Application Data\AdobeUM 2008-03-26 21:40---------d-----wC:\Program Files\LimeWire 2008-03-26 17:45---------d-----wC:\Program Files\Kate's Video Converter 2008-03-19 09:471,845,248----a-wC:\WINDOWS\system32\win32k.sys 2008-03-19 09:471,845,248------wC:\WINDOWS\system32\dllcache\win32k.sys 2008-03-10 13:4632,768----a-wC:\WINDOWS\system32\~GLH0003.TMP 2008-02-20 06:51282,624----a-wC:\WINDOWS\system32\gdi32.dll 2008-02-20 06:51282,624------wC:\WINDOWS\system32\dllcache\gdi32.dll 2008-02-20 05:3245,568----a-wC:\WINDOWS\system32\dnsrslvr.dll 2008-02-20 05:3245,568------wC:\WINDOWS\system32\dllcache\dnsrslvr.dll 2008-02-20 05:32148,992------wC:\WINDOWS\system32\dllcache\dnsapi.dll 2008-02-15 09:0718,432------wC:\WINDOWS\system32\dllcache\iedw.exe 2008-02-10 03:2115----a-wC:\Documents and Settings\Jeff Hansen\StopWZC.bat 2008-02-10 03:2016----a-wC:\Documents and Settings\Jeff Hansen\StartWZC.bat 2008-01-09 21:20251----a-wC:\Program Files\wt3d.ini 2007-03-23 14:39382----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb1942.dat 2007-03-23 14:3869,632----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb4827.dat 2007-03-23 14:38151----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb292.dat 2007-03-23 14:380----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb2391.dat 2006-11-30 03:4249----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb41.dat 2006-11-29 15:466,144----a-wC:\Documents and Settings\Guest\Application Data\internaldb1362.dat 2006-11-22 06:520----a-wC:\Program Files\Common Files\err.log 2006-11-18 17:080----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb5436.dat 2006-11-16 20:079,216----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb9040.dat 2006-11-16 20:070----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb1912.dat 2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb4604.dat 2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb3902.dat 2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb153.dat 2006-11-04 21:037,048----a-wC:\Documents and Settings\All Users\Application Data\ypinfo.bin 2007-12-06 23:1088--sh--rC:\WINDOWS\system32\41457874FA.sys 2007-09-10 18:0756--sh--rC:\WINDOWS\system32\FA74784541.sys 2007-12-06 23:106,580--sha-wC:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((( [emailprotected]_21.45.14.05 ))))))))))))))))))))))))))))))))))))))))) . - 2008-05-11 01:37:182,048--s-a-wC:\WINDOWS\bootstat.dat + 2008-05-11 02:24:272,048--s-a-wC:\WINDOWS\bootstat.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E1550C1-DB0B-4B2D-B338-CA5DCF368E13}] C:\WINDOWS\system32\pwlosnmw.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7C0AA32-5656-42F4-BF96-09ED9F459BD9}] 2008-02-07 21:07217088--a------C:\Program Files\Messenger\kywokelyt821058.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E93121AD-7C67-417A-A6A5-87C60214AC80}] C:\WINDOWS\system32\pmnlm.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ] "Steam"="c:\program files\steam\steam.exe" [2008-04-01 19:03 1271032] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 17:44 98304] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 17:41 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 17:45 118784] "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-12-19 09:08 1347584] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 12:56 761947] "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035] "CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2007-03-23 14:31 230512] "CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2007-03-23 14:31 185456] "YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43 407032] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-07 19:15 180269] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608] "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe] "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-16 02:37 57344] C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2005-03-09 15:57:14 81920] Microsoft Office Shortcut Bar.Lnk [2007-04-02 15:06:31 761] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696] Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-12-25 09:30:07 784912] WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-09-26 23:45:57 106560] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] c:\program files\common files\logitech\bluetooth\LBTWlgn.dll 2007-11-15 11:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm] C:\WINDOWS\system32\pmnlm.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\Program Files\\America Online 9.0\\waol.exe"= "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\WINDOWS\\system32\\sessmgr.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\StubInstaller.exe"= "C:\\Program Files\\Opera\\Opera.exe"= "C:\\Program Files\\AIM\\aim.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"= "C:\\Program Files\\Steam\\SteamApps\\hippiegothie\\team fortress 2\\hl2.exe"= R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38] R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2006-02-14 17:18] R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2006-11-15 15:55] S3 SaiH0461;SaiH0461;C:\WINDOWS\system32\DRIVERS\SaiH0461.sys [2006-08-08 13:25] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}] \Shell\AutoRun\command - E:\setup.exe . Contents of the 'Scheduled Tasks' folder "2008-05-05 15:24:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-05-11 02:24:33 C:\WINDOWS\Tasks\Winter Fun Wallpaper Changer.job" - C:\Documents and Settings\All Users\Start Menu\Programs\Winter Fun Pack 2004 for Windows XP\Winter Fun Wallpaper Changer.lnk . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-10 22:26:55 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\WLTRYSVC.EXE C:\WINDOWS\system32\BCMWLTRY.EXE C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Yahoo!\Antivirus\iSafe.exe C:\WINDOWS\ehome\ehrecvr.exe C:\WINDOWS\ehome\ehSched.exe C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\Tablet.exe C:\Program Files\Yahoo!\Antivirus\VetMsg.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\WINDOWS\system32\Tablet.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe . ************************************************************************** . Completion time: 2008-05-10 22:35:20 - machine was rebooted ComboFix-quarantined-files.txt 2008-05-11 02:34:55 ComboFix2.txt 2008-05-11 01:45:37 Pre-Run: 10,695,467,008 bytes free Post-Run: 12,507,443,200 bytes free 183--- E O F ---2008-04-11 07:09:05uninstall list Ad-Aware SE Personal Adobe Flash Player 9 ActiveX Adobe Flash Player Plugin Adobe Help Center 2.0 Adobe Photoshop Elements 4.0 Adobe Reader 7.1.0 Adobe Shockwave Player AIM "You've Got Pictures" Picture Finder Plugin v9.5.1.8 AOL Coach Version 1.0(Build:20040229.1 en) AOL Connectivity Services AOL Instant Messenger AOL Uninstaller (Choose which Products to Remove) Apple Mobile Device Support Apple Software Update AT&T Yahoo! Applications Audacity 1.2.5 Broadcom Management Programs CDDRV_Installer Conexant HDA D110 MDC V.92 Modem Corel Painter Essentials 3 CursorXP Dell Digital Jukebox Driver Dell Support 3.1 Dell Wireless WLAN Card DellConnect Digital Content Portal Digital Line Detect DivX Codec DivX Content Uploader DivX Converter DivX Player DivX Web Player Documentation & Support Launcher EducateU ESPNMotion Games, Music, & Photos Launcher GemMaster Mystic Half-Life 2 High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB888795) Hotfix for Windows XP (KB891593) Hotfix for Windows XP (KB895961) Hotfix for Windows XP (KB899337) Hotfix for Windows XP (KB899510) Hotfix for Windows XP (KB902841) Hotfix for Windows XP (KB926239) HyperCam 2 Intel(R) Graphics Media Accelerator Driver Internal Network Card Power Management Internet Service Offers Launcher iPod for Windows 2006-03-23 iTunes J2SE Runtime Environment 5.0 Update 1 J2SE Runtime Environment 5.0 Update 3 Java 2 Runtime Environment, SE v1.4.2_03 Java(TM) SE Runtime Environment 6 Update 1 KhalInstallWrapper Learn2 Player (Uninstall Only) LimeWire PRO 4.8.1 Logitech SetPoint Macromedia Flash 5 MCU Microsoft .NET Framework 1.0 Hotfix (KB887998) Microsoft .NET Framework 1.0 Hotfix (KB930494) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft GIF Animator Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Office 97, Professional Edition Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Modem Helper Mozilla Firefox (2.0.0.14) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 Parser and SDK NetWaiting NetZeroInstallers nik COLOR Efex Pro 2.0 IE Opera 9.24 Otto Peggle Deluxe Peggle Extreme Picasa 2 Portal PowerDVD 5.7 QuickSet QuickTime RealPlayer RealWorld Cursor Editor Safety Alert 2006 Safety Bar Saitek SST Programming Software Search Enhancer Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944533) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB947864) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) SigmaTel Audio Sonic DLA Sonic Encoders Sonic RecordNow Audio Sonic RecordNow Copy Sonic RecordNow Data Sonic Update Manager Spybot - Search & Destroy 1.4 Steam Synaptics Pointing Device Driver Tablet Team Fortress 2 Dedicated Server Update for Windows Media Player 10 (KB913800) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) Update for Windows XP (KB946627) Update Rollup 2 for Windows XP Media Center Edition 2005 URGE Viewpoint Manager (Remove Only) Viewpoint Media Player Viewpoint Toolbar WebCyberCoach 3.2 Dell WhiteCap Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890927 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB925766 WinZip Xvid 1.1.2 final uninstall That didn't get everything I hoped it would and there was a new entry I have not seen before. We may need to run it again if the next set of instructions don't work. ----- Your Java is out of date. Older versions of Java have VULNERABILITIES that malware can use to infect your system. Please follow these steps to remove older version(s) of Java components and update. Step 1 - Get the new version 
 
 | |
| 3066. | Solve : just a check? | 
| Answer» Logfile of Trend Micro HijackThis v2.0.2 
 
 
 When i get to 6%of download it keeps failing any ideas?Try a different site. http://www.filehippo.com/download_java_runtime/thanks again found away. to dowload through browser and not there download manager. | |
| 3067. | Solve : Buffer Overrun? | 
| Answer» Open HJT, checkmark all O1 entries, click "Fix checked". | |
| 3068. | Solve : Spyware + some disabled processes? | 
| Answer» My computer is being hit with some REALLY annoying popups and my desktop background was changed to some ad for spyware removal. I tried to follow the instructions in the before you get started thread and I found that some of the apps listed are being blocked by the administrator, which is me but I didn't block them. Task MANAGER is also disabled. 
 [recovering space - attachment deleted by admin]Looks good so far. Still some work to do. Please download Combofix by sUBs from one of the below links. (Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop. 
 
 
 If needed, see this Combofix tutorial with screenshots that will detail the downloading and running of combofix more thoroughly. Still be sure to rename combofix as detailed above. Next post please add: Combofix log | |
| 3069. | Solve : Dangerous virus on your computer? | 
| Answer» The original error went away and I got a new one with yop.exe and "CAVFrm.dll not found". I repeated the AutoRuns scan and deleted yop.exe and now there are no more error messages. | |
| 3070. | Solve : MicroSoft Windows Malicious Software Removal tool? | 
| Answer» I just DL'd this up-date and shortly afterward I got a message stating that it had found and removed Trojan Downloader:Win32/Zlob. I can't understand how this could have got in considering all the protections I have in place. I have Avast, Windows firewall, Windows Defender, Threatfire, Spybot S&D and Spywareblaster and Ad-Aware. Could this be a case of false positives?Possible. Don't clean ANYTHING.... | |
| 3071. | Solve : Computer infected with Trojan.Win32.Blackbird (among others!) - logs attached? | 
| Answer» Heavens know what my husband clicked on to get this on his computer, but now he has the much-feared "Trojan.Win32.Blackbird" icon on his desktop, as well as what seems to be a bunch of other Trojans on his computer.  
 
 
 ---------- Next post add Combofix logAttached with this reply is the combofix log. Also, now the computer is v e r y slow to start up... meaning the desktop comes up, but I can't really click on anything for a few minutes. The SuperAntiSpyware seems to be the culprit since its logo hangs on the computer... possibly not though. Causality vs correlation and all that. It could just be the complete FUBARedness (inventing a word here) of the computer. Thank you, thank you, thank you, for your help. - katheryne [recovering space - attachment deleted by admin]After we get all of the malware gone lets see if things get back to normal. Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 
 Code: [Select]KillAll:: Folder:: C:\Documents and Settings\All Users\Application DATA\wrefyhov Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{BB324F49-82D8-4778-9E25-267724F65061}"=- [HKEY_CLASSES_ROOT\clsid\{bb324f49-82d8-4778-9e25-267724f65061}] [HKEY_CLASSES_ROOT\mkrndofl.1] [HKEY_CLASSES_ROOT\TypeLib\{F0F2A7EE-1699-40E7-934F-03C3A3F8F42D}] [HKEY_CLASSES_ROOT\mkrndofl] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run] "mbJotgwLG7"=- 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick combofix's window while it is running. That may cause your system to freeze ---------- Download and install CleanUp!.exe Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows: 
 Note: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp! If you have a 64 bit Operating System do NOT run Cleanup and let me know as we will use another utility ---------- Next post add Combofix log Let me know how everything is now.Hi there, Attached is the most recent ComboFix log. - katheryne [recovering space - attachment deleted by admin]Looks much better as far as the malware is concerned. Now lets work on the performance issues. I see indications of 3 antivirus software installed. Do you primarily use AVG? Create An Uninstall List 
 Also let me know how things are now. To be almost certain that youve nuked the Virus you should create a restore point first then back up your data and do a complete Reinsall of your whole Operating System by FIRSTLY Re formatting your whole hardrive...this is just so that you dont leave any backdoor connections open to this Trojan/Virus. This is a security must seeing that any data or passwords typed via the interent can still possibly be logged and sent to the hacker. Are you saying we don't know what we are doing? Quote If you receive advice from someone other than the approved Malware Removal Specialists, you do so at your own risk. We are not responsible if you take potentially inaccurate/harmful advice from someone who is not a designated helper. Jackimo, while a clean install is always the only way to be 100% sure no infection is left, we use tools that analyze every file on a PC to determine if it is clean. Users can be confident in the advice we give. A reinstall isn't necessary in 99.99% of the infected PCs we see. Nor is it as practical as it sounds. excuse me, but I also have fallen VICTIM to this same situation. and though I have searched the forums and followed advice given to others on the blackbird thing, I don't think my laptop is completely clean and was wondering if you could help me? I downloaded everything that katheryne was advised to use and can post the logs for any of them if you'd like me too. right now though, my laptop cannot access the internet, and I know for a fact that it is my laptop and not the internet connection itself. also, I have recently downloaded AVG but cannot update it because of that. neither my laptop's wired nor wireless internet work and simply end up as limited or no connection. I'd really appreciate the help and thank you in advanced. also, I cannot access system restore at all.Please start a new topic and post the logs there.Hi again, Here is the uninstall list from HijackThis. I'm really wondering if the problem with the EXTREMELY slow initial response time of the computer is SuperAntiSpyware. It seems like the program is trying to update. But when I click on "install new updates", it does not find any. When I exit the program, the computer seems to snap out of its lethargy. Possibly a re-install of SuperAntiSpyware would work? Do I really need to run SuperAntiSpyware in the background anyway if I have AVG installed? (Would either of those programs, btw, have found this trojan and warned me?) I'd be perfectly happy to run just one anti-virus program. Whatever you'd recommend would be fine with me. - katheryne Adobe Flash Player ActiveX Adobe Reader 7.0.8 AOLIcon Apple Mobile Device Support Apple Software Update AVG Free 8.0 Blue's 123 Time Activities CCleaner (remove only) CleanUp! Conexant D850 56K V.9x DFVc Modem Corel Photo Album 6 Dell CinePlayer Dell Digital Jukebox Driver Dell Driver Reset Tool Dell Game Console Dell Support 3.1 Digital Content Portal Digital Line Detect DivX Content Uploader DivX Web Player Documentation & Support Launcher EarthLink setup files EducateU ELIcon Games, Music, & Photos Launcher Google Toolbar for Internet Explorer HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows Media Format SDK (KB910998) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) HP Care Pack Core HP LaserJet P2015 Series 1.0 HP Update Intel(R) Extreme Graphics 2 Driver Intel(R) PRO Network Adapters and Drivers Intel(R) PROSet for Wired Connections iTunes J2SE Runtime Environment 5.0 Update 6 Java DB 10.3.1.4 Java(TM) 6 Update 6 Java(TM) SE Development Kit 6 Update 6 LiveReg (Symantec Corporation) LiveUpdate 2.6 (Symantec Corporation) Malwarebytes' Anti-Malware MCU Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Outlook 2003 with Business Contact Manager Update Microsoft Office Professional Edition 2003 Microsoft Office Small Business Edition 2003 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Works Modem Helper Mozilla Firefox (2.0.0.14) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) My Sirius Studio NetWaiting NetZeroInstallers Norton Ghost 10.0 PCFriendly QuickTime RealPlayer Roxio DLA Roxio RecordNow Audio Roxio RecordNow Copy Roxio RecordNow Data Safari SearchAssist Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Sonic Activation Module Sonic Update Manager Spybot - Search & Destroy 1.4 SUPERAntiSpyware Free Edition Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) URGE URL Assistant Viewpoint Media Player WebCyberCoach 3.2 Dell Windows Driver Package - SIRIUS (zsi_fw) SIRIUS (07/28/2006 1.00.0003) Windows Driver Package - SIRIUS (zsi_zap) SIRIUS (07/28/2006 1.02.0006) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 WinRAR archiver Yahoo! Music Jukebox Yahoo! WidgetsUninstall Super... and the reinstall the new SUPERAntiSpyware 4.1.1040 Prerelease. It has some speed enhancements. You can turn off any monitoring with it. The free version doesn't have any real time protection anyway so it needs to be set to off. Go to add/remove programs and uninstall: J2SE Runtime Environment 5.0 Update 6 Java DB 10.3.1.4 <unless you use it. Java(TM) SE Development Kit 6 Update 6 LiveReg (Symantec Corporation) LiveUpdate 2.6 (Symantec Corporation) SearchAssist URL Assistant Viewpoint Media Player Now run CCleaner. ---------- Use StartUpLite to get rid of any un-necessary startups. You can uninstall startuplite when it is finished if you choose, or keep it. Your choice. ---------- Use the Secunia Software Inspector 
 ---------- Suggestion: Defrag the drive with a third party defrag program. This will give improved performance. Pick only one. I have used both of these and am now using IOBit because it has an automatic defrag feature. Iobit SmartDefrag Defraggler ---------- Let me know how things are now. I'll do what you recommend later tonight. In the meantime, I just got a "Resident Shield alert" saying: Accessed file is infected. Threat detected! File name: C:\System Volume Information _restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP534\A0033727.dll Threat name: Trojan horse Downloader.Zlob.SE Detected on open Is that from a Restore Point? I wouldn't mind deleting all my previous Restore Points. The data on this computer is all backed up. Yes it is a restore point. We would clear the restore points in the final steps, but we can do it now in order to keep any warnings from coming up. 
 Uninstalling the version of SuperAntiSpyware, installing the new version, and then setting it to NOT run at startup fixed much of the delay when starting up the computer. It does take AVG a little bit to get its *censored* in gear, but my husband calls the wait "not a problem". I'm just thinking he wants his computer back after my kicking him off it for almost a week. But he's right, the little bit of EXTRA wait for the virus scan to start up isn't that bad. Thanks again for all of your help. Hopefully this thread can help others who have experienced the same problem, or at least help point them to some of the best tools to use out there. - katheryne | |
| 3073. | Solve : UNKNOWN VIRUS? | 
| Answer» HI, I HAVE RECEIVED A MESSAGE BY MY ANTIVIR: Q-te A VIRUS OR UNWANTED PROGRAM WAS FOUND. C:\WINDOWS\Temp\tmp1D.tmp Contains detection pattern of a probably damaged sample CC/Agent.HM Unq-te My AVIRA antivir cannot neutralize it. Any help? Thanks! Please start here. Please read this before requesting malware removal helpQuote from: evg1024 on May 14, 2008, 01:22:39 PM HI,HI, I HAVE PREFORMED AS SUGGESTED AND SuperAntispyware log Malwarebytes' log Hijackthis log ARE ENCLOSED. THANKS VERY MUCH FOR THE VERY SOUND AND QUALITY ASSISTANCE! SHOULD I KEEP ALL DOWNLOADED PROGRAMS ON MY PC? AND HOW OFFTEN SHOULD I RUN IT? THANKS AGAIN! JEV [recovering space - attachment deleted by admin]Quote from: evilfantasy on May 14, 2008, 06:34:00 PM Please start here. Please read this before requesting malware removal helpThe logs look fine, are you still having any problems? Run the new programs EVERY other week or so just to ensure nothing has made it's way back into the computer. Just a quick fix with hijackthis and then some cleanup steps. Open Hijackthis and select Do a system scan only. Place a check mark next to the following entries: (if there) O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) Important: Close all windows except for Hijackthis and then click Fix checked. Exit Hijackthis. ---------- Please download ATF Cleaner by Atribune. ATF Cleaner Make sure that all browser windows are closed. Windows Vista USERS: ATF-Cleaner must be Run as an Administrator 
 Important: Restart the computer before continuing. ---------- This is a good time to clear your infected system restore points and establish a new clean restore point: 
 Use the Secunia Software Inspector 
 Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? Let us know if anything else comes up.HI, ALL IS WELL NOTED. THANKS A LOT FOR ALL - HAVE A VERY BEAUTIFUL DAY!Good to know. Safe surfing... There was no need for this to be broken up into two different threads, so I went ahead and merged them. Glad to see all is well. | |
| 3074. | Solve : Web browser problems? | 
| Answer» When i try to USE opera it lets me connect to my speed dial tabs such as google and then from there when i search for something it shuts down. Same with other sites it lets you get to the HOME page then when i got to navigate around it freezes up. I have been getting a few ads saying i have unwanted viruses and illegal porn with are probably spyware/malware?Most likely, your computer is infected... Print these instructions out. 1. Download SUPERAntiSpyware Free for Home Users: http://www.superantispyware.com/ * Double-click SUPERAntiSpyware.exe and use the default settings for installation. * An icon will be created on your desktop. Double-click that icon to launch the program. * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.) * Close SUPERAntiSpyware. Restart computer in Safe MODE. To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen * Open SUPERAntiSpyware. * Under "Configuration and Preferences", click the Preferences button. * Click the Scanning Control tab. * Under SCANNER Options make sure the following are checked (leave all others unchecked): o Close browsers before scanning. o Scan for tracking cookies. o Terminate memory threats before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for Harmful Software" click Scan your computer. * On the left, make sure you check C:\Fixed Drive. * On the right, under "Complete Scan", choose Perform Complete Scan. * Click "Next" to start the scan. Please be patient while it scans your computer. * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK". * Make sure everything has a checkmark next to it and click "Next". * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu. * If asked if you want to reboot, click "Yes". * To retrieve the removal information after reboot, launch SUPERAntispyware again. o Click Preferences, then click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor. o Please copy and paste the Scan Log results in your next reply. * Click Close to exit the program. Post SUPERAntiSpyware log. RESTART COMPUTER! 2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select Perform full scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in Notepad. * Post the log back here. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt RESTART COMPUTER! 3. Download HijackThis: http://www.snapfiles.com/get/hijackthis.html Post HijackThis log.at work atm. i will do this 2moro night. patio i am using vista(x86) 32 bit, sp1. got a cod4 final 2nite. wish my team luck!Good luck Yep...Good Luck. I thought cod was fish... | |
| 3075. | Solve : HJ log? | 
| Answer» Can someone please cheeck this for someone as there internet is down. | |
| 3076. | Solve : Boot Virus New Laptop (Xmas) please help!? | 
| Answer» Hi I got a new Compaq PRESARIO v6000 laptop at Xmas now someone I trusted sent me a “SOMETHING” over MSN/WLM. I now know this “virus” for want of a better WORD stopped my computer from booting (even getting to the Compaq screen before windows loads) I cured this virus by removing the laptop battery yay fixed but then it came back seeming randomly a few weeks later ad again today. I had full AVG trial installed and windows firewall along with WIN Defender at the time oh and I’m running on windows Vista home Pre and my hard drive is sectioned into my laptop recovery drive (D) and my main drive (C). So my question is how to I get rid of this forever? And what is it? | |
| 3077. | Solve : Help Please, Spyware/Adware issue.? | 
| Answer» Well, I believe it has to do with both adware and spyware. | |
| 3078. | Solve : how to utilize AVG update '.bin' files?? | 
| Answer» I subscribed to "[emailprotected]" to recieve update files via e-mail and they come in .bin form. I have not worked with these type of files before and don't know what section to download them to nor how to open them ect.  Important notice for AVG Free UsersPaid version. A paid version key code is required in order to be elgible for this AVG update service mail ist. I hope I'm not violating any license agreement by posting the contents of the message on this open forum, if so I certainly did so out of ignorance and will be happy for the text to be deleted or modified. Try this. Make sure your computer date and time are correct (AVG needs to know) Launch the AVG Control Center, select the Update Manager button, then press the "properties" button at the bottom of the window UNcheck the option "do not ask for update source", and click "apply" Click the Update button at the bottom of the window and find the folder you put .bin file Click OK and AVG will update (unless it's already up to date) I could not find a way to follow your directions in my AVG8 interface, so I went to my sisters computer, which is still running AVG 7.5 free version, and your directions work fine. But: You did give me enough information to figure out how it's done in my version of AVG 8 {version 8.0.93}. --This is how I did it: 1- create a file in My Documents. {I named my file "AVG 8 Update .bin fles"} 2- download the file in the e-mail labled "Update file for all Virus Database versions" to the location created in "My Documents" 3- open AVG "User Interface". {"AVG Overview" screen is displayed} 4- click on "Tools" then select "Update from Directory" in the drop down menu. Then select the file location in the file selection box displayed on the screen {"My Documents/AVG 8 Update .bin files" in my case}. 5- The update progress screen will display then "Update Finished Sucessfully" {in my case a subtitle displayed "New Update Files Not Found" since I already have then latest file downloaded via "Automatic Updates" set to updae every 4 hours. That being said, {" I already have then latest file downloaded via "Automatic Updates" set to updae every 4 hours."}, I see no advantage of this portion of the update service in my case. I was hoping the service would give more information about the latest threats such as possible sites that the threats can be contracted from, what e-mail message "subject ect." cantain threats, and possibly some tips for file names to enter in the "Do Not Alow" box in firewall advanced settings. I guess I just miss-understood the purpose of the update service. The webpage says, "Subscribe or unsubscribe for a free email service, providing you with information concerning the availability of new updates, current virus outbreaks, and other important news concerning AVG products. On average, AVG Update Bulletin is sent twice a week. In case of virus outbreaks it is sent more frequently." Where is the "other important news concerning AVG products"? Thanks for your help evilfantasy ! Glad you worked it out. Install SpywareBlaster and SITE Advisor if you don't already have them. SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware To install Site Advisor, just download the Plug-in for Internet Explorer or the Plug-in for FireFox Here are some links that will have some of the information you are looking for. http://free.grisoft.com/ww.top-threats http://www.ca.com/us/securityadvisor/pest/browse.aspx?cat=adware http://www.bitdefender.com/syndicate/rtvr/main.html# Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? Thanks for the excellent links. I've had limited time to explore everything but I have installed SpywareBlaster and I have a question about it in a minute. 1ST I'll update you on what I have done. Tony Kleins page suggested using Firefox browser due to better security features, faster ect. so I downloaded and installed it and have it set as my default and I locked down ActiveX in Internet Explorer per instructions. I installed Site Advisor for both IE and Firefox, installed Lavasoft's Ad-Aware and Spybot S&D. I already have Malwarebytes {paid version} and Secunia PSI installed as you suggested in a previous topic you helped me with. Current scans with AVG8, Malwarebytes, Spybot and Ad-Aware all show my computer to be infection free. So far a concern I see is in SpywareBlasters block list in the IE catagory. There are several items that do not have a check in the box and the names are in red letters. They are all listed as type = active x. Some of the names are as follows: MoneyTree (2) VX2 Variant Spyblast install control Spyblast iinstall control (2) SearchWWW ClientMan Variant Alexa Variant CoolWebSearch Variant 00110011-4B0B-44D5-ect. CoolWebSearch Variant 17DA0C9E-4AZ7---------- IEPlugin {8} Rank.com Hijacker CoolWebSearch / Gonnasearch Variant There are more I can post if you need them. My question is, should I check all these items and click on the box "Protect Against Checked Items" or are they active x controls that my software needs to function correctly? BTW My computer passed all security test except it failed the test in the "javascript, cookies and third party cookie" sections of http://www.jasons-toolbox.com/BrowserSecurity/ which I linked to from Tony Klien's page. Thanks again with your help so far. I imagine I might have some more questions after I learn more about all the cool tools you linked me too. SpywareBlasters blocks bad activex objects. To use it select Download latest protection updates. Then choose Enable all protection. [recovering space - attachment deleted by admin]That did it. SORRY, I missed clicking the 'Enable all protection' button. SpywareBlaster is now working fine and with paid version so it updates automatically. Thanks again!!!No problem, glad you got it going! | |
| 3079. | Solve : How does everything look?? | 
| Answer» Just wanted to make sure everything was running well on my girflirend's comp....... Please run through this quick? thank you!  | |
| 3080. | Solve : computer problems post-Trojan.Win32.Blackbird and friends? | 
| Answer» I'm not sure what to do. Can you get an XP CD and try a repair install?I don't have an XP CD... I'm just gonna reformat my hardrive, thanks anyway thoughweird... well, I had SERVICE pack 2, and I DOWNLOADED service pack 3, now my internet works (and I haven't reformatted), but it's very testy. sometimes the IP address is invalid... sometimes there's a problem with the DNS, and now my AIM no LONGER functions properly... | |
| 3081. | Solve : Is this registry a malware???? | 
| Answer» HI I have seen a LOT of forums saying that this directory O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe is malware of some sort....I don't know whether is it true or not..Can you guys help me???Btw my com running on windows vista.Anyway below is a log from hijackthis. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:19:23 AM, on 18/5/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16643) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\system32\ntvdm.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Program Files\Grisoft\AVG7\avgcc.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Windows\System32\spool\drivers\w32x86\3\E_FATIBNP.EXE C:\Program Files\Ares\Ares.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\System32\mobsync.exe C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\Grisoft\AVG7\avgw.exe C:\Program Files\Grisoft\AVG7\avginet.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\WerCon.exe C:\Program Files\Windows Live Toolbar\msn_sl.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sg.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SingNet R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll F3 - REG:win.ini: run= C:\WINPENJR\WIN16\CUSTOM.EXE O1 - Hosts: ::1 localhost O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [EPSON Stylus Photo R270 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBNP.EXE /FU "C:\Windows\TEMP\E_S40E6.tmp" /EF "HKCU" O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O4 - Global Startup: Bluetooth.lnk = ? O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xport to Microsoft EXCEL - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O13 - Gopher Prefix: O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 11740 bytesI don't think the file is malicious. You can run the tools in our removal thread to see if anything is turned up. Go to this thread and follow the instructions. There are a few things that need to be addressed, Open Hijackthis and select Do a system scan only. Place a check mark next to the following entries: (if there) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) Important: Close all windows except for Hijackthis and then click Fix checked. Exit Hijackthis. ---------- Your Java is out of date. Older versions of Java have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version(s) of Java components and update. Step 1 - Get the new version 
 
 
 | |
| 3082. | Solve : "Task Manger" is not available for clicking, please help....? | 
| Answer» My computer contracted some nasty malware yesterday and I think I got rid of it all by following the steps in the "Please read this before requesting malware removal help". However, when I press ALT+CONTROL+DELETE the option to click the Task Manager button is not available. Can anyone help me to fix this? Thanks in advance!If you have posted no logs you haven't followed the instructions in the Please Read This section...Here are the logs that I have from Superantispyware, Malwarebytes and hijackthis.  | |
| 3083. | Solve : Which Virus Scanner??? | 
| Answer» Okay I have a few virus scanners that I can install wonder which would work better? Bullguard,Norton,AVG,Avast I dont care much for avg since it comes with a firewall an you have to set all the features but I don't like Norton to much ehter cause you have to pay after a while. Avast!  An "ActiveX Compatibility" registry key is a result of the "Immunize" function included in some anti-spyware programs (e.g.: "Spybot search & destroy", "Spyware blaster",...) So AVG thinks that their database/definitions should be the only thing protecting a users computer from here on out. I think we all know that layered protection is the best method and you should never "put all your eggs in one BASKET" so to speak. And a quote from chaslang at majorgeeks.com Quote You may want to read comments I had on this here: http://forums.majorgeeks.com/showthread.php?t=159452Okay cause I didnt have one for most of the time.I get the FEELING your computing habits are on the dangerous side of things. Quote Okay I have a few virus scanners that I can install Hopefully these are licensed copies you have...Some what I pull a lot of crap off when I have the full defense up. Know there only trial programs for the most part.I see. Have a look at this. Free BitDefender AntiVirus 2008 License Key for 6 MonthsI got bitdefender if theres any differce between the two. | |
| 3084. | Solve : Is any malicious software in my computer? Please help!? | 
| Answer» This is what I get running hijackthis | |
| 3085. | Solve : Dell laptop will not stay shut down? | 
| Answer» This is wrong log (before you applied fixes), you can see "No action taken" after each line. | |
| 3086. | Solve : Need help. Question about the first aid recovery cd.? | 
| Answer» Thanks Broni. I really appreciate it! | |
| 3087. | Solve : Something is blocking my games from starting up? | 
| Answer» this is when i RESTARTED my computer and took it off safe mode. I did everything you told me to | |
| 3088. | Solve : can't access certain websites? | 
| Answer» Quote from: DANKK on May 29, 2008, 11:11:36 PM Quote from: Broni on May 29, 2008, 06:17:39 PMI want you to run one more program (if it'll run)... any further hope on this before I reformat the harddrrive?I had a similar problem, then I found his forum... try checking your "host" file... it worked for me http://www.broadbandreports.com/forum/remark,10186774 I lost this thread, somehow. I think, I didn't get any email notification. DANKK, if you're still there, please, update me on your computer status.Quote from: Broni on June 06, 2008, 03:24:12 PM I lost this thread, somehow. I think, I didn't get any email notification.I want you to run one more program (if it'll run)... Download SDFix (http://downloads.andymanchesta.com/removaltools/sdfix.exe) and save it to your Desktop. * Run the SDFix.exe by double clicking on it. * Allow it to install into the default location which is c:\SDFix * Now please reboot your computer into Safe Mode: # After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; # Instead of Windows loading as normal, the Advanced Options Menu should appear; # Select the first option, to run Windows in Safe Mode, then press Enter. * When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script. * Type Y to begin the cleanup process. * It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot. * Press any Key and it will restart the PC. * When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons. * Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt. * Attach the Report.txt file to your next message. SDFix: Version 1.186 Run by DAN on Thu 05/29/2008 at 06:40 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Windows Registry Values Restoring Windows Default Hosts File Restoring Default Desktop Wallpaper Rebooting Checking Files : Trojan Files Found: C:\WINDOWS\system32\000060.exe - Deleted C:\WINDOWS\system32\000090.exe - Deleted C:\WINDOWS\astctl32.ocx - Deleted C:\WINDOWS\default.htm - Deleted C:\WINDOWS\hosts - Deleted C:\WINDOWS\rundll32.vbe - Deleted C:\WINDOWS\system32\drivers\hosts - Deleted C:\WINDOWS\system32\hljwugsf.bin - Deleted C:\WINDOWS\xxxvideo.hta - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-29 21:48:00 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUIL anguages\RCV2\clb.dll] "0"=hex:00,00,28,0a,01,00,05,00 "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUIL anguages\RCV2\clbcatex.dll] "0"=hex:2a,00,3e,11,0c,00,d1,07 "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUIL anguages\RCV2\clbcatq.dll] "0"=hex:2a,00,3e,11,0c,00,d1,07 "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot \Minimal\vmdesched.sys] @="driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot \Network\vmdesched.sys] @="driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clbdriv er] "start"=dword:00000001 "type"=dword:00000001 "imagepath"=str(2):"\??\globalroot\systemroot\system32\driver s\vmdesched.sys" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILangu ages\RCV2\clb.dll] "0"=hex:00,00,28,0a,01,00,05,00 "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILangu ages\RCV2\clbcatex.dll] "0"=hex:2a,00,3e,11,0c,00,d1,07 "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILangu ages\RCV2\clbcatq.dll] "0"=hex:2a,00,3e,11,0c,00,d1,07 "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Min imal\vmdesched.sys] @="driver" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Net work\vmdesched.sys] @="driver" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\clbdriver] "start"=dword:00000001 "type"=dword:00000001 "imagepath"=str(2):"\??\globalroot\systemroot\system32\driver s\vmdesched.sys" scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\clbImageData] "affid"="7" "subid"="run04" "control"=hex:1a,00,15,13,07,11,18,1f,14,0a,49,09,4b,1a,09,50 ,11,e5,f5 "prov"="10010" "googleadserver"="pagead2.googlesyndication.com" "flagged"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Shell Extensions\Approved\{443EA021-5049-9583-E2C5-EC68521FB889}] "famgilbokocb"=hex:68,61,6f,62,6b,61,69,6d,68,61,64,62,6f,6c, 62,6b,00,02 "famgilbokopa"=hex:68,61,6f,62,6b,61,69,6d,68,61,64,62,6f,6c, 62,6b,00,02 "faaghhcjldie"=hex:61,61,00,00 scanning hidden files ... C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll 110080 bytes executable C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll 498688 bytes executable C:\WINDOWS\system32\drivers\vmdesched.sys 6656 bytes executable C:\WINDOWS\system32\clb.dll 10752 bytes executable C:\WINDOWS\system32\clbcatex.dll 110080 bytes executable C:\WINDOWS\system32\clbcatq.dll 498688 bytes executable C:\WINDOWS\system32\cdosys.dll 31560 bytes executable C:\WINDOWS\system32\clbinit.dll 1695 bytes C:\WINDOWS\system32\dllcache\clb.dll 10752 bytes executable C:\WINDOWS\system32\dllcache\clbcatex.dll 110080 bytes executable C:\WINDOWS\system32\dllcache\clbcatq.dll 498688 bytes executable C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll 110080 bytes executable C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll 501248 bytes executable scan completed successfully hidden processes: 0 hidden services: 1 hidden files: 13 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\shareda ccess\parameters\firewallpolicy\standardprofile\authorizedapp lications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmg r.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0" "C:\\Program Files\\Symantec\\pcAnywhere\\AWHOST32.EXE"="C:\\Program Files\\Symantec\\pcAnywhere\\AWHOST32.EXE:*:Disabled:pcAnywhe re Host Service" "C:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe"="C:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe:*:Disabled:pcAnywher e Remote Service" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\APC\\PowerChute Business Edition\\server\\pbeserver.exe"="C:\\Program Files\\APC\\PowerChute Business Edition\\server\\pbeserver.exe:*:Disabled:PowerChute Business Edition Server" "C:\\Program Files\\Common Files\\AOL\\1170644168\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1170644168\\ee\\aolsoftware.exe:*:Enabled:AOL Shared Components" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader" "C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk" "C:\\Program Files\\Symantec\\pcAnywhere\\WINAW32.EXE"="C:\\Program Files\\Symantec\\pcAnywhere\\WINAW32.EXE:*:Disabled:pcAnywher e Main Program" "C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Disabled:Bonjour" "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Disabled:Skype" "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\shareda ccess\parameters\firewallpolicy\domainprofile\authorizedappli cations\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmg r.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Wed 1 Sep 2004 54,384 A..H. --- "C:\Program Files\America Online 9.0\aolphx.exe" Wed 1 Sep 2004 156,784 A..H. --- "C:\Program Files\America Online 9.0\aoltray.exe" Wed 1 Sep 2004 31,344 A..H. --- "C:\Program Files\America Online 9.0\RBM.exe" Tue 20 May 2008 377 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti705.tmp" Tue 20 May 2008 114 A..H. --- "C:\Program Files\InterActual\InterActual Player\itiAF.tmp" Wed 19 Apr 2006 95,892 A..H. --- "C:\Program Files\Walgreens\Walgreens PhotoShow 4\data\Walgreens PhotoShow Express.exe" Thu 8 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8 c0d990dc65796\BIT5.tmp" Wed 25 May 2005 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp" Wed 25 May 2005 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp" Fri 10 Jun 2005 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp" Fri 10 Jun 2005 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp" Finished! How is your computer doing?Quote from: Broni on June 06, 2008, 11:18:22 PM How is your computer doing?See, if Malwarebytes will run now. | |
| 3089. | Solve : Wondering if desktop computer is infected ...? | 
| Answer» ALRIGHT, I had a problem with the whole bugs screensaver, blue/yellow warning on this desktop, but a couple months ago, it stopped after I ran Malwarebyte's Anti-Malware. I'm on a different computer [different than the laptop that evilfantasy helped me to fix] that I also believe is infected. Before following the procedures in the malware removal post, our internet was just HORRIBLE on this computer. Meaning, it WOULD not receive a signal and also, when we tried to access our homepage, it always said page cannot be displayed. With any page, it mentioned the same error message. However, after running the scans and restarting the computer, we picked up an EXCELLENT signal and our internet is just great. That's how I'm able to type out this message. =) Anyway, here's all the logs that you requested. I just want to cure this computer from any other infections that aren't surfacing yet or that I can't see. =) Thanks for the help !! [recovering space - attachment deleted by admin]Oh! Forgot to mention the fact that the computer now has set restrictions on a lot of options on the computer, such as assessing the Control Panel, the remove/add programs, the desktop properties, etc. The TASK Manager used to be restricted, but I found some .reg file extension from a website designed to fix this problem, saved it on the computer desktop, and it fixed after reboot. The other registry key file edit things for the control panel, add remove programs, etc, would not work; even after reboot it did not work. Another thing is SOMETIMES the desktop likes to freeze, and all the icons on the desktop would disappear, it the computer would be at a stand still. The only way to get out of this problem is just to turn the computer off by pressing the power button. The screen itself would not refresh, it just blanks out. I can see, you're using two antivirus programs: Avira, and McAfee. It looks like Avira is active, and McAfee used to be your antivirus. Please EXPLAIN. One of them has to go.I'll get rid of Mcafee because I recently downloaded Avira to start the malware removal process. I didn't think we had an antivirus program that was active on that computer. Thanks for that information. Quote I didn't think we had an antivirus program that was active on that computer.Not good. Use this tool: http://majorgeeks.com/McAfee_Consumer_Product_Removal_Tool_d5420.html to remove McAfee. When done, post new HJT log. | |
| 3090. | Solve : Re: Windows Security Center? | 
| Answer» Thanks Savior, I am having the same problems as Arwest had on May 1, 2008, | |
| 3091. | Solve : Malware Protector 2008/Bug Screen and Background virus? | 
| Answer» Last night I was attacked by this when visiting a video game site and quickly exited. Im running xp with sp2 and Webroot Spy Sweeper with Antivirus. I removed the Malware Protector 2008 shortly after it installed using the Control panel. I think the spy sweeper blocked most of it but I think some traces still remain.  | |
| 3092. | Solve : PC running slow after virus removal? | 
| Answer» AVG 8.0 still would not recognize my Win XP SP2. | |
| 3093. | Solve : I to have the bug screensaver herpies? | 
| Answer» Quote Is bad computer still in Safe Mode? Yes but just to make sure I wasn't crazy I put memory stick back in good computer the program fired right up. I tried opening superantivirus on bad computer in both mode's.. same ERROR message every time "THE DRIVE OR NETWORK CONNECTION THAT THE SHORTCUT "BOOTSAFE.INK' REFERSE TO IS UNAVAILABLE. MAKE SURE THAT THE DISK IS PROPERLY INSERTED OR THE NETWORK RESOURCE IS AVAILABLE, AND THEN TRY AGAIN.QuoteBOOTSAFE.LNK not .INK is part of Superantispyware.... Try Malwarebytes.Quote from: Broni on June 11, 2008, 10:42:23 PM BOOTSAFE.LNK not .INK is part of Superantispyware.... ya TYPO on the .ink do yo have alink to malwarebytes ?.. My instructions?O... sorry thanx malwarebytes is not opening eather ?... Try HijackThis, then.Quote from: Broni on June 12, 2008, 07:57:30 PM Try HijackThis, then. I tried .... it would'nt open I get the same error message I'm afraid, you're facing Windows reinstall.Transfer SDFix over and run it in Safe Mode. Post the log when complete. Download SDFix.exe and save it to your Desktop. Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that CONTAINS the Windows Directory, TYPICALLY C:\SDFix) Now then reboot your computer in Safe Mode by doing the following: 
 Evil, hey bro I just tried double clicking SDFix in safe mode and I get nothing but a hour glass for like 0.2 sec.. Broni Could you point me out to the best wright up on installing windows ?.. Thanks in advance & for every body who worked with me. XP clean install: http://www.michaelstevenstech.com/cleanxpinstall.htmlI've still got a few more things to try unless you would rather just reinstall. Download Deckard's Association File Tool (DAFT) and save it to your desktop. 
 | |
| 3094. | Solve : Win32.trojan? | 
| Answer» Is there a program that can get rid of Win32.trojan , Win32.backdoor , and many more. | |
| 3095. | Solve : Cant open downloaded zips problems- Hijack log? | 
| Answer» Okay keep in mind that other people use this pc. But I cant open any zips that are downloaded an hope that something will say in it | |
| 3096. | Solve : It is me again lol? | 
| Answer» HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. | |
| 3097. | Solve : McAfee or Avast... THAT is a question? | 
| Answer» My ISP has the option of having McAfee Antivirus and Firewall being installed.  Windows Defender actually popped up and alerted me to something yesterday (updating and activating the new version of malwarebytes real time protection) which was a shocker. Haven't had that happen in months! Maybe the last update did something?Now to wait for their site to no longer be under maintenance... and to cross my fingers hoping that it WONT end up charging extra due to some random POLICY changes that they made without TELLING anyone down the line way back... | |
| 3098. | Solve : Bug Screensaver Virus...Again? | 
| Answer» HELLO. I saw in another THREAD about this virus to DL SuperAntiSpyware, Malwarebytes and HJT. Run them and POST the logs here. I've downloaded the programs and am going to try running them now. Will be back shortly to post the logs. THANKS in advance! | |
| 3099. | Solve : Spyware? Please help me :(? | 
| Answer» Very good ....checking....*** You need to update your Java:  | |
| 3100. | Solve : I am infected with ntos.exe trojan keylogger - please help.? | 
| Answer» I run Win XP SP2 and all software is legal.  
 
 
 Hello EvilFantasy Thank you for your advice. I have removed the two specified items use HJT (renamed Sniper) and I have run the F-Secure online scan and attached the log to this post. I look forward to hearing what you think. PS: Your 'attach' function is still not working for me today (it causes my IE6 to consistently crash each time). I know you asked me to paste it, but if it's ok with you, I would prefer to host the file at the location below: FSecureOnlineScannerLogHow is everything now?Hi EvilFantasy Thank you for your continued help with this. I am amazed and delighted to say that the ominous ntos.exe entry in the usernit section of my registry has now disappeared. In addition, I have performed scans with SuperAntiSpyware and Malwarebytes Anti-Malware and both have found nothing! Does this mean that my computer is ok again now? Does this mean that you're a genius? Looks good!!! Final steps. Set a New Restore Point to prevent possible reinfection from an OLD one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed. 
 Use the Secunia Software Inspector to check for out of date software. 
 Here are some GREAT FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. To prevent unknown applications from being installed on your computer install WinPatrol 2008 Using Winpatrol to protect your computer from malicious software Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam. SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. Using SpywareBlaster to protect your computer from Spyware and Malware Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hello EvilFantasy Thank you so much for all your help. I have scanned everything again just to be certain and it appears that my computer is definitely healed! You're a life-saver! Kind regards PippsNo problem. Safe surfing... | |